Three Threat Groups Target Russian Enterprises with Backdoors
Score: 8/10

Three Threat Groups Target Russian Enterprises with Backdoors

Russian enterprises are facing sophisticated multi-stage attacks from NightEagle, Hacking Cat, and Toy Ghouls involving custom backdoors, wipers, and tunneling tools.

Executive Summary

Russian enterprises have recently been targeted by three distinct threat clusters: NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls. NightEagle focuses on persistence and lateral movement within Active Directory, leveraging compromised credentials and custom backdoors like GhostContainer. Hacking Cat, a pro-Ukrainian hacktivist entity, has transitioned from defacements to destructive operations using Gorilla RAT and various ransomware families (Monkey, ClearWater, Nemo Wiper).

Technical analysis reveals a high reliance on exploiting known Microsoft Exchange vulnerabilities (CVE-2020-0688, CVE-2021-26855) and utilizing unconventional command-and-control (C2) channels such as HiveMQ MQTT and Matrix-based messengers. The collaboration between hacktivist groups suggests a shared development pipeline for malware tools.

These campaigns pose a significant risk to critical infrastructure and commercial sectors due to the use of wipers and ransomware that often lack recovery mechanisms, effectively functioning as destructive malware. The shift toward custom-built tools like Bird Agent indicates an increasing maturity in evasion techniques.

Key Details

Threat Name

NightEagle APT

Affects

Microsoft Exchange, Remote Desktop Services, Windows, Exchange servers

Adversary

NightEagle Other Adversaries and Aliases: Hacking Cat; Toy Ghouls; Cyber Anarchy Squad; Ukrainian Cyber Alliance

Malware/Tools

GhostContainer, Gorilla RAT, Monkey, ClearWater, Nemo Wiper, GenieLocker, Bird Agent, rdp2tcp, Evil-WinRM, LockBit

Report Score

8out of 10
Quality Score
Good
IOC Quality4
TTP Details9
Detection Guidance6
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources