Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Enterprises Face Threats from Cyber Groups

Russian Enterprises Face Threats from Cyber Groups

Posted on September 16, 2026 By CWS

Recent reports from Kaspersky reveal that three distinct cyber threat groups, identified as NightEagle, Hacking Cat, and Toy Ghouls, have been actively targeting businesses in Russia. Each group employs unique methods, ranging from backdoors to ransomware, posing significant challenges to corporate cybersecurity.

NightEagle’s Advanced Techniques

NightEagle, also known as APT-Q-95, has been active since 2023 and is noted for its sophisticated techniques to gain persistence in networks. This group frequently uses valid credentials to access corporate VPNs, often originating from IP addresses linked to Cloudflare WARP and European virtual infrastructure providers. They deploy a backdoor known as GhostContainer, which infiltrates Microsoft Exchange Servers, allowing for arbitrary code execution and file manipulation.

The malware blends into normal server operations, evading detection, and has affected entities in Asia previously. NightEagle exploits various vulnerabilities, such as CVE-2019-0708, to gain elevated privileges and has been observed using tunneling tools to navigate internal networks.

Hacking Cat’s Destructive Tactics

Another group, Hacking Cat, aligns itself with pro-Ukrainian hacktivists and has shifted its focus from website defacement to more destructive attacks, including ransomware. The group has exploited Exchange server vulnerabilities to deploy Gorilla RAT, a trojan that facilitates remote access and control over networks.

Hacking Cat also uses a ransomware family called Monkey, which targets multiple operating systems using various programming languages. Some variants of Monkey function as wipers, erasing data without storing encryption keys, thus causing irreversible damage.

Toy Ghouls’ Custom Backdoor Deployment

Toy Ghouls, a financially motivated group, has transitioned from using well-known ransomware to developing a custom backdoor called Bird Agent. This malware uses unconventional communication channels, such as HiveMQ and Matrix-based messengers, to evade detection. The backdoor is delivered through Windows Remote Management tools and can establish persistence on infected systems.

The shift towards bespoke tools suggests Toy Ghouls’ intention to enhance their attack’s sophistication, making detection and mitigation more challenging for targeted enterprises.

These developments underscore the evolving tactics of cyber threats and emphasize the need for enhanced cybersecurity measures within Russian enterprises. As cyber attackers refine their methods, businesses must remain vigilant and invest in robust security solutions to protect their digital assets.

The Hacker News Tags:Backdoor, Cybersecurity, Hacking Cat, Kaspersky, Malware, NightEagle, Ransomware, Russian enterprises, Toy Ghouls

Post navigation

Previous Post: TP-Link Camera Vulnerabilities Threaten User Privacy
Next Post: Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Related Posts

Law Enforcement’s Use of Webloc for Global Device Tracking Law Enforcement’s Use of Webloc for Global Device Tracking The Hacker News
Citrix Releases Patches for NetScaler Vulnerabilities Citrix Releases Patches for NetScaler Vulnerabilities The Hacker News
New LOTUSLITE Variant Targets Indian Banks and South Korean Policy New LOTUSLITE Variant Targets Indian Banks and South Korean Policy The Hacker News
Critical Flaw in Palo Alto PAN-OS Allows Remote Code Execution Critical Flaw in Palo Alto PAN-OS Allows Remote Code Execution The Hacker News
Microsoft OneDrive File Picker Flaw Grants Apps Full Cloud Access — Even When Uploading Just One File Microsoft OneDrive File Picker Flaw Grants Apps Full Cloud Access — Even When Uploading Just One File The Hacker News
Orchid Security Enhances Enterprise Identity Observability Orchid Security Enhances Enterprise Identity Observability The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark