CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

September 16, 2026

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers Ravie LakshmananSep 16, 2026Malware / Vulnerability Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement. "In most incidents, the attackers used compromised valid credentials to gain access to corporate VPNs," Kaspersky said in an analysis published today. "VPN connections originated from IP addresses in the Russian segment linked to Cloudflare WARP tunnels, as well as from IP addresses…

CVEs: CVE-2020-0688, CVE-2019-0708, CVE-2021-26855, CVE-2026-42897