Hacking Cat Evolves Tactics: Destructive Malware Targets Russian Entities
Pro-Ukraine hacktivist group **Hacking Cat** has escalated its operations from basic defacements to sophisticated, destructive cyberattacks against Russian targets. New research by **Kaspersky** reveals the group's use of custom-built tools like **Gorilla RAT** and **Monkey Ransomware**, complicating attribution efforts.
Researchers have unveiled a significant evolution in the tactics employed by the pro-Ukraine hacktivist group, **Hacking Cat**. Once known for website defacements and data leaks, the group has transitioned to more advanced and destructive attacks targeting Russian organizations.
**Kaspersky**, a Russian cybersecurity firm, detailed these developments in a recent report. The firm noted that **Hacking Cat** often collaborates with other Ukraine-linked hacker groups and utilizes a diverse array of custom-built tools, making the attribution of individual attacks considerably more challenging.
**Hacking Cat** initiated its attacks against Russian entities around February 2024. By the summer of 2025, the group reportedly shifted its focus towards operations designed to encrypt and destroy data.
### New Malware Families Uncovered
**Kaspersky**'s investigation uncovered two distinct malware families associated with **Hacking Cat**'s operations: **Gorilla RAT** and **Monkey Ransomware**.
**Gorilla RAT** is a previously undocumented remote-access tool. In some attacks, hackers exploited vulnerabilities in **Microsoft Exchange** servers to establish an initial foothold before deploying **Gorilla RAT**. This custom tool enables network traffic tunneling, granting attackers remote access to systems within a victim's network.
**Monkey Ransomware** encrypts user data, appending the ".monkey" extension to affected files. Researchers observed numerous variants of this ransomware on compromised systems. First appearing in late summer or early fall 2025, the malware saw rapid development, with attackers deploying variants written in different programming languages over subsequent months.
**Kaspersky** speculated that this unusually rapid development could indicate the use of generative AI in malware creation or modification, or simply extensive experimentation by the hackers.
### Collaborative Operations and Shared Tools
**Hacking Cat** has engaged in notable joint operations. In March, it partnered with **Cyber Anarchy Squad** to claim responsibility for breaching a contractor of **Rosatom**, Russiaβs state nuclear energy corporation. In June, it collaborated with the **Ukrainian Cyber Alliance** on a destructive attack against **Donbassteploenergo**, a state-owned heating provider in Russian-occupied Ukrainian territory.
**Kaspersky** also observed different hacktivist groups utilizing the same custom-built tools and, in some instances, identical multi-stage infection chains in separate attacks. For example, during a joint operation with the **Ukrainian Cyber Alliance**, the hackers deployed **Nemo Wiper**, malware seemingly designed for data destruction and infrastructure disruption rather than ransom generation.
This overlap suggests a potential common developer or a small group of developers creating and maintaining malware distributed across multiple hacktivist operations. This sharing further complicates the attribution of specific attacks.
### Hacking Cat Disputes Attribution
**Hacking Cat** has publicly contested some of **Kaspersky**'s attributions regarding the malware described in the report. In a Telegram statement, the group acknowledged ownership of "a couple of the tools" but explicitly denied responsibility for the "lockers" (ransomware), accusing **Kaspersky** of linking unrelated tools to their operations and criticizing the company's reverse-engineering work.
