logo

NightEagle and Toy Ghouls Join Hacking Cat in Hitting Russian Firms

ID: 939bcbdd-6df3-5565-b571-2cf551df41cb

STIX ID: report--939bcbdd-6df3-5565-b571-2cf551df41cb

Feed Name: CosmicBytez Labs

Threat Score
82/100

Date Published: 2026-09-16

Date Updated: 2026-09-17

...
...

Kaspersky researchers describe three distinct threat clusters—NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls—targeting Russian enterprises with a mix of state-aligned espionage, hacktivism, and financially motivated operations; notable findings include NightEagle’s GhostContainer backdoor nesting in Exchange, reuse of BlueKeep and AD flaws, Toy Ghouls’ MQTT/Matrix-based C2 and GenieLocker ransomware, and overlapping initial-access techniques such as compromised VPN credentials and Exchange exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.