Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Executive Summary

Kaspersky identified three threat actor clusters—NightEagle (APT‑Q‑95), Hacking Cat, and Toy Ghouls—targeting Russian enterprises with backdoors, ransomware, and wiper malware. NightEagle, active since 2023, uses new persistence and lateral movement techniques.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-16T15:27:49+00:00 - Category: threat-intel

Original Description: Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.

"These days people seek knowledge, not wisdom. Knowledge is of the past, wisdom is of the future."

— Vernon Cooper
Source: The Hacker News