Home Β· Wiki Β· Incidents & Campaigns
type: incident Β· created: 2026-09-17 Β· updated: 2026-09-17 Β· tags: [incident, global, ransomware] Β· confidence: high Β· severity: critical Β· affected_sectors: [global] Β· au_impact: false

Kaspersky has published analysis of three threat activity clusters targeting enterprises in Russia β€” NightEagle (also tracked as APT-Q-95), Hacking Cat and Toy Ghouls β€” and the access route in the NightEagle incidents is the part with transferable value: in most cases the attackers used compromised valid credentials to reach corporate VPNs, with connections originating from Russian-segment IP addresses linked to Cloudflare WARP tunnels and from addresses associated with European virtual infrastructure providers. The group, active since at least 2023, deploys GhostContainer, a modular backdoor previously documented in July 2025 that gives operators complete access to a victim's Microsoft Exchange Server and the ability to run arbitrary code, with new techniques reported for persistence and lateral movement. The clustering is significant for attribution practice as much as for tradecraft: three distinct activity sets operating against one national victim population, one of them a hacktivist-adjacent cluster whose rapid multi-language malware iteration this digest recorded on 15 September as possibly generative-AI-assisted, means the same tooling and infrastructure is being shared across groups with different motivations. The credential-plus-VPN access pattern is also the one most likely to defeat controls that assume an intrusion begins with exploitation, and the use of commercial tunnelling services to blend into legitimate traffic is the anti-attribution measure to note alongside the access vector.

Attribute Detail
Sector Global (Macro)
Date 2026-09-17
Source The Hacker News
Reliability Tier 2