Researchers have uncovered new hacking tools used by the pro-Ukraine hacktivist group Hacking Cat, which has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets. The group often works alongside other Ukraine-linked hackers and uses a wide range of custom-built tools, making it “significantly more difficult” to attribute individual attacks to a specific threat actor, Russian cybersecurity firm Kaspersky said in a recent report. Hacking Cat has been attacking Russian organizations since around February 2024, and by the summer of 2025 began shifting toward operations designed to encrypt and destroy data. Kaspersky said it discovered two malware families in attacks linked to the group: a previously undocumented remote-access tool dubbed Gorilla RAT and Monkey Ransomware, which according to previous reports encrypts user data and adds the “.monkey” extension to affected files. In some attacks, the hackers exploited vulnerabilities in Microsoft Exchange servers to gain an initial foothold before deploying Gorilla RAT. The custom tool can tunnel network traffic, allowing attackers to remotely access systems inside a victim’s network. Researchers also discovered numerous variants of Monkey Ransomware on systems compromised in attacks attributed to Hacking Cat. The malware first appeared in late summer or early fall 2025, but the attackers tweaked it over the following months, deploying variants written in different programming languages. Kaspersky said the unusually rapid development could indicate that generative AI was used to help create or modify the malware, or simply that the hackers were experimenting with its capabilities. In March, Hacking Cat and another pro-Ukraine hacktivist group, Cyber Anarchy Squad, claimed responsibility for breaching a contractor working for Rosatom, Russia’s state nuclear energy corporation. In June, it worked with the hacktivist group Ukrainian Cyber Alliance on a destructive attack on Donbassteploenergo, a state-owned heating provider operating in Russian-occupied parts of Ukraine’s Donetsk region. Kaspersky said researchers have also seen different hacktivist groups use the same custom-built tools and, in some cases, identical multi-stage infection chains in separate attacks. For example, during a joint operation with the Ukrainian Cyber Alliance, the hackers used malware called Nemo Wiper. Researchers said the malware appears designed to deliberately destroy data and disrupt infrastructure rather than generate ransom payments. Such overlap could indicate that a common developer or small group of developers is creating and maintaining malware that is then distributed among multiple hacktivist operations, researchers said. That sharing also makes it considerably more difficult to determine which group was behind a particular attack. Hacking Cat rejected Kaspersky’s attribution of some of the malware described in the report. “A couple of the tools are ours, sure, but the lockers definitely are not,” the group said in a Telegram statement last week, accusing Kaspersky of linking tools from unrelated groups to Hacking Cat and criticizing the company’s reverse-engineering work.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.