Skip to content
Hacktivist Groups 4BID, Hakerskii Kit, and C.A.S. Broaden Attack Geography, Report Says

Hacktivist Groups 4BID, Hakerskii Kit, and C.A.S. Broaden Attack Geography, Report Says

Technadu June 9, 2026

Securelist reports that hacktivist groups 4BID, Hakerskii Kit, and C.A.S. have broadened their attack geography, targeting organizations across Kazakhstan, the UAE, Egypt, and Syria, beyond their focus on Russian and occasional Belarusian targets. The investigation began after researchers spotted indicators of compromise inside a breached Russian organization, then traced the activity to several interconnected actors.

In most cases, attackers gained initial access by exploiting ProxyShell in Microsoft Exchange before deploying the fd.aspx web shell for remote control, file transfers, and reconnaissance. The campaigns combined custom scripts, new ransomware samples, and commercially available remote monitoring and management tools, according to Securelist by Kaspersky.

Among the software identified were:

Researchers also documented a previously undocumented backdoor named BlackSalt, EDR-killing utilities including GhostDriver, and an updated version of Blackout Locker.

ClearWater ransomware surfaced across multiple compromised infrastructures. Securelist mentions that public sources reported Hakerskii Kit claimed an attack on a Russian factory where ClearWater was also detected, with the attackers publicly thanking the C.A.S. group for their contribution.

Securelist noted that the majority of compromised infrastructures still belong to Russian and Belarusian organizations. However, for the first time, it identified victims in Kazakhstan, the UAE, Syria, and Egypt.

The report assesses that these actors appear to be pivoting toward the wider CIS region and the Middle East, a shift that correlated with a statement from an alleged 4BID member claiming that attacking Russia is no longer profitable.

Last week, an RAlord affiliate was allegedly banned for violating the CIS ransomware rule by infecting the Eriell Group. In May, Russian hackers targeted 13,500 Signal accounts in a hijacking campaign.

Extracted Entities

Attack Types (1)

Companies (1)

Countries (3)

Platforms (1)

Ransomware Groups (1)

Tools (1)

Vulnerabilities (1)