GhostContainer is a modular .NET backdoor for Microsoft Exchange servers running on Windows. It is associated with the NightEagle (APT-Q-95) activity cluster and has been deployed against government and high-technology organizations in Asia, as well as in intrusions targeting Russian enterprises. The implant is loaded by the Exchange service and processes attacker commands concealed within Exchange web traffic rather than beaconing to dedicated command-and-control infrastructure. It can execute command lines and shellcode, load additional .NET payloads, perform file operations, and execute web requests. GhostContainer also creates virtual server pages and provides web-proxy, socket-forwarding, and long-lived TCP-tunneling functionality, enabling access to internal systems through a compromised Exchange server. Its defense-evasion functions attempt to disable AMSI and Windows Event Log instrumentation in memory. Observed deployments have been linked to compromises of exposed Exchange infrastructure; the precise delivery mechanism has not been conclusively established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
GhostContainer incorporates components from several open-source projects, including the Neo-reGeorg tunnel, an exploit for the CVE-2020-0688 vulnerability, and the GhostWebShell class from the ysoserial utility. | The attackers deployed the GhostContainer backdoor on Microsoft Exchange servers. The backdoor is a .NET assembly containing classes for C2-command processing, AMSI and Windows Event Log evasion, virtual-path redirection, network-traffic proxying, and socket forwarding.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers deployed the GhostContainer backdoor on Microsoft Exchange servers. The backdoor is a .NET assembly containing classes for C2-command processing, AMSI and Windows Event Log evasion, virtual-path redirection, network-traffic proxying, and socket forwarding.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
“Detection of a malicious DLL’s .NET assembly being loaded via PowerShell: suspicious_assembly_loading_into_powershell_via_reflection.”
C2 commands and functionality: Command ID Description... 2 Execute a command line
“The names of the repositories and archives were disguised to look legitimate” and “files contained within the archives were also given names mimicking known legitimate software.”
One of the most notable features is that it creates an instance of the App_Web_843e75cf5b63, which serves as a loader for the web proxy class (App_Web_8c9b251fb5b3) via a virtual page injector.
“Stub: processes C2 commands delivered to the infected system through the x-owa-urlpostdata headers.”
“App_Web_8c9b251fb5b3 implements network traffic redirection (proxying) and socket forwarding functionality.”
it can function as a proxy or tunnel, potentially exposing the internal network to external threats or facilitating the exfiltration of sensitive data from internal devices... Receives data from the internal network, encodes it, and sends it back to the attacker as an HTTP response body.
“evades detection by the Antimalware Scan Interface (AMSI) and Windows Event Log mechanisms by overwriting addresses in amsi.dll and ntdll.dll.”
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET Microsoft Exchange backdoor used by NightEagle for in-memory command-and-control, AMSI and Windows Event Log evasion, virtual-path request handling, traffic proxying, and socket forwarding.
Модульный .NET-бэкдор для Microsoft Exchange, обеспечивающий выполнение команд C2, обход AMSI и журналирования Windows через патчинг amsi.dll и ntdll.dll, а также проксирование и перенаправление сетевого трафика. Для размещения, вероятно, использовалась манипуляция ASP.NET VIEWSTATE с извлеченными криптографическими ключами Exchange.
A .NET Microsoft Exchange backdoor used by NightEagle that receives C2 commands through x-owa-urlpostdata headers, disables or bypasses AMSI and Windows Event Log mechanisms by overwriting addresses in amsi.dll and ntdll.dll, and provides HTTP request redirection, proxying, and socket-forwarding capabilities. The reported implementation incorporates components from Neo-reGeorg, an exploit for CVE-2020-0688, and ysoserial's GhostWebShell class.
Referenced as a specialized threat associated with attacks on Microsoft Exchange servers; no functional details are provided in the content beyond being an Exchange-related threat worth reviewing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.