Pro-Ukraine Hacking Cat group deploying new malware against Russian targets
The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.

The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said. Researchers have uncovered new hacking tools used by the pro-Ukraine hacktivist group Hacking Cat, which has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets. The group often works alongside other Ukraine-linked hackers and uses a wide range of custom-built tools, making it “significantly more difficult” to attribute individual attacks to a specific threat actor, Russian cybersecurity firm Kaspersky said in a recent report . Hacking Cat has been attacking Russian organizations since around February 2024, and by the summer of 2025 began shifting toward operations designed to encrypt and destroy data.
Researchers said the malware appears designed to deliberately destroy data and disrupt infrastructure rather than generate ransom payments.
Kaspersky said the unusually rapid development could indicate that generative AI was used to help create or modify the malware, or simply that the hackers were experimenting with its capabilities.
Who is affected
Researchers also discovered numerous variants of Monkey Ransomware on systems compromised in attacks attributed to Hacking Cat.
“A couple of the tools are ours, sure, but the lockers definitely are not,” the group said in a Telegram statement last week, accusing Kaspersky of linking tools from unrelated groups to Hacking Cat and criticizing the company’s reverse-engineering work.
Why this matters
Researchers said the malware appears designed to deliberately destroy data and disrupt infrastructure rather than generate ransom payments.
The technical picture
Kaspersky said the unusually rapid development could indicate that generative AI was used to help create or modify the malware, or simply that the hackers were experimenting with its capabilities.
What to watch next
Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.