Exploited in the wild Microsoft Exchange NightEagle nation-state Active Directory Microsoft
Кибершпионы NightEagle нацелились на производственные и строительные предприятия в России
CVE Tools coverage
Kaspersky researchers report that NightEagle (APT-Q-95) has targeted Russian manufacturing and construction organizations, marking its first known activity outside Asia. The group used compromised VPN accounts to enter networks, deployed the GhostContainer backdoor on Microsoft Exchange servers, and used tunneling tools to retain covert access. Attackers also abused Active Directory weaknesses and unpatched systems, including CVE-2019-0708, to gain administrator access, extract domain credential hashes, and potentially take over domain controllers.