Hacking Cat: Destructive breaches using Gorilla RAT and Monkey ransomware
Kaspersky reported a campaign by the Hacking Cat group against Russian organizations: attackers exploit Exchange vulnerabilities, deploy Gorilla RAT for remote control, and encrypt data with Monkey ransomware on Windows, Linux, and ESXi. Some variants do not save decryption keys, making losses irreversible.
- Initial access via Microsoft Exchange vulnerabilities (CVE-2021-26855 and others)
- Gorilla RAT communicates with C2 via WebSocket and tunnels TCP to internal services
- Monkey ransomware encrypts Windows, Linux, and ESXi; some variants delete logs and backups
- Some Rust variants do not save keys — data cannot be recovered
Read next
Security