highAPT

NightEagle, Hacking Cat, and Toy Ghouls Campaigns Targeting Russian Enterprises

First seen Sep 17, 2026 · Updated Sep 17, 2026

APTbackdoorransomwarewiperRussiaNightEagleAPT-Q-95lateral-movementpersistenceKaspersky

Kaspersky has identified three distinct threat activity clusters—NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls—actively targeting Russian enterprises using a combination of backdoors, ransomware, and wiper malware. NightEagle, active since at least 2023, has introduced new persistence and lateral movement techniques, indicating continued evolution and operational maturity across these campaigns.

Technical Analysis

NightEagle (APT-Q-95) demonstrates advanced tradecraft with novel persistence mechanisms and lateral movement techniques, suggesting a well-resourced, likely state-aligned or espionage-motivated actor. The parallel deployment of backdoors, ransomware, and wipers across the three clusters indicates a mixed-motive threat landscape combining data theft, financial extortion, and destructive intent against the same target set. Specific malware families, CVEs, and encryption schemes were not disclosed in the available reporting, limiting technical attribution at this stage. Enterprises running AI agent frameworks, RAG pipelines, or LLM-integrated tooling within targeted Russian organizations should be aware that backdoor persistence and lateral movement techniques could expose API keys, credentials, or agent orchestration hosts if these systems reside on compromised networks, warranting inclusion in incident response scoping.

Affected Systems

Enterprise networks within Russian organizations; specific OS versions, software, or infrastructure not detailed in source reporting

Indicators of Compromise

  • No specific hashes, IPs, or domains provided in source data; refer to forthcoming Kaspersky technical reports for NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls indicators

Remediation Steps

  1. 1

    Monitor Kaspersky Threat Intelligence Updates

    Track official Kaspersky reports for detailed IOCs, TTPs, and YARA/Sigma rules associated with NightEagle, Hacking Cat, and Toy Ghouls as they are published.

  2. 2

    Harden Persistence Vectors

    Audit scheduled tasks, registry run keys, WMI subscriptions, and service installations for unauthorized entries indicative of novel persistence techniques.

  3. 3

    Segment Critical Networks

    Implement network segmentation to limit lateral movement between enterprise segments, especially isolating systems running AI agent, automation, or orchestration tooling.

  4. 4

    Backup and Wiper Resilience

    Ensure offline, immutable backups are maintained given the presence of wiper malware in the threat set, and test recovery procedures regularly.

  5. 5

    Credential Rotation

    Rotate API keys, service account credentials, and secrets on any hosts potentially exposed to backdoor activity, particularly those integrated with AI agent or LLM tooling.

Industries Most Exposed

Enterprise/Corporate (Russia)Critical InfrastructureTechnology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.