Pro-Ukraine hacktivist group Hacking Cat has escalated operations against Russian organizations from website defacements and data leaks to campaigns that encrypt or destroy victim data. Kaspersky assessed with high confidence that the group uses the previously undocumented Go- and WebSocket-based Gorilla RAT, which supports command execution, file transfers, TCP tunneling, and—in some variants—VNC control; reported intrusions have at times followed exploitation of Microsoft Exchange vulnerabilities.
The activity has also been linked to cross-platform Monkey Ransomware variants targeting Windows, Linux, and ESXi, including Rust-based samples that do not preserve decryption keys and therefore operate effectively as wipers despite presenting ransom demands. Researchers observed overlaps with Ukraine-linked groups including Cyber Anarchy Squad and Ukrainian Cyber Alliance, such as ClearWater ransomware and a delivery chain for Nemo Wiper, while noting only tentative infrastructure and operational ties to Thor. Hacking Cat disputed the attribution, saying it owns certain tools but denying responsibility for the ransomware lockers.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
Monkey Ransomware emerged in late summer or early autumn 2025, with Windows-focused Rust, .NET, and C++ variants and a Go variant targeting Linux and ESXi. Some Rust versions did not retain decryption keys, making their operations effectively destructive despite ransom notes.
By summer or after mid-2025, Hacking Cat evolved from defacements and leaks toward operations intended to encrypt or destroy victim data.
Cobalt Strike infrastructure at 179.43.186[.]214 was observed in Hacking Cat-associated activity alongside Monkey Ransomware.
Hacking Cat created its Telegram channel and initially publicized website defacements, data leaks, and penetration-testing tools targeting organizations in the Russian Federation.
Hacking Cat rejected Kaspersky's attribution of some malware, acknowledging that some tools belonged to the group while denying ownership of the ransomware lockers.
Kaspersky linked the previously undocumented Gorilla RAT and numerous Monkey Ransomware variants to attacks attributed to Hacking Cat, assessing with high confidence that both toolsets were used only in the group's operations. The reporting said Exchange Server vulnerabilities were used for initial access in some incidents.
After January 2026, Hacking Cat replaced an earlier Go-based Gorilla RAT reverse shell with a more fully featured WebSocket-based remote-access tool supporting command execution, file transfers, TCP tunneling, and, in some samples, VNC control.
In a separate incident, operators used Gorilla RAT with LSAPlatformUpdate.ps1 and LSANetLogin DLLs to install a malicious Windows network provider and deliver Nemo Wiper. The chain forced Safe Mode with Networking, configured automatic administrator login, disabled USB storage and user input, and displayed a fake Windows update screen before the wiper disrupted services and overwrote data.
In a joint incident publicly acknowledged by Hacking Cat, a batch script downloaded and executed ClearWater ransomware. Hacking Cat thanked Cyber Anarchy Squad for assistance.
Hacking Cat and Ukrainian Cyber Alliance conducted a destructive attack against Donbassteploenergo, a state-owned heating provider serving Russian-occupied parts of Ukraine's Donetsk region.
Hacking Cat and Cyber Anarchy Squad claimed responsibility for breaching a contractor of Rosatom, Russia's state nuclear energy corporation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 46 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcesecurelist.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.