INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Targets Russian Enterprises with Backdoors and Ransomware

| 2026-09-16 15:27 HIGH HIGH RANSOMWARE & EXTORTION MALWARE & BOTNETS STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
The threat landscape is increasingly complex, with multiple groups targeting Russian enterprises using advanced tactics and techniques. The most recent incidents include the deployment of custom backdoors by Toy Ghouls (aka Bearlyfy, [IOC HIDDEN • LOGIN REQUIRED], and Feral Wolf), a ransomware strain dubbed Monkey that has been used in attacks since late summer 2025, and a new variant of the same malware known as ClearWater. These threats are linked to pro-Ukrainian hacktivist entities such as Hacking Cat and Cyber Anarchy Squad, which have been observed teaming up with each other to deliver ransomware strains like Monkey. The use of custom backdoors by Toy Ghouls has also raised concerns about the potential for full-fledged wiper malware to be deployed in future attacks.
Technical Mitigations AI-generated
* Implement a robust network segmentation strategy to isolate critical infrastructure and limit the spread of malware. * Conduct regular vulnerability assessments and penetration testing on Microsoft Exchange servers to identify potential entry points for NightEagle attacks. * Use secure authentication protocols, such as multi-factor authentication (MFA), to prevent attackers from gaining access to corporate VPNs or internal networks. * Monitor network traffic patterns and log analysis can help detect suspicious activity that may indicate a NightEagle attack. * Regularly update and patch operating systems, applications, and services to ensure they have the latest security patches and features.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

op•••••.evtx
ex•••••.tcp
ap•••••.ipify
tr•••••.gen
1c•••••.exe
1c•••••.exe
Ad•••••.exe
ad•••••.exe
10.0.•••.•••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Neo-reGeorgNeo-reGeorgBabukBabukWiperWiper CVE-2020-0688CVE-2020-0688 CVE-2019-0708CVE-2019-0708 CVE-2026-42897CVE-2026-42897 CVE-2021-26855CVE-2021-26855
Target & Sectors
NORTH_AMERICA NORTH_AMERICA technologytechnology governmentgovernment
Incident Timeline
‎February 2024
The threat actor deployed a wiper malware called Nemo Wiper, which overwrites files with random bytes and fills the remaining free disk space with files containing random alphanumeric names and the .lock extension.
source_region Russian Federation
organisation the First Time Rounding
organisation Bearlyfy
organisation Laboo.boo
organisation LockBit
infrastructure Windows
infrastructure Linux
organisation Golang
organisation VMware
organisation Microsoft Outlook
organisation AMSI
organisation RunOnce
organisation Event Tracing for
organisation ETW
organisation Task
organisation Windows Command Prompt
organisation TCP
organisation Hacking Cat
organisation ClearWater
organisation ChaCha20-Poly1305
data_breach 32 byte
organisation SELinux
organisation AppArmor
organisation AES-256-CBC
organisation the Ukrainian
organisation Exchange
organisation Cyber Anarchy Squad
organisation Cyber Alliance
organisation Toy Ghouls
‎July 2025
Threat actors used Microsoft dev tunnels and rdp2tcp to deliver GhostContainer, a known modular backdoor, to target victim's Microsoft Exchange servers.
organisation Microsoft Exchange
tactic T1584.004 - Server
organisation ASP.NET
organisation GhostContainer
organisation VIEWSTATE
organisation Active Directory
organisation the Administrators and Remote Desktop Users
organisation Microsoft
organisation Pro-Ukrainian Hacking Cat Deploys Gorilla
‎late summer 2025
Threat actors used ransomware to target Russian enterprises with backdoors and wipers.
tactic Ransomware
‎July 2026
Threat actors used Windows Remote Management to deliver the Bird Agent backdoor and its configuration files to compromised systems.
infrastructure Windows
organisation 0.1.0
tactic T1021.006 - Windows Remote Management
organisation Bird
organisation the Windows Registry
organisation CLI
organisation HiveMQ
‎2026/09/16
Threat actors used compromised valid credentials to gain access to corporate VPNs.
‎2026/09/16
NightEagle exploited CVE-2019-0708 (BlueKeep) vulnerabilities in Microsoft RDP implementations to gain access and create backdoors on targeted Russian enterprises.
organisation NightEagle
organisation Ransomware
organisation Wipers
organisation Kaspersky
organisation IP
organisation Cloudflare
organisation ASP.NET
organisation GhostContainer
organisation Kaspersky Threat Analysis Traffic
infrastructure Windows
organisation Active Directory
organisation APT
organisation the Antimalware Scan Interface
organisation AMSI
organisation Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
organisation XPSRD
organisation RDP
organisation Domain-Password
organisation the Active Directory
organisation Kaspersky Research Sandbox
organisation TCP
organisation Microsoft
organisation Global Emergency Response Team
organisation GERT
organisation APT-Q-95
organisation GhostContainer on Microsoft Exchange
organisation Microsoft Exchange
organisation Trojan.MSIL.GhostContainer.gen
organisation GitHub
organisation the Administrators and Remote Desktop Users
organisation Kaspersky Threat Analysis
organisation Kaspersky Threat Attribution Engine
organisation KTAE
organisation KTAE However
organisation Kaspersky Endpoint Detection and
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
data_breach
32
Byte
Intelligence Sources