GhostContainer is a modular .NET backdoor for Microsoft Exchange Server on Windows. It provides remote control of compromised Exchange servers through command processing embedded in Exchange web traffic, allowing operators to execute commands and shellcode, load additional .NET payloads, and perform file operations. It can create virtual server-side pages, proxy and redirect network traffic, forward sockets, and establish tunnels between external operators and internal hosts. GhostContainer includes evasion functionality targeting AMSI and Windows Event Log mechanisms and is designed to blend with Exchange server components rather than use conventional beaconing infrastructure. The malware incorporates code derived from public projects, including Neo-reGeorg and components associated with exploitation of CVE-2020-0688. GhostContainer has been deployed by the NightEagle (APT-Q-95) cyberespionage cluster following compromise of corporate environments, particularly against Microsoft Exchange servers. Observed targeting includes government and high-technology organizations in Asia and businesses in Russia. Its exact initial deployment mechanism has not been conclusively established; exploitation of Microsoft Exchange weaknesses, including CVE-2020-0688, has been assessed as a possible vector.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
GhostContainer собран из компонентов нескольких опенсорсных проектов, свободно доступных на GitHub. В их числе туннель Neo-reGeorg, эксплоит для CVE-2020-0688, а также компоненты ysoserial. | After gaining access through VPN accounts, the attackers deployed the GhostContainer backdoor on Microsoft Exchange servers. It is assembled from components of several open-source projects, including Neo-reGeorg, an exploit for CVE-2020-0688, and ysoserial components.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After gaining access through VPN accounts, the attackers deployed the GhostContainer backdoor on Microsoft Exchange servers. It is assembled from components of several open-source projects, including Neo-reGeorg, an exploit for CVE-2020-0688, and ysoserial components.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
“Detection of a malicious DLL’s .NET assembly being loaded via PowerShell: suspicious_assembly_loading_into_powershell_via_reflection.”
C2 commands and functionality: Command ID Description... 2 Execute a command line
“The names of the repositories and archives were disguised to look legitimate” and “files contained within the archives were also given names mimicking known legitimate software.”
One of the most notable features is that it creates an instance of the App_Web_843e75cf5b63, which serves as a loader for the web proxy class (App_Web_8c9b251fb5b3) via a virtual page injector.
it can function as a proxy or tunnel, potentially exposing the internal network to external threats or facilitating the exfiltration of sensitive data from internal devices... Receives data from the internal network, encodes it, and sends it back to the attacker as an HTTP response body.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Microsoft Exchange server backdoor used by NightEagle that can proxy network traffic and bypass AMSI and Windows logging mechanisms. It is composed from publicly available open-source components.
A Microsoft Exchange server backdoor used by NightEagle to remotely control compromised servers, evade certain Windows security and logging mechanisms, redirect network traffic, and support persistence and lateral movement.
A .NET Microsoft Exchange backdoor used by NightEagle to receive commands through Exchange web headers, impair Windows scanning and event logging, and redirect network traffic, turning the compromised mail server into a covert internal relay.
A .NET Microsoft Exchange server backdoor that receives commands through Exchange web headers, can weaken Windows scanning and event logging, and redirects network traffic to turn the mail server into a concealed internal relay.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.