NightEagle, Hacking Cat, and Toy Ghouls Campaigns Targeting Russian Enterprises
First seen Sep 17, 2026 · Updated Sep 17, 2026
Kaspersky has identified three distinct threat activity clusters—NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls—actively targeting Russian enterprises using a combination of backdoors, ransomware, and wiper malware. NightEagle, active since at least 2023, has introduced new persistence and lateral movement techniques, indicating continued evolution and operational maturity across these campaigns.
Technical Analysis
NightEagle (APT-Q-95) demonstrates advanced tradecraft with novel persistence mechanisms and lateral movement techniques, suggesting a well-resourced, likely state-aligned or espionage-motivated actor. The parallel deployment of backdoors, ransomware, and wipers across the three clusters indicates a mixed-motive threat landscape combining data theft, financial extortion, and destructive intent against the same target set. Specific malware families, CVEs, and encryption schemes were not disclosed in the available reporting, limiting technical attribution at this stage. Enterprises running AI agent frameworks, RAG pipelines, or LLM-integrated tooling within targeted Russian organizations should be aware that backdoor persistence and lateral movement techniques could expose API keys, credentials, or agent orchestration hosts if these systems reside on compromised networks, warranting inclusion in incident response scoping.
Affected Systems
Enterprise networks within Russian organizations; specific OS versions, software, or infrastructure not detailed in source reporting
Indicators of Compromise
- No specific hashes, IPs, or domains provided in source data; refer to forthcoming Kaspersky technical reports for NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls indicators
Remediation Steps
- 1
Monitor Kaspersky Threat Intelligence Updates
Track official Kaspersky reports for detailed IOCs, TTPs, and YARA/Sigma rules associated with NightEagle, Hacking Cat, and Toy Ghouls as they are published.
- 2
Harden Persistence Vectors
Audit scheduled tasks, registry run keys, WMI subscriptions, and service installations for unauthorized entries indicative of novel persistence techniques.
- 3
Segment Critical Networks
Implement network segmentation to limit lateral movement between enterprise segments, especially isolating systems running AI agent, automation, or orchestration tooling.
- 4
Backup and Wiper Resilience
Ensure offline, immutable backups are maintained given the presence of wiper malware in the threat set, and test recovery procedures regularly.
- 5
Credential Rotation
Rotate API keys, service account credentials, and secrets on any hosts potentially exposed to backdoor activity, particularly those integrated with AI agent or LLM tooling.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.