Skip to content
Three Adversary Groups Deploy Backdoors, Ransomware and Wiper Malware

Three Adversary Groups Deploy Backdoors, Ransomware and Wiper Malware

Ground.News September 17, 2026

Russian Firms Under Fire: Three Adversary Groups Deploy Backdoors, Ransomware and Wiper Malware

Three threat groups are hitting Russian companies with advanced backdoors, ransomware and custom wipers. Kaspersky details the tactics of NightEagle, Hacking Cat and Toy Ghouls. The campaigns reveal evolving capabilities and strategic intent amid the Ukraine conflict. New U.S. and UK warnings highlight parallel Russian-linked operations.

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.

100 % of the sources are Center

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage

Extracted Entities

APT Groups (1)

Attack Types (2)

Countries (2)