Russian Firms Under Fire: Three Adversary Groups Deploy Backdoors, Ransomware and Wiper Malware
5 Articles
5 Articles
Russian Firms Under Fire: Three Adversary Groups Deploy Backdoors, Ransomware and Wiper Malware
Three threat groups are hitting Russian companies with advanced backdoors, ransomware and custom wipers. Kaspersky details the tactics of NightEagle, Hacking Cat and Toy Ghouls. The campaigns reveal evolving capabilities and strategic intent amid the Ukraine conflict. New U.S. and UK warnings highlight parallel Russian-linked operations.
A Kaspersky report unmasks three active clusters against Russian enterprise: NightEagle's VPN cyberespionage with the GhostContainer backdoor on Exchange, and Toy Ghouls, a financial group passed by ransomware builder stolen from Bird Agent, a facility that uses MQTT and Matrix as C2 channels.The article Bird Agent speaks on Matrix and MQTT: Kaspersky reveals NightEagle and Toy Ghouls, the new clusters against Russian companies comes from (in) d…
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium







