Rosatom: Pro-Ukraine Hacking Cat group deploying new malware against Russian targets

Rosatom: Pro-Ukraine Hacking Cat group deploying new malware against Russian targets

Pro-Ukraine Hacktivist Group Hacking Cat Evolves with Destructive Cyberattacks on Russian Targets

Researchers at Kaspersky have identified a shift in tactics by the pro-Ukraine hacktivist group Hacking Cat, which has transitioned from website defacements and data leaks to more advanced and destructive cyber operations targeting Russian entities. Active since February 2024, the group began deploying data-encrypting and wiper malware by mid-2025, signaling a significant escalation in its capabilities.

Kaspersky’s report highlights two newly discovered malware families linked to Hacking Cat:

  • Gorilla RAT, a custom remote-access tool that tunnels network traffic, enabling attackers to infiltrate and move laterally within compromised systems. In some cases, the group exploited Microsoft Exchange vulnerabilities to gain initial access.
  • Monkey Ransomware, first observed in late summer/early fall 2025, which encrypts files with a “.monkey” extension. The malware has seen rapid iteration, with variants written in multiple programming languages suggesting possible use of generative AI or aggressive experimentation by the attackers.

Hacking Cat frequently collaborates with other Ukraine-aligned groups, including Cyber Anarchy Squad and the Ukrainian Cyber Alliance. Notable joint operations include:

  • A March 2025 breach of a contractor for Rosatom, Russia’s state nuclear energy corporation.
  • A June 2025 destructive attack on Donbassteploenergo, a state-owned heating provider in Russian-occupied Donetsk.

The group’s operations also overlap with other hacktivist collectives in tooling and attack methods. For instance, Nemo Wiper, a malware designed to permanently destroy data, was deployed in a joint operation with the Ukrainian Cyber Alliance. Kaspersky researchers noted that shared malware and identical infection chains across groups suggest a centralized developer or small team may be supplying tools to multiple hacktivist operations, complicating attribution.

Hacking Cat has denied responsibility for some of the malware attributed to it by Kaspersky, claiming in a Telegram statement that while some tools are theirs, others particularly the ransomware were incorrectly linked to the group. The dispute underscores the challenges in tracking the evolving tactics of decentralized hacktivist networks.

Source: https://therecord.media/ukraine-malware-russia-ransomware

Rosatom cybersecurity rating report: https://www.rankiteo.com/company/rosatom

"id": "ROS1789410912",
"linkid": "rosatom",
"type": "Cyber Attack",
"date": "2/2024",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'industry': 'nuclear energy',
                        'location': 'Russia',
                        'name': 'Rosatom contractor',
                        'type': 'contractor'},
                       {'industry': 'heating/energy',
                        'location': 'Russian-occupied Donetsk',
                        'name': 'Donbassteploenergo',
                        'type': 'state-owned enterprise'}],
 'attack_vector': ['Microsoft Exchange vulnerabilities',
                   'remote-access tool (Gorilla RAT)',
                   'lateral movement'],
 'data_breach': {'data_encryption': True,
                 'sensitivity_of_data': 'high',
                 'type_of_data_compromised': ['sensitive contractor data',
                                              'operational data']},
 'date_detected': '2024-02-01',
 'date_publicly_disclosed': '2025',
 'description': 'Researchers at Kaspersky have identified a shift in tactics '
                'by the pro-Ukraine hacktivist group Hacking Cat, which has '
                'transitioned from website defacements and data leaks to more '
                'advanced and destructive cyber operations targeting Russian '
                'entities. The group began deploying data-encrypting and wiper '
                'malware by mid-2025, including Gorilla RAT and Monkey '
                'Ransomware, and has collaborated with other Ukraine-aligned '
                'groups in high-profile attacks on Russian infrastructure.',
 'impact': {'brand_reputation_impact': True,
            'data_compromised': True,
            'operational_impact': ['disruption of state-owned heating services',
                                   'potential compromise of nuclear energy '
                                   'contractor data'],
            'systems_affected': ['Rosatom contractor systems',
                                 'Donbassteploenergo heating provider '
                                 'systems']},
 'initial_access_broker': {'backdoors_established': 'Gorilla RAT',
                           'entry_point': 'Microsoft Exchange vulnerabilities',
                           'high_value_targets': ['Rosatom contractor',
                                                  'Donbassteploenergo']},
 'investigation_status': 'ongoing',
 'lessons_learned': 'The evolving tactics of decentralized hacktivist groups, '
                    'including the use of generative AI for malware '
                    'development and shared tooling among collectives, '
                    'complicate attribution and defense strategies.',
 'motivation': 'Hacktivism (pro-Ukraine, anti-Russia)',
 'post_incident_analysis': {'corrective_actions': ['Patch management for '
                                                   'critical vulnerabilities',
                                                   'Enhanced detection for '
                                                   'remote-access tool usage',
                                                   'Improved attribution and '
                                                   'tracking of decentralized '
                                                   'hacktivist networks'],
                            'root_causes': ['Exploitation of unpatched '
                                            'Microsoft Exchange '
                                            'vulnerabilities',
                                            'Use of custom remote-access tools '
                                            '(Gorilla RAT) for lateral '
                                            'movement',
                                            'Collaboration with other '
                                            'hacktivist groups for shared '
                                            'tooling and attack methods']},
 'ransomware': {'data_encryption': True,
                'ransomware_strain': 'Monkey Ransomware'},
 'recommendations': ['Enhance monitoring for lateral movement and '
                     'remote-access tool usage',
                     'Patch Microsoft Exchange vulnerabilities promptly',
                     'Collaborate with cybersecurity researchers to track '
                     'emerging threats from hacktivist groups',
                     'Implement robust backup and recovery measures to '
                     'mitigate wiper malware impacts'],
 'references': [{'source': 'Kaspersky'},
                {'source': 'Hacking Cat Telegram statement'}],
 'response': {'communication_strategy': 'Telegram statements (denial of '
                                        'responsibility for some malware)',
              'third_party_assistance': 'Kaspersky (research and analysis)'},
 'threat_actor': 'Hacking Cat',
 'title': 'Pro-Ukraine Hacktivist Group Hacking Cat Evolves with Destructive '
          'Cyberattacks on Russian Targets',
 'type': ['ransomware', 'wiper malware', 'data breach', 'destructive attack'],
 'vulnerability_exploited': 'Microsoft Exchange vulnerabilities'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.