therecord.media Pro-Ukraine Hacking Cat Group Unleashes New Malware Against Russian Targets
Article Content
- •Hacking Cat has evolved to deploy sophisticated malware against Russian targets.
- •New malware includes Gorilla RAT and Monkey Ransomware, with rapid development possibly aided by AI.
- •The group collaborates with other hacktivists, complicating attribution of attacks.
The pro-Ukraine hacktivist group Hacking Cat has developed new malware tools, including Gorilla RAT and Monkey Ransomware, targeting Russian organizations since February 2024. The group has transitioned from website defacements to more destructive attacks, with a focus on encrypting and destroying data. Kaspersky identified that the malware exploits vulnerabilities in Microsoft Exchange servers to gain access. The Monkey Ransomware, which encrypts files with a '.monkey' extension, has multiple variants developed since late summer 2025. The rapid evolution of these tools suggests possible use of generative AI in their development. Hacking Cat has collaborated with other hacktivist groups, including Cyber Anarchy Squad and Ukrainian Cyber Alliance, in various attacks. Notably, they claimed responsibility for breaching a contractor for Rosatom and executing a destructive attack on Donbassteploenergo. Kaspersky's report indicates that overlapping malware usage among different groups complicates attribution. Hacking Cat disputes Kaspersky's claims regarding some malware attributions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Hydra Ransomware, Gorilla RAT and Donbassteploenergo in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…