Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Reported exploitedMicrosoft Exchange ServerNightEagleOur summary
Kaspersky reports that NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls have targeted Russian enterprises with backdoors, ransomware, and destructive malware. NightEagle compromised Microsoft Exchange Server and exploited CVE-2019-0708 for lateral movement, while Hacking Cat abused Microsoft Exchange vulnerabilities CVE-2021-26855 and CVE-2026-42897 to deploy Gorilla RAT and Monkey ransomware. Toy Ghouls used WinRM to install Bird Agent backdoors that use MQTT or Matrix-based Element communications, increasing the risk of persistent access across affected networks.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.