ZeroHour
Product

Dev Tunnels

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies

Kaspersky links NightEagle (APT-Q-95) intrusions in Russia to stolen VPN credentials, the GhostContainer Exchange backdoor, and Microsoft Dev Tunnels abuse.

Kaspersky's Global Emergency Response Team attributes new intrusions against Russian organizations to NightEagle (APT-Q-95), active since at least 2023 and previously focused on Asia. Initial access uses valid VPN credentials, followed by the .NET GhostContainer backdoor on Microsoft Exchange servers, which abuses ASP.NET view state injection, disables AMSI and event logging, and proxies traffic. Operators moved laterally via RDP, abused Microsoft Dev Tunnels with rdp2tcp, used Impacket atexec and netsh portproxy, and in one case exploited BlueKeep (CVE-2019-0708) to create admin accounts and attempt DCSync.

GBHackersupdated · 3h agofirst · 1d agoThreat actor in the wild 6 sourcesCVE-2019-0708CVE-2020-0688

Related CVEs

  • Unauthenticated RCE in Microsoft Remote Desktop Services (BlueKeep)
    CVE-2019-0708 is a use-after-free (CWE-416) vulnerability in Microsoft Remote Desktop Services, formerly Terminal Services, in which an unauthenticated attacker can connect to a target system over RDP and send specially crafted requests to trigger the flaw. Because the trigger requires no authentication, the flaw is wormable: a successful exploit grants remote code execution on the target host, potentially with elevated privileges, and could allow self-propagating attacks similar to WannaCry. Organizations running the affected Microsoft Remote Desktop Services, particularly legacy Windows releases still accepting inbound RDP connections, are in scope. Exploitation is confirmed in the wild: the flaw (nicknamed BlueKeep) is listed in CISA's KEV catalog (added 2021-11-03), CISA notes known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days.
    · Microsoft Remote Desktop Services KEV ransomware PoC ×4mass
  • RCE in Microsoft Exchange Server from Shared Install-Time Validation Keys
    CVE-2020-0688 is a remote code execution vulnerability in Microsoft Exchange Server caused by the validation key not being uniquely created at install time, leaving deployments with a predictable, shared key (CWE-287, improper authentication). A remote attacker who can reach an affected Exchange server and knows the common install-time key can supply maliciously crafted, cryptographically signed payloads that the server trusts, triggering code execution without needing per-server secrets. Successful exploitation gives the attacker code execution on the Exchange server, which can be used to access mail data, move laterally, and stage follow-on activity; CISA notes known use in ransomware campaigns. All organizations running the affected on-premises Microsoft Exchange Server are in scope per CISA's listing, though the affected version range is not specified in the source data. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-11-03 with known ransomware use, and EPSS rates 30-day exploitation probability at 100% (top percentile).
    · Microsoft Exchange Server KEV ransomware PoC ×2mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.