Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Hacking Cat. Show all posts

Pro-Ukraine Hacking Cat Group Deploys New Malware Against Russian Targets

 

A pro-Ukraine hacktivist group known as Hacking Cat has significantly escalated its cyber operations against Russian targets by deploying newly developed malware, marking a strategic shift from simple website defacements to sophisticated data destruction campaigns. Researchers at Kaspersky uncovered two previously undocumented malware families—Gorilla RAT and Monkey Ransomware—being used in coordinated attacks that exploit server vulnerabilities and encrypt critical files across compromised networks. This evolution demonstrates how hacktivist groups are becoming increasingly capable of mounting technically advanced and sustained campaigns in the ongoing cyberwar between Ukraine and Russia. 

Hacking Cat first emerged around February 2024, initially focusing on low-impact operations such as defacing Russian websites and leaking stolen documents to embarrass adversaries and spread pro-Ukraine messaging. However, by summer 2025, the group began executing more destructive campaigns designed to encrypt and permanently destroy data on targeted systems rather than merely exposing information. This tactical evolution reflects a broader trend among Ukraine-aligned hacktivists, who are increasingly collaborating and sharing custom-built tools to maximize disruption against Russian infrastructure, state-linked organizations, and entities supporting Moscow's war efforts. 

The newly identified Gorilla RAT serves as a remote-access trojan that can tunnel network traffic, enabling attackers to move laterally within victim networks after exploiting vulnerabilities in Microsoft Exchange servers. Monkey Ransomware, which appends a ".monkey" extension to encrypted files, has appeared in multiple variants written in different programming languages since its debut in late 2025. Kaspersky researchers noted that the unusually rapid iteration of the ransomware could suggest the use of generative AI tools to accelerate malware development, though the hackers may also be experimenting with different coding approaches to evade detection and improve effectiveness against diverse targets. 

Joint operations and shared toolkits

Hacking Cat frequently coordinates with other pro-Ukraine groups, including the Cyber Anarchy Squad and the Ukrainian Cyber Alliance, to execute high-impact attacks that cause maximum disruption. In March 2026, the group claimed responsibility for breaching a contractor working for Rosatom, Russia's state nuclear energy corporation, demonstrating its ability to penetrate sensitive industrial networks. Later, in June, it participated in a destructive operation against Donbassteploenergo, a heating provider in Russian-occupied Donetsk, using Nemo Wiper—a tool designed specifically to erase data and disrupt critical infrastructure rather than collect ransom payments from victims. 

The sharing of malware among hacktivist collectives has complicated efforts to attribute specific attacks to individual groups, as multiple organizations now use identical multi-stage infection chains and custom-developed tools. Kaspersky's report linked several tools to Hacking Cat, but the group pushed back in a Telegram statement, acknowledging ownership of "a couple of the tools" while denying responsibility for the ransomware variants. Hacking Cat accused the cybersecurity firm of incorrectly associating unrelated malware with its operations and criticized the quality of its reverse-engineering analysis, highlighting the challenges researchers face in tracking decentralized hacktivist ecosystems. 

Despite these attribution disputes, the overlap in toolkits underscores a maturing cyberwar ecosystem in which Ukraine-aligned hackers are pooling resources, expertise, and custom malware to sustain pressure on Russian targets. The deployment of AI-assisted development tools, coordinated joint operations, and increasingly destructive capabilities signal that hacktivist groups are no longer peripheral actors but integral components of Ukraine's broader resistance strategy. As the conflict continues, cybersecurity experts warn that similar collaborations could emerge elsewhere, reshaping how non-state actors participate in modern warfare through digital means.