NightEagle APT targets Russian organizations
Kaspersky reports that the NightEagle APT group targeted Russian organizations, using stolen VPN credentials and deploying the GhostContainer backdoor on Microsoft Exchange Server. The attackers used Microsoft dev tunnels, rdp2tcp, and Active Directory techniques to sustain access and move through victim networks, while exploiting CVE-2019-0708 (BlueKeep) in at least one incident. The activity can lead to domain controller compromise and exposure of the wider Active Directory environment.
Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia, as we reported previously. We have now identified attacks by the group targeting businesses in Russia. This post examines both known and new tools NightEagle used in its latest campaign.…