CVE Tools
Back to feed
Incident Exchange Server NightEagle nation-state Microsoft malware

NightEagle APT targets Russian organizations

Kaspersky Securelist·By by Stanislav Larinsky, Kaspersky Security Services··6 min read
CVE Tools coverage

Kaspersky reports that the NightEagle APT group targeted Russian organizations, using stolen VPN credentials and deploying the GhostContainer backdoor on Microsoft Exchange Server. The attackers used Microsoft dev tunnels, rdp2tcp, and Active Directory techniques to sustain access and move through victim networks, while exploiting CVE-2019-0708 (BlueKeep) in at least one incident. The activity can lead to domain controller compromise and exposure of the wider Active Directory environment.

Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia, as we reported previously. We have now identified attacks by the group targeting businesses in Russia. This post examines both known and new tools NightEagle used in its latest campaign.…

Continue reading on Kaspersky Securelist