Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Summary
Enterprises in Russia are being targeted by three distinct threat activity clusters: NightEagle, Hacking Cat, and Toy Ghouls. Kaspersky reports that NightEagle, active since at least 2023, is employing new persistence and lateral movement techniques. The attacks involve backdoors, ransomware, and wipers.
IFF Assessment
The article details ongoing attacks against enterprises with malicious tools like backdoors, ransomware, and wipers, which represent a direct threat to cybersecurity defenses.
Defender Context
Defenders should be aware of these emerging threat groups targeting Russian enterprises and the types of attacks they are employing. Monitoring for indicators of compromise related to backdoors, ransomware, and wiper malware is crucial, as is understanding the persistence and lateral movement techniques used by threat actors like NightEagle.