Threat Intelligence

Three Distinct Threat Groups Hit Russian Enterprises With Backdoors, Ransomware and Wipers

The Hacker News · 17 Sept 2026
Key Takeaway Businesses using Microsoft Exchange or VPN access should enforce strong credential hygiene, monitor for unusual VPN login origins, and keep servers patched against known vulnerabilities to reduce the risk of backdoor compromise.

Kaspersky researchers have documented attacks by three distinct threat activity clusters against Russian enterprises, tracked as NightEagle, Hacking Cat and Toy Ghouls. The most detailed findings concern NightEagle, active since at least 2023, which has been observed using compromised valid credentials to access corporate VPNs, often connecting from Cloudflare WARP tunnels or European virtual infrastructure providers.

NightEagle's attacks involve a modular backdoor called GhostContainer, which gives attackers full control over a victim's Microsoft Exchange Server, including running arbitrary code, manipulating files and loading extra modules. The malware disguises itself as a normal server component to avoid detection and can also act as a traffic tunnel. It reuses code from several public open-source projects, including a known Exchange vulnerability exploit. The exact delivery method remains unclear, but researchers believe it involves manipulating the server's cryptographic keys and configuration to launch the backdoor directly in memory.

Once inside a network, NightEagle uses tunneling tools and remote desktop protocols to move laterally, exploiting Active Directory vulnerabilities to gain higher privileges and reach deeper into internal systems. Kaspersky notes that GhostContainer has previously been used against government and technology organisations in Asia, suggesting this is not an isolated regional threat.

backdoor malware Microsoft Exchange VPN security ransomware threat intelligence

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.