Pro-Ukraine Hackers Are Building AI-Assisted Malware to Hit Russian Infrastructure
The pro-Ukraine hacktivist group Hacking Cat has moved well beyond website defacements, according to a report by The Record. Researchers at Kaspersky identified two new malware families linked to the group: Gorilla RAT, a remote-access tool that lets attackers control a victim's machine from a distance by tunnelling network traffic inside corporate systems, and Monkey Ransomware, which encrypts files and appends a ".monkey" extension.
The group exploited vulnerabilities in Microsoft Exchange servers to gain an initial foothold before deploying these tools. Kaspersky noted the unusually rapid development of multiple ransomware variants across different programming languages, suggesting generative AI may have assisted in writing or modifying the code.
Several hacktivist groups appear to be sharing the same custom tools and infection chains — making it harder to pinpoint who is behind any individual attack.
What to watch for: Organisations using Microsoft Exchange should ensure all available patches are applied and monitor for unexpected outbound network connections.
Sources

