CVE Tools
Back to feed
Exploited in the wild Microsoft Exchange Server NightEagle ransomware Microsoft Exchange APT-Q-95

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

The Hacker News·By The Hacker News··8 min read
CVE Tools coverage

Kaspersky reports that NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls have targeted Russian enterprises with backdoors, ransomware, and destructive malware. NightEagle compromised Microsoft Exchange Server and exploited CVE-2019-0708 for lateral movement, while Hacking Cat abused Microsoft Exchange vulnerabilities CVE-2021-26855 and CVE-2026-42897 to deploy Gorilla RAT and Monkey ransomware. Toy Ghouls used WinRM to install Bird Agent backdoors that use MQTT or Matrix-based Element communications, increasing the risk of persistent access across affected networks.