Executive Summary
Russian enterprises have recently been targeted by three distinct threat clusters: NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls. NightEagle focuses on persistence and lateral movement within Active Directory, leveraging compromised credentials and custom backdoors like GhostContainer. Hacking Cat, a pro-Ukrainian hacktivist entity, has transitioned from defacements to destructive operations using Gorilla RAT and various ransomware families (Monkey, ClearWater, Nemo Wiper).
Technical analysis reveals a high reliance on exploiting known Microsoft Exchange vulnerabilities (CVE-2020-0688, CVE-2021-26855) and utilizing unconventional command-and-control (C2) channels such as HiveMQ MQTT and Matrix-based messengers. The collaboration between hacktivist groups suggests a shared development pipeline for malware tools.
These campaigns pose a significant risk to critical infrastructure and commercial sectors due to the use of wipers and ransomware that often lack recovery mechanisms, effectively functioning as destructive malware. The shift toward custom-built tools like Bird Agent indicates an increasing maturity in evasion techniques.
Key Details
Threat Name
NightEagle APT
Affects
Microsoft Exchange, Remote Desktop Services, Windows, Exchange servers
Adversary
NightEagle Other Adversaries and Aliases: Hacking Cat; Toy Ghouls; Cyber Anarchy Squad; Ukrainian Cyber Alliance
Malware/Tools
GhostContainer, Gorilla RAT, Monkey, ClearWater, Nemo Wiper, GenieLocker, Bird Agent, rdp2tcp, Evil-WinRM, LockBit
