LIVE · cybersecurity feed
Live wire
breach

Pro-Ukraine Hacking Cat group deploying new malware against Russian targets

The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.

zeroday.news ·

A pro-Ukraine hacktivist group known as Hacking Cat has reportedly escalated its operations against Russian targets, moving from website defacements and data leaks to more destructive attacks involving data encryption and destruction. Cybersecurity researchers have identified new custom-built hacking tools associated with the group, which has been active since approximately February 2024.

According to a report from Russian cybersecurity firm Kaspersky, Hacking Cat began shifting towards operations designed to encrypt and destroy data by the summer of 2025. Kaspersky researchers discovered two malware families in attacks linked to the group: Gorilla RAT, a previously undocumented remote-access tool, and Monkey Ransomware.

Gorilla RAT is described as a custom tool capable of tunneling network traffic, which allows attackers to remotely access systems within a victim's network. In some instances, the attackers exploited vulnerabilities in Microsoft Exchange servers to establish an initial foothold before deploying Gorilla RAT.

Monkey Ransomware, which encrypts user data and appends the ".monkey" extension to affected files, first emerged in late summer or early fall of 2025. Kaspersky noted the rapid development of this malware, with numerous variants written in different programming languages appearing over subsequent months. This rapid evolution could suggest the use of generative AI in its creation or modification, or simply extensive experimentation by the attackers.

Hacking Cat often collaborates with other Ukraine-linked hacktivist groups. In March, Hacking Cat and Cyber Anarchy Squad claimed responsibility for breaching a contractor of Rosatom, Russia’s state nuclear energy corporation. In June, Hacking Cat partnered with the Ukrainian Cyber Alliance in a destructive attack against Donbassteploenergo, a state-owned heating provider operating in Russian-occupied parts of Ukraine’s Donetsk region. During this joint operation, the groups utilized malware identified as Nemo Wiper, which appears designed for data destruction and infrastructure disruption rather than ransom generation.

The use of shared custom-built tools and identical multi-stage infection chains across different hacktivist groups has been observed by researchers. This overlap complicates attribution and could indicate that a common developer or a small group of developers is creating and maintaining malware that is then distributed among multiple hacktivist operations.

However, Hacking Cat has disputed some of Kaspersky's attributions. In a Telegram statement, the group acknowledged that "a couple of the tools are ours," but explicitly denied responsibility for the "lockers," accusing Kaspersky of incorrectly linking tools from unrelated groups to Hacking Cat and criticizing the firm's reverse-engineering efforts.

breachmalware
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s