CYBER DELTA FORCESearch

Pro-Ukraine Hacking Cat group deploying new malware against Russian targets

The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.

CDF News DeskThe Record14 Sept 2026, 9:45 pm
Image courtesy of The Record. Original report
CDF REPORT

The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said. Researchers have uncovered new hacking tools used by the pro-Ukraine hacktivist group Hacking Cat, which has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets. The group often works alongside other Ukraine-linked hackers and uses a wide range of custom-built tools, making it “significantly more difficult” to attribute individual attacks to a specific threat actor, Russian cybersecurity firm Kaspersky said in a recent report . Hacking Cat has been attacking Russian organizations since around February 2024, and by the summer of 2025 began shifting toward operations designed to encrypt and destroy data.

Researchers said the malware appears designed to deliberately destroy data and disrupt infrastructure rather than generate ransom payments.

Kaspersky said the unusually rapid development could indicate that generative AI was used to help create or modify the malware, or simply that the hackers were experimenting with its capabilities.

Who is affected

Researchers also discovered numerous variants of Monkey Ransomware on systems compromised in attacks attributed to Hacking Cat.

“A couple of the tools are ours, sure, but the lockers definitely are not,” the group said in a Telegram statement last week, accusing Kaspersky of linking tools from unrelated groups to Hacking Cat and criticizing the company’s reverse-engineering work.

Why this matters

Researchers said the malware appears designed to deliberately destroy data and disrupt infrastructure rather than generate ransom payments.

The technical picture

Kaspersky said the unusually rapid development could indicate that generative AI was used to help create or modify the malware, or simply that the hackers were experimenting with its capabilities.

What to watch next

Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.

MORE IN DATA BREACHES

More cybersecurity reporting

240,000 Hit by Data Breach at Japan’s Digital AgencySecurityWeek · 15 Sept 2026, 5:15 pmTelegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML ExportsThe Hacker News · 14 Sept 2026, 11:28 pmPersonal, Financial Info Exposed in Revolut Data BreachSecurityWeek · 14 Sept 2026, 6:33 pmWebinar: How malicious OAuth apps can lead to Google Workspace breachesBleepingComputer · 14 Sept 2026, 5:45 pm