Kaspersky Names Three Hacking Crews Going After Russian Companies

Kaspersky says NightEagle, Hacking Cat and Toy Ghouls are running separate campaigns against Russian firms, with NightEagle showing fresh persistence tricks.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Photoreal news-editorial wide shot of a dimly lit operations center at night, blue and amber monitor glow, abstract map of Eastern Europe faintly visible on a l
Share

Key points

  • Kaspersky says three separate hacking groups, tracked as NightEagle, Hacking Cat and Toy Ghouls, are targeting Russian companies.
  • NightEagle, also known as APT-Q-95, has been active since at least 2023 according to Kaspersky.
  • The vendor says NightEagle is using new methods to stay inside networks and move between machines.
  • No public link between the three groups has been established.
  • Attribution here is single-vendor, so treat the naming with caution.

Russian businesses are being hit by three different hacking crews at once, according to fresh reporting from Kaspersky picked up by The Hacker News.

The Moscow-based security firm names the groups as NightEagle, Hacking Cat and Toy Ghouls. Kaspersky treats them as distinct operations rather than one campaign wearing different masks.

The most detail belongs to NightEagle, also tracked as APT-Q-95 in the naming system used by QiAnXin. Kaspersky says the group has been running operations since at least 2023 and has added new tools for two specific jobs: staying inside a network after the initial break-in (what analysts call persistence), and hopping from the first infected machine to others on the same network (lateral movement).

Who is being targeted?

Russian enterprises, according to Kaspersky. The vendor has published no victim count or sector breakdown, so the shape of the targeting is still fuzzy.

That matters because the label covers everything from a regional manufacturer to a state-linked energy giant. Without sector detail, it's hard to say whether this is espionage aimed at a specific industry or opportunistic hitting of whoever is exposed.

What do we actually know about the three groups?

Beyond the names and Kaspersky's assessment that they're separate, not much. Here is the state of play as reported.

Cluster Also known as First seen Notes from Kaspersky
NightEagle APT-Q-95 At least 2023 New persistence and lateral movement techniques
Hacking Cat Not disclosed Not disclosed Targeting Russian enterprises
Toy Ghouls Not disclosed Not disclosed Targeting Russian enterprises

The original headline flagged backdoors, ransomware and wipers across the campaigns. Kaspersky's public summary doesn't tie a specific tool to a specific group in a way that lets outsiders verify the split.

How confident should we be in the attribution?

Low to medium, and only because a single vendor is doing the talking. NightEagle's overlap in naming with APT-Q-95, a cluster QiAnXin has written about, is a small piece of corroboration. For Hacking Cat and Toy Ghouls there's no public second source yet.

That's not a criticism of Kaspersky's work. It's how cluster naming goes early in a campaign: one telemetry set, one vendor's view, and the rest of the industry either confirms or quietly renames it later. We've tracked Kaspersky across 16 stories since late June and single-vendor attribution has been a recurring caveat worth keeping.

The thing worth saying plainly: the interesting detail here isn't the group names but the direction of the arrows. Russian firms are now the ones showing up in a Kaspersky roundup that used to focus outward. Worth watching whether Western vendors pick up the same clusters or see something different entirely.

Should you worry if your company operates in Russia?

The usual defences apply. Be cautious with unexpected email attachments, report anything unusual to your IT team, and keep devices patched. NightEagle's focus on persistence means that once it's in, it plans to stay, so an early report from staff is worth far more than a late one.

© 2026 Threat Vectr