Hacking Cat is a pro-Ukraine hacktivist group active since approximately February 2024, principally targeting organizations in the Russian Federation. Its early activity included website defacements, publication of stolen documents, and promotion of pro-Ukraine messaging. From mid-2025, it was associated with more disruptive operations intended to encrypt or destroy victim data. The group has reportedly collaborated with Cyber Anarchy Squad and Ukrainian Cyber Alliance; shared tooling and infection chains among these collectives complicate attribution of individual operations. Hacking Cat has been associated with exploitation of Microsoft Exchange Server vulnerabilities for initial access and with Gorilla RAT, a Go-based remote-access tool supporting command execution, system and process discovery, file transfer, TCP tunneling, and in some variants remote desktop control. Gorilla RAT includes anti-analysis checks and supports Windows persistence. Operations attributed to the group have also involved Monkey Ransomware variants targeting Windows, Linux, and VMware ESXi. These variants impair recovery mechanisms and encrypt files; certain variants reportedly do not preserve decryption material, making their effects destructive despite ransom-note behavior. Related operations have included ClearWater ransomware and Nemo Wiper, the latter designed to overwrite data and impede recovery. The group has claimed attacks affecting a contractor connected to Russia's state nuclear-energy sector and a heating provider in Russian-occupied Donetsk. Hacking Cat has acknowledged ownership of some tools attributed to it but publicly denied responsibility for ransomware variants linked to its activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Attacks mounted by [Hacking Cat] have weaponized vulnerabilities in Exchange servers (e.g., CVE-2021-26855 and CVE-2026-42897) to deliver a Go-based remote access trojan dubbed Gorilla RAT.
Attacks mounted by [Hacking Cat] have weaponized vulnerabilities in Exchange servers (e.g., CVE-2021-26855 and CVE-2026-42897) to deliver a Go-based remote access trojan dubbed Gorilla RAT.
45 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A pro-Ukrainian hacktivist group targeting Russian enterprises. It has evolved from defacement and data-breach activity to destructive and ransomware/wiper operations, including Exchange exploitation and deployment of Gorilla RAT, Monkey ransomware, ClearWater, and Nemo Wiper.
Ukraine-aligned hacktivist collective conducting disruptive operations against Russian and Russia-linked targets. It is associated with exploitation of Microsoft Exchange servers, lateral movement, file encryption and destruction, data wiping, website defacements, and document leaks. The group coordinates with other pro-Ukraine collectives, although it disputes attribution of some ransomware variants.
Conducts destructive hacktivist operations against Russian organizations, including data encryption/destruction attacks. It has collaborated with other Ukraine-linked hacktivist groups and allegedly used or been linked to several custom malware families, although it disputes attribution of the ransomware/locker tools.
Pro-Ukrainian-aligned hacktivist activity targeting Russian organizations, using Exchange server exploitation for access, Gorilla RAT for remote control and network tunneling, and Monkey Ransomware or destructive payloads including Nemo Wiper. The group also conducts joint operations with other hacktivist collectives.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.