#ParsedReport #CompletenessHigh
11-09-2026
Untangling the Knot: Breaking Down the Hacking Cat Group's Toolset
https://securelist.ru/tr/hacking-cat/117062/
Report completeness: High
Actors/Campaigns:
Hacking_cat (motivation: hacktivism)
Cyber_anarchy_squad (motivation: hacktivism)
Bo_team
4bid
Thor
Threats:
Monkey_ransomware
Gorilla
Process_hacker_tool
Upx_tool
Shadow_copies_delete_technique
Hydra_ransomware
Clearwater
Cobalt_strike_tool
Victims:
Russian organizations
Industry:
Military
Geo:
Russian federation, Ukrainian, Russian
CVEs:
CVE-2021-26855 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- microsoft exchange_server (2013, 2016, 2019)
CVE-2021-27076 [Vulners]
CVSS V3.1: 8.8,
Vulners: Exploitation: True
Soft:
- microsoft business_productivity_servers (2010)
- microsoft sharepoint_foundation (2013)
- microsoft sharepoint_server (2016, 2019)
TTPs:
Tactics: 4
Technics: 0
IOCs:
IP: 8
Domain: 1
Url: 1
File: 6
Hash: 35
Soft:
Telegram, qemu, Linux, ESXI, Outlook, Task Scheduler, Winlogon, Windows Defender, crontab, Windows PowerShell, have more...
Algorithms:
chacha20-poly1305, base64, aes-256-cbc, xor, chacha20
Win API:
EtwEventWrite, GetCommandLineW, StartServiceCtrlDispatcherW, CreateToolhelp32Snapshot, OpenProcess, OpenProcessToken, DuplicateTokenEx, WTSEnumerateSessionsW, WTSQueryUserToken, CreateProcessAsUserW, have more...
Win Services:
SQLWriter, MSExchangeIS, MSSQLSERVER, MSSQLServerADHelper100, SQLAgent$SYSTEM_BGC, SQLSERVERAGENT
Languages:
powershell, golang, rust
Post #32403
40