Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
The pro-Ukraine hacktivist group Hacking Cat has evolved from defacement and data-leak attacks to destructive operations using proprietary malware. According to a Kaspersky report cited by The Record, the group has deployed two new families: Gorilla RAT, a remote-access tool with tunneling capabilities, and Monkey Ransomware, which encrypts files and appends the .monkey extension. The finding, dated September 14, 2026, marks a turning point in the cyber conflict escalation between Russia and Ukraine.
- Hacking Cat has been active since February 2024 and shifted from defacement to custom destructive malware in roughly 18 months.
- Kaspersky identified Gorilla RAT for remote access and tunneling, and Monkey Ransomware with the
.monkeyextension and variants written in multiple programming languages. - The group denied via Telegram that it authored the "lockers," complicating attribution despite tool sharing with other hacktivist groups.
- Kaspersky hypothesizes that the rapid development of variants may indicate generative AI use, with the plausible alternative being simple operator experimentation.
From February 2024: The Trajectory Toward Destructive Malware
Hacking Cat emerged in February 2024 with defacement attacks against Russian targets. Throughout 2025, the group shifted its modus operandi toward encryption and data-destruction operations. The first appearance of Monkey Ransomware dates to late summer or early autumn 2025, with variants developed in different programming languages.
In parallel, Kaspersky documented the use of Gorilla RAT, described as a previously undocumented remote-access tool with network-traffic tunneling functionality to establish and maintain remote access to compromised systems. In some attacks, the group exploited vulnerabilities in Microsoft Exchange Server to gain initial access. The specific vulnerability used is not known.
Monkey Ransomware and the Attribution Problem
Monkey Ransomware appends the .monkey extension to encrypted files. However, authorship of this tool is contested. In a Telegram statement, Hacking Cat claimed: "A couple of the tools are ours, sure, but the lockers definitely are not." This explicit distinction introduces uncertainty into the mapping of the group's capabilities.
Attribution complexity is amplified by Kaspersky's observation that multiple hacktivist groups share the same custom tools and identical infection chains, suggesting a common developer or an internal tool marketplace. Kaspersky noted that this sharing makes it "significantly more difficult to attribute individual attacks to a specific threat actor."
Collaborations and Joint Operations in 2026
The Kaspersky report documents two significant operations in the first half of 2026. In March 2026, Hacking Cat and Cyber Anarchy Squad claimed an attack against a Rosatom contractor, Russia's state nuclear energy corporation. In June 2026, Hacking Cat collaborated with the Ukrainian Cyber Alliance in a destructive attack on Donbassteploenergo, using Nemo Wiper.
It is unclear whether these collaborations are ad hoc or structured. The exact relationship among Hacking Cat, Cyber Anarchy Squad, and Ukrainian Cyber Alliance remains unspecified in the available dossier.
"unusually rapid development could indicate that generative AI was used to help create or modify the malware, or simply that the hackers were experimenting with its capabilities" — Kaspersky, cited by The Record
The Generative AI Hypothesis: Acceleration or Experimentation
Kaspersky raised the hypothesis that the rapid development of Monkey Ransomware variants — across multiple programming languages in a compressed timeframe — may indicate the use of generative AI to create or modify the malware. The dossier specifies this is a hypothesis, not a confirmation, and that the plausible alternative is that the operators themselves were simply experimenting with the technology's capabilities.
The dossier does not contain independently verifiable technical details on Gorilla RAT, such as hashes, indicators of compromise, or command-and-control server behavior. This absence limits the ability to independently verify attributions and claimed capabilities.
Recommended Actions
Organizations with exposure to Russian targets or interests in the region should consider three specific actions based on the documented case. First: monitor for files with the .monkey extension as an indicator of compromise linked to Monkey Ransomware. Second: review Microsoft Exchange Server access logs for unexplained anomalies, given that Hacking Cat exploited Exchange vulnerabilities for initial access. Third: treat hacktivist group claims with caution, as Kaspersky documented custom tool sharing among distinct groups, making single-group attribution unreliable.
The speed of Hacking Cat's evolution — from February 2024 to late summer 2025 for the first ransomware deployment — demands frequent threat-intelligence feed updates. The possible, if unconfirmed, acceleration via generative AI suggests that malware development cycles in hacktivism may compress further.
Why It Matters
The documented evolution raises questions about the boundary between hacktivism and organized cybercrime. When politically motivated groups deploy ransomware and wipers, and when tool sharing makes attribution impractical, the categorical distinction becomes operationally irrelevant for defenses. The Hacking Cat case shows how brand identity in the cyber underground is managed selectively: claiming some operations, denying others, maintaining strategic ambiguity.
The source does not specify whether the use of Exchange as an initial-access vector continues, nor whether Monkey Ransomware variants remain in active deployment. The dossier does not clarify whether Gorilla RAT and Monkey Ransomware have been observed co-occurring in the same incidents or represent independent development lines.
Frequently Asked Questions
Is Monkey Ransomware confirmed as Hacking Cat's work?
No. The group explicitly denied authorship of the "lockers" in a Telegram statement. Kaspersky cites tool sharing among groups as a factor complicating attribution.
What evidence exists for generative AI use in malware development?
No direct evidence exists. Kaspersky formulated a hypothesis based on the speed of variant development, with a plausible alternative: simple experimentation by the operators themselves.
Which Exchange vulnerability was exploited?
The dossier does not specify which Microsoft Exchange Server vulnerability was used for initial access in the documented attacks.
Information is based on the cited source and current as of publication.
Sources
- https://therecord.media/ukraine-malware-russia-ransomware
- https://www.europesays.com/ukraine/41949/
- https://thehackernews.com/2026/06/winrar-flaw-exploited-by-russia-aligned.html
- https://www.anthropic.com/threat-intelligence-report-september-2026
- https://www.resecurity.com/blog/article/trinity-of-chaos-the-lapsus-shinyhunters-and-scattered-spider-alliance-embarks-on-global-cybercrime-spree
- https://thehackernews.com/
- https://thehackernews.com/p/upcoming-hacker-news-webinars.html
- https://thehackernews.com/search/label/Threat%20Intelligence
- https://thehackernews.com/search/label/Vulnerability
- https://thehackernews.com/search/label/Cyber%20Attack
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.