NightEagle (APT-Q-95), active since at least 2023 and previously focused on Asian targets, has expanded operations against Russian businesses. The group obtained initial access primarily through compromised corporate VPN credentials, deployed the GhostContainer backdoor on Microsoft Exchange servers, and used tunneling infrastructure to preserve access and support RDP-based lateral movement.
In observed intrusions, the actors abused Active Directory weaknesses, targeted CVE-2019-0708 (BlueKeep), attempted Kerberos ticket abuse and DCSync activity, and pursued domain-controller and full Active Directory compromise. The campaign combines custom malware with public tools, legitimate Microsoft development tunnels, and native Windows port-forwarding capabilities to reduce detection opportunities.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
NightEagle, also tracked as APT-Q-95, has been active since at least 2023 and was previously focused on organizations in Asia.
Researchers reported that NightEagle used Impacket atexec to create scheduled tasks and netsh interface portproxy to forward internal traffic, in addition to dev tunnels and rdp2tcp. The report also identified GitHub repositories masquerading as legitimate resources and hashes for AdobeSync.exe and adobe_32.exe.
Researchers reported confirmed GhostContainer activity affecting a government agency and a high-tech company in Asia. They assessed that the Exchange compromise likely involved a known N-day flaw, possibly CVE-2020-0688, although the initial-access attribution remained inconclusive.
Researchers disclosed that GhostContainer receives commands through the x-owa-urlpostdata HTTP header and bypasses AMSI and Windows Event Log mechanisms by overwriting addresses in amsi.dll and ntdll.dll. They also assessed that NightEagle likely abused Exchange ASP.NET cryptographic keys and the VIEWSTATE parameter to launch the payload in memory.
In one observed incident, NightEagle exploited CVE-2019-0708 (BlueKeep) to create and elevate a local account. The group also abused Kerberos ticket requests and attempted DCSync activity in pursuit of domain-controller and Active Directory compromise.
The group used Microsoft dev tunnels to expose RDP and rdp2tcp to tunnel traffic through established RDP sessions, enabling access and lateral movement while avoiding additional suspicious open ports.
During observed intrusions, NightEagle deployed the GhostContainer .NET backdoor on Microsoft Exchange servers, using it for command handling, proxying, virtual-path redirection, and socket forwarding.
NightEagle expanded its operations to target businesses in Russia, commonly using compromised valid credentials to access corporate VPNs.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcesecurelist.ru
Open sourcesecurelist.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.