Three distinct threat groups – NightEagle, Hacking Cat, and Toy Ghouls – have been identified by Kaspersky as actively targeting Russian enterprises using a range of malicious tools including backdoors, ransomware, and wipers. NightEagle exploits VPN credentials and Active Directory vulnerabilities to deploy the GhostContainer backdoor, while pro-Ukrainian hacktivist group Hacking Cat leverages Exchange server vulnerabilities to deliver the Gorilla RAT and multiple variants of Monkey ransomware, some of which function as wipers. Toy Ghouls, a financially motivated group, has evolved from using leaked ransomware builders to deploying a custom "Bird Agent" backdoor that uses unconventional C2 channels, including an MQTT broker and the Matrix-based Element messenger, to evade detection.