Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Executive Summary
Kaspersky identified three threat actor clusters—NightEagle (APT‑Q‑95), Hacking Cat, and Toy Ghouls—targeting Russian enterprises with backdoors, ransomware, and wiper malware. NightEagle, active since 2023, uses new persistence and lateral movement techniques.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-16T15:27:49+00:00 - Category: threat-intel
Original Description: Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
"These days people seek knowledge, not wisdom. Knowledge is of the past, wisdom is of the future."
— Vernon Cooper