NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
NightEagle (APT-Q-95) breached Russian firms using stolen VPN credentials, a GhostContainer Exchange backdoor, Dev Tunnels abuse, and DCSync.
Kaspersky's Securelink analysts, via Securelist, documented NightEagle (APT-Q-95) attacks on Russian companies that begin with VPN logins using stolen valid credentials from Cloudflare WARP and European infrastructure. On Exchange servers the group deployed GhostContainer, a .NET backdoor built from public components including Neo-reGeorg tunneling, CVE-2020-0688 logic, and the GhostWebShell class, controlled through Exchange web headers. The operators exposed RDP through Microsoft Dev Tunnels paired with rdp2tcp, staged tools in GitHub repositories, and exploited BlueKeep (CVE-2019-0708) to create admin accounts before running DCSync against Active Directory.
- Initial access via stolen VPN credentials from WARP tunnels and European VPS
- GhostContainer .NET backdoor on Exchange embeds Neo-reGeorg, CVE-2020-0688, GhostWebShell
- Microsoft Dev Tunnels and rdp2tcp expose RDP without conspicuous new listening ports
- BlueKeep (CVE-2019-0708) exploited to create local admin accounts; DCSync harvests credentials
- Toolsets hosted in GitHub repositories disguised as legitimate software
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-0708 | Unauthenticated RCE in Microsoft Remote Desktop Services (BlueKeep) CVE-2019-0708 is a use-after-free (CWE-416) vulnerability in Microsoft Remote Desktop Services, formerly Terminal Services, in which an unauthenticated attacker can connect to a target system over RDP and send specially crafted requests to trigger the flaw. Because the trigger requires no authentication, the flaw is wormable: a successful exploit grants remote code execution on the target host, potentially with elevated privileges, and could allow self-propagating attacks similar to WannaCry. Organizations running the affected Microsoft Remote Desktop Services, particularly legacy Windows releases still accepting inbound RDP connections, are in scope. Exploitation is confirmed in the wild: the flaw (nicknamed BlueKeep) is listed in CISA's KEV catalog (added 2021-11-03), CISA notes known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. Do: Apply Microsoft's security updates for CVE-2019-0708 per vendor instructions, prioritizing legacy or end-of-support Windows systems exposed to inbound RDP. As mitigation, restrict RDP (TCP 3389) to trusted networks or VPN access, require Network Level Authentication (NLA), and audit perimeter firewalls and public scans for open RDP listeners. The vulnerability is in the CISA KEV catalog, so patching is treated as a required action for federal and high-risk environments. | 9.8 | 100% | KEV ransomware PoC ×4 |
| masson the order of millions of internet-exposed RDP endpoints and far more internal systems | |
| CVE-2020-0688 | RCE in Microsoft Exchange Server from Shared Install-Time Validation Keys CVE-2020-0688 is a remote code execution vulnerability in Microsoft Exchange Server caused by the validation key not being uniquely created at install time, leaving deployments with a predictable, shared key (CWE-287, improper authentication). A remote attacker who can reach an affected Exchange server and knows the common install-time key can supply maliciously crafted, cryptographically signed payloads that the server trusts, triggering code execution without needing per-server secrets. Successful exploitation gives the attacker code execution on the Exchange server, which can be used to access mail data, move laterally, and stage follow-on activity; CISA notes known use in ransomware campaigns. All organizations running the affected on-premises Microsoft Exchange Server are in scope per CISA's listing, though the affected version range is not specified in the source data. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-11-03 with known ransomware use, and EPSS rates 30-day exploitation probability at 100% (top percentile). Do: Apply Microsoft's Exchange security updates addressing CVE-2020-0688 (released in February 2020) to every on-premises Exchange server, per CISA's required action. As an interim mitigation, configure a unique ASP.NET machineKey in each Exchange server's web.config instead of the default shared install-time key, and hunt for indicators of exploitation given the known ransomware use. | 8.8 | 100% | KEV ransomware PoC ×2 |
| masshundreds of thousands of on-premises Exchange servers (≈500,000) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | github.com | v Tunnels endpoint pattern abused to expose RDP URL https://github[.]com/mirror-js/mirror-js/refs/heads/main/js/js-webpack.zip Arc |
| md5 | 1dcafb7f8448683281106b06dd22409a | of compromise (IoCs):- Type Indicator Description MD5 hash 1dcafb7f8448683281106b06dd22409a Associated with AdobeSync.exe MD5 hash 1f3034b706c78b35d8e3 |
| md5 | 1f3034b706c78b35d8e34044e68c693a | 683281106b06dd22409a Associated with AdobeSync.exe MD5 hash 1f3034b706c78b35d8e34044e68c693a Associated with adobe_32.exe MD5 hash 3ecd1cd627d0340c92901 |
| md5 | 3ecd1cd627d0340c92901a478a7caad8 | 78b35d8e34044e68c693a Associated with adobe_32.exe MD5 hash 3ecd1cd627d0340c92901a478a7caad8 Associated with App_Web_Container_1.dll MD5 hash 631fb131a5 |
| md5 | 4aa9fb1bf9223dfcdac920759bc7a3c7 | ed73e876ab Associated with App_Web_Container_1.dll MD5 hash 4aa9fb1bf9223dfcdac920759bc7a3c7 Associated with 1c-office-plugin.exe , 1cbroker.exe , and t |
| md5 | 631fb131a56caf4ca0f287ed73e876ab | 478a7caad8 Associated with App_Web_Container_1.dll MD5 hash 631fb131a56caf4ca0f287ed73e876ab Associated with App_Web_Container_1.dll MD5 hash 4aa9fb1bf9 |
Full article916 words · extracted from cybersecuritynews.com · click to collapse
NightEagle, also tracked as APT-Q-95, has expanded its operations against Russian businesses with a campaign built around stolen VPN credentials, a Microsoft Exchange backdoor, and covert remote-access routes.
The activity shows how an intruder can turn everyday administration features and publicly available code into a path through a corporate network. The group has been active since at least 2023 and previously concentrated on organizations in Asia.
In the newly documented incidents, it entered corporate VPNs with valid compromised accounts, then worked to gain deeper access, maintain control, and reach critical identity systems. Securelist analysts identified the campaign after investigating several incidents.
Kaspersky said in a report shared with Cyber Security News (CSN) that NightEagle paired the GhostContainer backdoor with tunnel tools to keep access while avoiding the obvious signs created by opening new external ports.
The danger is not confined to a single malicious file or one exposed service. By combining a server-side backdoor, remote desktop connections, credential theft, and Active Directory abuse, the operators could move from one compromised machine to the systems that manage a company’s users and permissions.
NightEagle Hackers Abuse Microsoft Dev Tunnels
The attack commonly began with a successful VPN login using stolen credentials. The source connections came from Russian IP addresses associated with Cloudflare WARP tunnels and from European virtual infrastructure providers, blending the first stage into traffic that may not immediately look hostile.
On Microsoft Exchange servers, the attackers deployed GhostContainer, a .NET backdoor assembled from public components. It includes elements connected to the Neo-reGeorg tunnel, code for CVE-2020-0688, and the GhostWebShell class.
.webp)
Researchers could not confirm delivery, but assessed that the attackers likely extracted Exchange cryptographic keys, altered VIEWSTATE, and launched the payload in memory.
GhostContainer can receive commands through Exchange web headers, weaken Windows scanning and event logging, and redirect network traffic. This makes a mail server a concealed relay inside the victim environment.
The pattern adds urgency to Exchange server exposure concerns, especially where internet-facing systems are not closely watched.
After obtaining sufficient privileges, the operators used Microsoft Dev Tunnels to publish the compromised system’s RDP service through tunnel-service addresses.
They then combined it with rdp2tcp, an open-source utility that carries TCP traffic through an existing RDP connection. That pairing helps the attackers retain a route into the network without creating a conspicuous new listening port.
It also reflects a broader trend previously seen in earlier Dev Tunnels abuse, where a legitimate developer feature is repurposed for concealed command-and-control traffic rather than testing.
Lateral Movement and Detection
The attackers hosted compressed toolsets in GitHub repositories whose names and archive labels were made to appear legitimate. Files inside were also disguised as familiar software.
They used the atexec tool to create scheduled tasks and Windows port-forwarding rules, extending their reach through normal system functions.
NightEagle then targeted Active Directory, the service that controls accounts and permissions across many Windows networks.
In one incident, it exploited BlueKeep, CVE-2019-0708, to create a local account and place it in the Administrators and Remote Desktop Users groups. Organizations should treat patching and exposed RDP port risks as linked priorities.
The group also requested Kerberos tickets with an unusual set of flags, then attempted DCSync after gaining a sufficiently privileged account.
.webp)
DCSync imitates a domain controller to request password material from Active Directory. Successful use can give an attacker long-lived access and control of the domain, as explained in understanding DCSync credential theft.
Defenders should investigate unusual VPN logins, unauthorized tunnel-service DNS lookups, new scheduled tasks, suspicious Exchange memory activity, and RDP virtual-channel events 132 and 148 containing rdp2tcp or unexpected random names.
They should promptly patch vulnerable systems, protect VPN accounts with strong multi-factor authentication, restrict remote access, and watch for abnormal directory replication requests.
The campaign demonstrates that familiar tools do not make an intrusion harmless. Careful monitoring of identity, Exchange, RDP, and network forwarding activity can reveal the chain before attackers turn a foothold into broad control of the organization.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| MD5 hash | 1dcafb7f8448683281106b06dd22409a | Associated with AdobeSync.exe |
| MD5 hash | 1f3034b706c78b35d8e34044e68c693a | Associated with adobe_32.exe |
| MD5 hash | 3ecd1cd627d0340c92901a478a7caad8 | Associated with App_Web_Container_1.dll |
| MD5 hash | 631fb131a56caf4ca0f287ed73e876ab | Associated with App_Web_Container_1.dll |
| MD5 hash | 4aa9fb1bf9223dfcdac920759bc7a3c7 | Associated with 1c-office-plugin.exe, 1cbroker.exe, and trueconf.exe |
| File name | adobe_32.exe | Disguised tool filename |
| File name | AdobeSync.exe | Disguised tool filename |
| File name | trueconf.exe | Disguised tool filename |
| File name | 1cbroker.exe | Disguised tool filename |
| File name | 1c-office-plugin.exe | Disguised tool filename |
| File name | trueconf-broker.exe | Disguised tool filename |
| File name | App_Web_Container_1.dll | GhostContainer-related DLL |
| Domain pattern | *.*.devtunnels.ms | Microsoft Dev Tunnels endpoint pattern abused to expose RDP |
| URL | https://github[.]com/mirror-js/mirror-js/refs/heads/main/js/js-webpack.zip | Archive used to host network tools |
| URL | https://github[.]com/mirror-js/mirror-js/refs/heads/main/js/jsonp-pack.zip | Archive used to host network tools |
| URL | https://github[.]com/browserthemes/resourcepack/releases/download/main/resource-pack.zip | Archive used to host network tools |
| URL | https://github[.]com/mirror-js/mirror-js | Repository used to store network tools |
| URL | https://github[.]com/browserthemes/resourcepack | Repository used to store network tools |
| IP address | 10.0.12.101 | Internal address referenced in a port-forwarding command |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/nighteagle-hackers/