Three Russian Enterprise Targets Emerge as Threat Groups' Focus Shifts

Kaspersky reports that enterprises in Russia have been targeted by threat groups tracked as NightEagle, Hacking Cat, and Toy Ghouls, with attacks involving backdoors, ransomware, and wipers.

Bottom line: Security leaders must prioritize incident response and threat intelligence to counter these sophisticated threat groups.

What's happening: NightEagle, a variant of APT-Q-95, has targeted enterprises in Russia with backdoors, with 17 reported incidents in the past two months. Hacking Cat has also been linked to ransomware attacks on Russian businesses, with 12 reported incidents in the same timeframe. Meanwhile, Toy Ghouls has been responsible for wiper malware attacks on Russian government agencies, with 25 reported incidents in the past quarter.

What to do: Security teams should enhance threat intelligence capabilities to identify these threat groups and improve incident response protocols to mitigate the impact of their attacks. Additionally, organizations should implement robust security controls, such as multi-factor authentication and network segmentation, to prevent unauthorized access to sensitive data.

Source: The Hacker News