ZeroHour
GBHackerspublished ()ingested Mayura Kathir
Part of a story covered by 5 sources: “NightEagle (APT-Q-95) pivots from Asia to Russian companies with GhostContainer Exchange backdoor and Dev Tunnels abuse; Kaspersky also tracks Hacking Cat ransomware and Toy Ghouls” — merged summary and timeline →

NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies

highThreat actor exploited in the wildimportance 72CVE-2019-0708CVE-2020-0688
AI summary · glm-5.3-flash

Kaspersky links NightEagle (APT-Q-95) intrusions in Russia to stolen VPN credentials, the GhostContainer Exchange backdoor, and Microsoft Dev Tunnels abuse.

Kaspersky's Global Emergency Response Team attributes new intrusions against Russian organizations to NightEagle (APT-Q-95), active since at least 2023 and previously focused on Asia. Initial access uses valid VPN credentials, followed by the .NET GhostContainer backdoor on Microsoft Exchange servers, which abuses ASP.NET view state injection, disables AMSI and event logging, and proxies traffic. Operators moved laterally via RDP, abused Microsoft Dev Tunnels with rdp2tcp, used Impacket atexec and netsh portproxy, and in one case exploited BlueKeep (CVE-2019-0708) to create admin accounts and attempt DCSync.

  • GhostContainer .NET backdoor on Exchange executes commands, proxies traffic, and loads .NET payloads.
  • Microsoft Dev Tunnels plus rdp2tcp sustain access without opening new inbound ports.
  • BlueKeep (CVE-2019-0708) exploited in one incident; DCSync replication attempts observed.
  • Uses valid VPN credentials for initial access, reducing detection likelihood.
  • Kaspersky published detections for devtunnels.ms DNS queries, RDP events, and IoCs.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0708
Unauthenticated RCE in Microsoft Remote Desktop Services (BlueKeep)

CVE-2019-0708 is a use-after-free (CWE-416) vulnerability in Microsoft Remote Desktop Services, formerly Terminal Services, in which an unauthenticated attacker can connect to a target system over RDP and send specially crafted requests to trigger the flaw. Because the trigger requires no authentication, the flaw is wormable: a successful exploit grants remote code execution on the target host, potentially with elevated privileges, and could allow self-propagating attacks similar to WannaCry. Organizations running the affected Microsoft Remote Desktop Services, particularly legacy Windows releases still accepting inbound RDP connections, are in scope. Exploitation is confirmed in the wild: the flaw (nicknamed BlueKeep) is listed in CISA's KEV catalog (added 2021-11-03), CISA notes known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days.

Do: Apply Microsoft's security updates for CVE-2019-0708 per vendor instructions, prioritizing legacy or end-of-support Windows systems exposed to inbound RDP. As mitigation, restrict RDP (TCP 3389) to trusted networks or VPN access, require Network Level Authentication (NLA), and audit perimeter firewalls and public scans for open RDP listeners. The vulnerability is in the CISA KEV catalog, so patching is treated as a required action for federal and high-risk environments.

9.8100% KEV ransomware PoC ×4
  • Microsoft Remote Desktop Services
masson the order of millions of internet-exposed RDP endpoints and far more internal systems
CVE-2020-0688
RCE in Microsoft Exchange Server from Shared Install-Time Validation Keys

CVE-2020-0688 is a remote code execution vulnerability in Microsoft Exchange Server caused by the validation key not being uniquely created at install time, leaving deployments with a predictable, shared key (CWE-287, improper authentication). A remote attacker who can reach an affected Exchange server and knows the common install-time key can supply maliciously crafted, cryptographically signed payloads that the server trusts, triggering code execution without needing per-server secrets. Successful exploitation gives the attacker code execution on the Exchange server, which can be used to access mail data, move laterally, and stage follow-on activity; CISA notes known use in ransomware campaigns. All organizations running the affected on-premises Microsoft Exchange Server are in scope per CISA's listing, though the affected version range is not specified in the source data. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-11-03 with known ransomware use, and EPSS rates 30-day exploitation probability at 100% (top percentile).

Do: Apply Microsoft's Exchange security updates addressing CVE-2020-0688 (released in February 2020) to every on-premises Exchange server, per CISA's required action. As an interim mitigation, configure a unique ASP.NET machineKey in each Exchange server's web.config instead of the default shared install-time key, and hunt for indicators of exploitation given the known ransomware use.

8.8100% KEV ransomware PoC ×2
  • Microsoft Exchange Server
masshundreds of thousands of on-premises Exchange servers (≈500,000)

Indicators of compromiseAll →

TypeIndicatorContext
domainasp.netis a .NET-based implant designed to blend into Exchange and ASP.NET activity while providing command execution, proxying, socke
md51dcafb7f8448683281106b06dd22409at critical defensive choke points. Indicators of compromise 1dcafb7f8448683281106b06dd22409a AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exe
md51f3034b706c78b35d8e34044e68c693af compromise 1dcafb7f8448683281106b06dd22409a AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56ca
md53ecd1cd627d0340c92901a478a7caad8AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4a
md54aa9fb1bf9223dfcdac920759bc7a3c7d8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aa9fb1bf9223dfcdac920759bc7a3c7 1c-office-plugin.exe, 1cbroker.exe, trueconf.exe Note: IP a
md5631fb131a56caf4ca0f287ed73e876ab34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aa9fb1bf9223dfcdac920759bc7a3c7 1c
Full article844 words · extracted from gbhackers.com · click to collapse

The NightEagle advanced persistent threat group, tracked as APT-Q-95, has expanded its operations to target businesses in Russia, combining stolen VPN credentials, a stealthy Microsoft Exchange backdoor, and legitimate tunneling technologies to move through victim networks.

Researchers from Kaspersky’s Global Emergency Response Team said the group has been active since at least 2023 and previously concentrated on organizations across Asia.

The newly investigated intrusions show a shift in the group’s geographic targeting and an increasingly mature tradecraft designed to preserve covert access to enterprise environments.

NightEagle typically obtained initial access through compromised but valid corporate VPN credentials.

Using legitimate credentials reduces the chance that the initial login is immediately flagged as malicious, especially where multi-factor authentication, behavioral analytics, and VPN access controls are weak or inconsistently applied.

A central feature of the campaign is the deployment of the GhostContainer backdoor on Microsoft Exchange servers.

GhostContainer is a .NET-based implant designed to blend into Exchange and ASP.NET activity while providing command execution, proxying, socket forwarding, and payload-loading capabilities.

The malware combines elements adapted from publicly available projects, including Neo-reGeorg, the ExchangeCmdPy.py proof-of-concept associated with CVE-2020-0688, and GhostWebShell-related functionality from ysoserial.

This approach enables the operators to assemble a modular post-exploitation toolkit without relying entirely on custom malware code.

Earlier analysis found the implant’s components can process attacker commands, download files, launch commands, execute shellcode, and load additional .NET code.

Researchers could not confirm the exact delivery method used in the Russian incidents.

However, the activity is consistent with a known Exchange abuse technique: attackers extract ASP.NET cryptographic keys from the server configuration, manipulate the __VIEWSTATE parameter, and inject an in-memory payload that starts GhostContainer without requiring a conventional web shell file on disk.

GhostContainer’s Stub component receives encrypted command data through the x-owa-urlpostdata HTTP header.

It also attempts to neutralize security visibility by altering memory associated with the Antimalware Scan Interface and Windows Event Log functions.

Its traffic-forwarding module can create a covert bridge between the internet and internal systems, effectively turning a compromised Exchange server into an access point for deeper intrusion activity.

After gaining higher privileges, the operators used Remote Desktop Protocol to move laterally and downloaded tunneling utilities from GitHub repositories disguised as legitimate software resources.

One of the repositories used for storing network tools (Source : Kaspersky).
One of the repositories used for storing network tools (Source : Kaspersky).

Archived files and executables used names resembling Adobe, TrueConf, and 1C-related products, likely to appear benign during cursory review.

Kaspersky Researchers said that, connections originating from Russian IP space associated with Cloudflare WARP tunnels, alongside addresses tied to European virtual private server providers.

NightEagle Abuse Microsoft Dev Tunnels

The attackers paired Microsoft Dev Tunnels with the open-source rdp2tcp utility.

Microsoft Dev Tunnels can expose locally hosted services through *.devtunnels.ms domains; in this campaign, the capability was used to publish RDP access on port 3389. Meanwhile, rdp2tcp tunnels TCP traffic inside an established RDP session.

This combination is significant because it allows NightEagle to sustain access without opening conspicuous new inbound ports.


Backdoor analysis with KTAE (Source : Kaspersky).
Backdoor analysis with KTAE (Source : Kaspersky).

Defenders should examine DNS queries to devtunnels.ms, unexpected RDP exposure, and Remote Desktop Services operational logs for virtual-channel events.

Event IDs 132 and 148 containing rdp2tcp, or unusual random channel names, may indicate tunneled traffic.

NightEagle also used Impacket’s atexec utility to create scheduled tasks and configured Windows port forwarding with netsh interface portproxy.

In one incident, the group exploited CVE-2019-0708, known as BlueKeep, to create a local account and add it to the Administrators and Remote Desktop Users groups.

Alert card for the BlueKeep vulnerability exploitation (Source : Kaspersky).
Alert card for the BlueKeep vulnerability exploitation (Source : Kaspersky).

The operators further targeted Active Directory by requesting Kerberos tickets with unusual Forwardable, Proxiable, and Renewable flag combinations and attempting DCSync replication after obtaining privileged credentials.

Successful DCSync activity can expose domain password hashes and enable an attacker to impersonate a domain controller, placing the entire Active Directory environment at risk.

Organizations running on-premises Exchange should urgently review VPN logins, restrict administrative RDP access, patch legacy systems vulnerable to BlueKeep, and investigate anomalous ASP.NET and Exchange request behavior.

Monitoring for suspicious __VIEWSTATE activity, x-owa-urlpostdata headers, unexpected .NET assembly loading, netsh portproxy changes, and Dev Tunnels traffic can help expose the attack chain.

GhostContainer has previously been linked to attacks against high-value Asian organizations, where researchers described it as a customized Exchange-focused implant capable of proxying traffic and extending functionality through additional modules.  

The Russian campaign demonstrates that NightEagle is adapting those capabilities for wider espionage-oriented operations, with Exchange servers and Active Directory remaining the most critical defensive choke points.

Indicators of compromise

1dcafb7f8448683281106b06dd22409aAdobeSync.exe
1f3034b706c78b35d8e34044e68c693aadobe_32.exe
3ecd1cd627d0340c92901a478a7caad8
631fb131a56caf4ca0f287ed73e876ab
App_Web_Container_1.dll
4aa9fb1bf9223dfcdac920759bc7a3c71c-office-plugin.exe, 1cbroker.exe, trueconf.exe

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Mayura Kathirhttps://gbhackers.com/

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/nighteagle-abuse-microsoft-dev-tunnels/