← Blog · · df00tech

Kaspersky Details Three Threat Clusters Hitting Russian Enterprises With Backdoors, Ransomware, and Wipers

security-news campaign

What Happened

Kaspersky has published multiple reports identifying three distinct threat activity clusters — tracked as NightEagle (also known as APT-Q-95), Hacking Cat, and Toy Ghouls — targeting enterprises in Russia. According to Kaspersky, NightEagle has been active since at least 2023 and has been observed using new techniques for persistence and lateral movement. Details on the specific tactics, tooling, and targeting of Hacking Cat and Toy Ghouls were not included in the summary reviewed here.

Why It Matters

The reported toolset spans backdoors, ransomware, and wipers — a combination that suggests these clusters may pursue a mix of long-term espionage access and disruptive or destructive outcomes, rather than a single objective. Multiple concurrent clusters operating against the same national enterprise base also raises the likelihood of overlapping infrastructure, shared victims, or attribution ambiguity for defenders trying to distinguish one intrusion from another.

What Defenders Should Watch For

  • Hunt for anomalous persistence mechanisms and unusual lateral movement patterns, particularly given Kaspersky's note that NightEagle has introduced new techniques in these areas.
  • Treat backdoor, ransomware, and wiper activity as potentially originating from the same intrusion chain — destructive payloads may follow an initial, quieter foothold.
  • Review endpoint and EDR telemetry for indicators associated with APT-Q-95 as they become available from vendor reporting.
  • Ensure backup and recovery processes are tested and isolated from production credentials, given the wiper/ransomware component reported.
  • Monitor for follow-on technical reporting from Kaspersky, which may publish IOCs, YARA rules, or further TTP detail on all three clusters.

Note: specific indicators of compromise, malware family names beyond the cluster labels, and detailed TTPs for Hacking Cat and Toy Ghouls were not available in the source summary at time of writing — this write-up reflects only what has been publicly reported so far.

Developing Story

This is net-new threat intelligence and the reporting is still developing. For the original coverage, see The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.