Skip to content
Pro-Ukraine Hacking Cat Group Unleashes New Malware Against Russian Targets

Pro-Ukraine Hacking Cat Group Unleashes New Malware Against Russian Targets

First seen 15 Sep 2026, 15:35 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 17:55 UTC
  • Hacking Cat has evolved to deploy sophisticated malware against Russian targets.
  • New malware includes Gorilla RAT and Monkey Ransomware, with rapid development possibly aided by AI.
  • The group collaborates with other hacktivists, complicating attribution of attacks.

The pro-Ukraine hacktivist group Hacking Cat has developed new malware tools, including Gorilla RAT and Monkey Ransomware, targeting Russian organizations since February 2024. The group has transitioned from website defacements to more destructive attacks, with a focus on encrypting and destroying data. Kaspersky identified that the malware exploits vulnerabilities in Microsoft Exchange servers to gain access. The Monkey Ransomware, which encrypts files with a '.monkey' extension, has multiple variants developed since late summer 2025. The rapid evolution of these tools suggests possible use of generative AI in their development. Hacking Cat has collaborated with other hacktivist groups, including Cyber Anarchy Squad and Ukrainian Cyber Alliance, in various attacks. Notably, they claimed responsibility for breaching a contractor for Rosatom and executing a destructive attack on Donbassteploenergo. Kaspersky's report indicates that overlapping malware usage among different groups complicates attribution. Hacking Cat disputes Kaspersky's claims regarding some malware attributions.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-02-01
Hacking Cat begins attacks on Russian organizations
The group initiates operations targeting Russian entities, marking a shift in their tactics.
Therecord.Media
2025-03-01
Breach of Rosatom contractor
Hacking Cat and Cyber Anarchy Squad claim responsibility for breaching a contractor for Rosatom.
Therecord.Media
2025-06-01
Destructive attack on Donbassteploenergo
Hacking Cat collaborates with Ukrainian Cyber Alliance to execute a destructive attack on a state-owned heating provider.
Therecord.Media
2025-08-01
Monkey Ransomware variants discovered
Multiple variants of Monkey Ransomware are identified, indicating ongoing development and deployment.
Therecord.Media

More articles in this cluster (3)

Following this threat?

Track Hydra Ransomware, Gorilla RAT and Donbassteploenergo in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed