Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
- ID
- 25150
- Status
- summarized
- Published
- 16 Sep 2026, 11:27 PM
- Fetched
- 17 Sep 2026, 12:43 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/three-threat-groups-target-russian.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.0
- Created
- 17 Sep 2026, 12:47 AM
- Tags
- Audience
- developers
What happened
Kaspersky reports three threat clusters—NightEagle, Hacking Cat, and Toy Ghouls—targeting Russian enterprises with backdoors, ransomware, and wipers. NightEagle (APT-Q-95) uses compromised VPN credentials via Cloudflare WARP tunnels, deploys the GhostContainer modular backdoor on Microsoft Exchange servers, and moves laterally using Microsoft dev tunnels, rdp2tcp, and Active Directory vulnerabilities.
Why it matters
This is APT-on-Russian-enterprise activity with no direct impact on what this audience builds or ships. The only transferable detail is the attack chain pattern: compromised VPN credentials leading to Exchange server compromise via publicly available GitHub tools (Neo-reGeorg, ysoserial) and CVE-2020-0688 exploitation—if you run on-prem Exchange, patch it; otherwise there is no actionable takeaway here.
Discussion angle
Skip this segment unless someone in the group runs on-prem Exchange; the only useful note is how attackers stitched together open-source GitHub tools into a working Exchange backdoor, which is a reminder that public offensive tooling lowers the bar for sophisticated attacks.