CVE Tools
Back to feed
Exploited in the wild Microsoft Exchange NightEagle nation-state Active Directory Microsoft

Кибершпионы NightEagle нацелились на производственные и строительные предприятия в России

Хакер (xakep.ru)·By Мария Нефёдова··2 min read
CVE Tools coverage

Kaspersky researchers report that NightEagle (APT-Q-95) has targeted Russian manufacturing and construction organizations, marking its first known activity outside Asia. The group used compromised VPN accounts to enter networks, deployed the GhostContainer backdoor on Microsoft Exchange servers, and used tunneling tools to retain covert access. Attackers also abused Active Directory weaknesses and unpatched systems, including CVE-2019-0708, to gain administrator access, extract domain credential hashes, and potentially take over domain controllers.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store