NightEagle is a cyber-espionage threat actor active since at least 2023, also tracked as APT-Q-95 and APT-C-78. It has targeted Chinese government, defense, and critical-technology organizations, including entities associated with artificial intelligence, semiconductor manufacturing, and quantum technology, and has also targeted enterprises in Russia. The group has been linked to compromises of Microsoft Exchange Server, including reported use of an Exchange zero-day exploit chain to deploy GhostContainer, a modular .NET backdoor capable of command execution, payload loading, file operations, web proxying, socket forwarding, and covert tunneling. GhostContainer conceals command traffic within Exchange web requests and includes mechanisms intended to bypass AMSI and Windows event logging. NightEagle has exfiltrated mailbox data and has targeted source-code repositories and backup systems. In other intrusions, it obtained access to corporate VPNs using compromised credentials, used Microsoft Dev Tunnels, RDP tunneling, Windows port forwarding, and scheduled tasks to maintain access and move laterally, and abused Active Directory and Kerberos capabilities to escalate privileges and attempt domain replication. It has also exploited CVE-2019-0708 (BlueKeep) in at least one incident. Attribution to a particular country remains unconfirmed; an assessment based on operational hours suggested possible North American operator activity, but no formal country linkage has been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
In one incident, they exploited a well-known RDP implementation vulnerability, CVE-2019-0708 (BlueKeep). They used the vulnerable mechanism to create a local account on the system and add it to the Administrators and Remote Desktop Users groups.
The value element in the XML starts with a hardcoded string /wEPDwUKLTcyODc4 , and the same string is used in another open-source project, ExchangeCmdPy.py , to exploit the Exchange vulnerability CVE-2020-0688... We suspect that the vulnerability exploited in the Exchange attack may be related to CVE-2020-0688.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting intrusions against Russian businesses using compromised VPN credentials, the GhostContainer Exchange backdoor, network tunneling, Active Directory attacks, and lateral movement to compromise domain controllers.
Conducting intrusions against Russian enterprises using compromised valid VPN credentials, deploying the GhostContainer backdoor on Microsoft Exchange servers, tunneling RDP traffic, exploiting Active Directory weaknesses, and performing credential theft and domain-controller compromise.
Conducting intrusion campaigns against organizations in Asia and businesses in Russia. The group gains initial access using compromised VPN credentials, deploys the GhostContainer backdoor on Microsoft Exchange, tunnels traffic with Microsoft dev tunnels and rdp2tcp, moves laterally over RDP, and targets Active Directory for privilege escalation, credential access, persistence, and domain-controller compromise.
Espionage actor targeting China’s government/defense/technology sectors by exploiting Microsoft Exchange via a zero-day exploit chain.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.