Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Kaspersky details NightEagle, Hacking Cat, and Toy Ghouls targeting Russian enterprises with Exchange backdoors, Gorilla RAT, and destructive Monkey ransomware.
Kaspersky reports three threat clusters targeting Russian enterprises: NightEagle (APT-Q-95), the pro-Ukrainian hacktivist group Hacking Cat, and Toy Ghouls. NightEagle uses compromised VPN credentials and the GhostContainer modular backdoor to fully compromise Microsoft Exchange servers, chaining CVE-2020-0688 exploitation, BlueKeep (CVE-2019-0708), Active Directory vulnerabilities, and DCSync to seize domain controllers. Hacking Cat exploits Exchange flaws including CVE-2021-26855 and CVE-2026-42897 to deliver the Gorilla RAT and multiple Monkey ransomware variants written in Rust, .NET, C++, and Golang targeting Windows, Linux, and VMware ESXi, with some variants acting as wipers that never store the encryption key.
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
Kaspersky reports Mustang Panda's updated CoolClient backdoor now deploys a signed kernel-mode Windows rootkit, hitting government victims in Myanmar, Mongolia, Pakistan, and Russia.
Kaspersky identified a new CoolClient variant attributed to HoneyMyte (Mustang Panda) that installs a digitally signed Windows kernel driver, msagent.sys, to hide and protect malicious processes, files, registry keys, and C2 network information. CoolClient is consistently deployed as a secondary backdoor after PlugX, with confirmed victims including government entities in Myanmar, Mongolia, Pakistan, and Russia. In a Myanmar campaign, PlugX was used to deploy CoolClient via a renamed Sangfor executable for DLL side-loading, a scheduled task for persistence, and RPC-based process creation with PPID spoofing. The driver, signed with a 2013 certificate issued to Nanjing Ranyi Technology, implements 33 IOCTL handlers, process hiding via unlinking, a filesystem minifilter, and registry callbacks.
Iranian Hackers Pose as Recruiters to Deliver Cross
Kaspersky attributes new cross-platform RATs NodeRabbit and PollCat to Iranian group Nimbus Manticore, spread via recruiter-themed LinkedIn lures.
Kaspersky links two previously undocumented malware families, NodeRabbit (Node.js) and PollCat (obfuscated JavaScript), to the Iranian threat actor Nimbus Manticore, also known as Iranian Dream Job. Victims in Afghanistan, Egypt, and Ethiopia received trojanized coding challenge archives containing fake npm packages (colorized_terminal, pretty-log) that silently launched the RATs as background processes. NodeRabbit contacts Azure-hosted C2 servers via checkin, task, and result API endpoints and supports 11 commands including shell execution, file operations, and network enumeration. Persistence is platform-specific: Windows Run keys or scheduled tasks, Linux cron entries, and macOS launch agents, impersonating Microsoft Edge updates or Intel's Driver & Support Assistant.
Pro-Ukraine Hacking Cat group deploying new malware against Russian targets
Kaspersky links pro-Ukraine hacktivist group Hacking Cat to Gorilla RAT and Monkey Ransomware in destructive attacks on Russian targets.
Kaspersky reports that pro-Ukraine group Hacking Cat, active since February 2024, has shifted from defacements to destructive encryption attacks, using a previously undocumented Gorilla RAT remote-access tool and Monkey Ransomware, which appends the .monkey extension to files. Initial access in some attacks came from exploited Microsoft Exchange vulnerabilities, and rapid multi-language malware variants suggest possible generative AI assistance. Shared tools like Nemo Wiper across groups including Ukrainian Cyber Alliance complicate attribution, and targets include Rosatom contractor and heating provider Donbassteploenergo.
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Kaspersky details Iranian Cavern Manticore's expanded C2 framework using DNS and Google Apps Script, plus APT42's TAMECAT spyware in nuclear-sector phishing.
Kaspersky reported new components in the Cavern (Cav3rn) C2 framework, used by Iranian MOIS-affiliated Cavern Manticore (with overlaps to MuddyWater and OilRig's Lyceum) against Israeli entities, monitored since December 2025. The new GoogleService.dll module performs DNS A-record queries to choose between direct HTTPS and a Google Apps Script relay per transaction, with the DNS infrastructure able to rotate the Google deployment ID; Kaspersky also found an inter-component broker (rnp.dll) and linked the framework's plugin-based pivot to late April 2026. Separately, Group-IB and Kaspersky detailed HOLLOWGRAPH, a .NET NativeAOT DLL first seen in the wild June 7, 2026, that uses Microsoft 365 calendar events via the Graph API as two-way dead drops dated May 13, 2050, with DNS tunneling refreshing Entra ID credentials. DarkAtlas also reported APT42's TAMECAT modular surveillance framework delivered via LNK masquerading as PDFs in spear-phishing targeting the nuclear energy sector in April-May 2026, with the group using generative AI to accelerate operations.
Iranian cyber spies target aviation, fintech developers with new malware
Kaspersky links Iranian espionage group Mirage Kitten to fake job offers delivering new NodeRabbit and PollCat malware at aviation and fintech targets.
Kaspersky attributes the campaign to Iran-linked Mirage Kitten (also tracked as UNC1549, Smoke Sandstorm and Nimbus Manticore), which targeted developers and specialists in Egypt, Ethiopia and Afghanistan via fake recruiter contacts on LinkedIn and job platforms. Victims were lured into running malicious coding assessments that deployed two previously unknown families: NodeRabbit, a cross-platform RAT for Windows, Linux and macOS, and PollCat, which provides persistence and delivers additional payloads. The group masks activity behind legitimate Microsoft Azure and Cloudflare infrastructure, sometimes embedding victim organization names in Azure subdomains. The group has been active since at least 2022, focusing on aviation, aerospace and financial technology sectors in Africa and the Middle East.
Mustang Panda Upgrades CoolClient With a Kernel Rootkit
Mustang Panda's updated CoolClient backdoor deploys a signed kernel driver to hide processes, files and network activity in Asian intrusions.
Kaspersky analysis shows Mustang Panda (HoneyMyte) upgraded its CoolClient espionage backdoor with a signed kernel-mode driver installed as a Windows service, communicating via IOCTL requests to hide processes, files and registry entries. In a Myanmar campaign the actor deployed PlugX first, then CoolClient via a fake Windows Defender directory and Sangfor defender.exe DLL sideloading, with scheduled task and AutoRun persistence and UAC bypass. The updated variant was observed in intrusions across Pakistan, Mongolia and Myanmar, with victims also in Russia including confirmed government entities.