ZeroHour
The Recordpublished ()ingested
Part of a story covered by 6 sources: “NightEagle (APT-Q-95) expands from Chinese high-tech targets to Russian companies with GhostContainer Exchange backdoor; Kaspersky also tracks Hacking Cat ransomware and Toy Ghouls” — merged summary and timeline →

Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia

highThreat actor exploited in the wildimportance 68
AI summary · glm-5.3-flash

Kaspersky reports the NightEagle espionage group (APT-Q-95) expanded from China-focused targets to Russian companies, backdooring Microsoft Exchange servers with GhostContainer using stolen VPN credentials.

Kaspersky investigated several incidents over the past year at Russian businesses attributed to NightEagle (APT-Q-95), a group active since at least 2023 and previously focused on Chinese defense, semiconductor, AI, and quantum technology targets. Hackers used stolen credentials to access corporate networks through VPNs, targeted Microsoft Exchange servers, and installed the GhostContainer backdoor, believed deployed by extracting Exchange encryption keys and executing the payload in memory via Microsoft's web application framework. The group stored hacking tools in GitHub repositories disguised as legitimate software such as AdobeSync and TrueConf, exploited Active Directory weaknesses for privilege escalation and lateral movement, and targeted domain controllers. Attribution remains uncertain; Chinese researchers previously associated the group with North America.

  • NightEagle active since at least 2023, previously targeting Chinese defense, semiconductor, AI, and quantum organizations
  • GhostContainer backdoor on Exchange servers evades Windows security logging and redirects network traffic
  • GitHub repositories disguised as legitimate software (AdobeSync, TrueConf) store hacking tools
  • Active Directory weaknesses exploited for privilege escalation, lateral movement, and domain controller compromise
  • Attribution uncertain; Chinese researchers previously associated the group with North America
Full article527 words · extracted from therecord.media · click to collapse

A cyberespionage group previously known for targeting sensitive technology and defense organizations in China has expanded its operations to Russian companies, according to new research released this week.

The group, known as NightEagle or APT-Q-95, has been active since at least 2023 but had previously focused its attacks in Asia. Over the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.

In most cases, the hackers used stolen credentials to gain access to corporate networks through virtual private networks, or VPNs. Once inside a network, NightEagle targeted Microsoft Exchange email servers and installed a backdoor known as GhostContainer, which allows attackers to remotely control compromised servers, evade some Windows security and logging mechanisms and redirect network traffic.

Kaspersky said it could not determine exactly how the hackers initially planted GhostContainer on the Exchange servers. Researchers believe, however, that the attackers used a technique they had observed previously that involves extracting encryption keys from Exchange and manipulating Microsoft's web application framework to execute the backdoor directly in the server's memory.

The group also used GitHub to store archives containing hacking tools, disguising repositories and files with names designed to resemble legitimate software, including AdobeSync and TrueConf.

After gaining an initial foothold, the hackers exploited weaknesses in Active Directory, Microsoft's system for managing users, computers and permissions across corporate networks, to obtain greater privileges and move between systems.

Those techniques allowed the hackers to maintain access, steal credentials and impersonate legitimate users, according to Kaspersky. The attackers ultimately tried to compromise domain controllers, or servers that play a central role in managing access across an organization's network.

"To expand the geographic scope of its targets, NightEagle is updating its methods and adopting new techniques for persistence and lateral movement," Kaspersky researchers said.

Kaspersky did not identify the Russian companies that were targeted or disclose how many organizations were affected. The company also did not specify the likely motivation behind the attacks.

NightEagle first came to public attention in July 2025, when researchers at Chinese cybersecurity company QiAnXin described a hacking operation they tracked as APT-Q-95. The researchers said the group had been active since at least 2023 and had targeted organizations in China working in strategically sensitive industries, including defense, semiconductors, artificial intelligence and quantum technology.

QiAnXin characterized the activity as cyberespionage and said the hackers had targeted Microsoft Exchange servers using what researchers at the time believed could be a previously unknown vulnerability.

The researchers dubbed the group NightEagle because its operators typically carried out attacks during nighttime hours in China and frequently changed the infrastructure they used to conduct their operations.

Chinese cybersecurity researchers have previously associated the group with North America. Those claims have not been independently confirmed by other researchers, and the group's attribution remains uncertain.

No previous article

No new articles

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/hacking-group-nighteagle-expands-russia-china