Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Enterprises Face Threats from Cyber Groups

Russian Enterprises Face Threats from Cyber Groups

Posted on September 16, 2026 By CWS

Recent reports from Kaspersky reveal that three distinct cyber threat groups, identified as NightEagle, Hacking Cat, and Toy Ghouls, have been actively targeting businesses in Russia. Each group employs unique methods, ranging from backdoors to ransomware, posing significant challenges to corporate cybersecurity.

NightEagle’s Advanced Techniques

NightEagle, also known as APT-Q-95, has been active since 2023 and is noted for its sophisticated techniques to gain persistence in networks. This group frequently uses valid credentials to access corporate VPNs, often originating from IP addresses linked to Cloudflare WARP and European virtual infrastructure providers. They deploy a backdoor known as GhostContainer, which infiltrates Microsoft Exchange Servers, allowing for arbitrary code execution and file manipulation.

The malware blends into normal server operations, evading detection, and has affected entities in Asia previously. NightEagle exploits various vulnerabilities, such as CVE-2019-0708, to gain elevated privileges and has been observed using tunneling tools to navigate internal networks.

Hacking Cat’s Destructive Tactics

Another group, Hacking Cat, aligns itself with pro-Ukrainian hacktivists and has shifted its focus from website defacement to more destructive attacks, including ransomware. The group has exploited Exchange server vulnerabilities to deploy Gorilla RAT, a trojan that facilitates remote access and control over networks.

Hacking Cat also uses a ransomware family called Monkey, which targets multiple operating systems using various programming languages. Some variants of Monkey function as wipers, erasing data without storing encryption keys, thus causing irreversible damage.

Toy Ghouls’ Custom Backdoor Deployment

Toy Ghouls, a financially motivated group, has transitioned from using well-known ransomware to developing a custom backdoor called Bird Agent. This malware uses unconventional communication channels, such as HiveMQ and Matrix-based messengers, to evade detection. The backdoor is delivered through Windows Remote Management tools and can establish persistence on infected systems.

The shift towards bespoke tools suggests Toy Ghouls’ intention to enhance their attack’s sophistication, making detection and mitigation more challenging for targeted enterprises.

These developments underscore the evolving tactics of cyber threats and emphasize the need for enhanced cybersecurity measures within Russian enterprises. As cyber attackers refine their methods, businesses must remain vigilant and invest in robust security solutions to protect their digital assets.

The Hacker News Tags:Backdoor, Cybersecurity, Hacking Cat, Kaspersky, Malware, NightEagle, Ransomware, Russian enterprises, Toy Ghouls

Post navigation

Previous Post: TP-Link Camera Vulnerabilities Threaten User Privacy
Next Post: Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Related Posts

Miasma Worm Affects 73 Microsoft GitHub Repositories Miasma Worm Affects 73 Microsoft GitHub Repositories The Hacker News
China-Based APT UAT-7810 Enhances ORB Network with LONGLEASH China-Based APT UAT-7810 Enhances ORB Network with LONGLEASH The Hacker News
Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise The Hacker News
Citrix Releases Emergency Patches for Actively Exploited CVE-2025-6543 in NetScaler ADC Citrix Releases Emergency Patches for Actively Exploited CVE-2025-6543 in NetScaler ADC The Hacker News
Critical Dahua Camera Flaws Enable Remote Hijack via ONVIF and File Upload Exploits Critical Dahua Camera Flaws Enable Remote Hijack via ONVIF and File Upload Exploits The Hacker News
Anthropic AI Unearths Firefox Security Flaws Anthropic AI Unearths Firefox Security Flaws The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management
  • Browser Extension Risks AI Assistant Security
  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management
  • Browser Extension Risks AI Assistant Security
  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark