Security News

Pro-Ukraine Hacktivist Group Escalates to Destructive Malware Attacks

The Record · 15 Sept 2026
Key Takeaway Businesses should patch Microsoft Exchange and other internet-facing systems promptly, as unpatched vulnerabilities remain a common entry point for both hacktivist and criminal ransomware attacks.

Security researchers at Kaspersky have uncovered new malicious tools linked to Hacking Cat, a pro-Ukraine hacktivist group that has shifted from simple website defacements and data leaks to more destructive cyberattacks. Since February 2024, the group has targeted Russian organisations, and by mid 2025 its operations increasingly involved encrypting and destroying victim data rather than just stealing or leaking it.

Kaspersky identified two new malware families used in these attacks: Gorilla RAT, a remote-access tool that lets attackers tunnel into victim networks, and Monkey Ransomware, which encrypts files and appends a ".monkey" extension. In some cases, attackers exploited vulnerabilities in Microsoft Exchange servers to gain initial access before deploying Gorilla RAT. Researchers noted that Monkey Ransomware has been rapidly updated with multiple variants written in different programming languages, a pace of development that could suggest the use of generative AI tools or ongoing experimentation by the attackers.

Hacking Cat has also collaborated with other pro-Ukraine hacktivist groups, including Cyber Anarchy Squad and the Ukrainian Cyber Alliance, on notable incidents such as a breach of a Rosatom contractor and a destructive attack on a Russian-occupied heating utility. Kaspersky observed that different hacktivist groups are sharing custom tools and even identical attack chains, making it harder to attribute specific incidents to a single actor.

ransomware hacktivism Russia-Ukraine cyber conflict Microsoft Exchange malware

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.