ZeroHour

Search: “virtual patching”

72 stories

NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies

NightEagle (APT-Q-95) breached Russian firms using stolen VPN credentials, a GhostContainer Exchange backdoor, Dev Tunnels abuse, and DCSync.

Kaspersky's Securelink analysts, via Securelist, documented NightEagle (APT-Q-95) attacks on Russian companies that begin with VPN logins using stolen valid credentials from Cloudflare WARP and European infrastructure. On Exchange servers the group deployed GhostContainer, a .NET backdoor built from public components including Neo-reGeorg tunneling, CVE-2020-0688 logic, and the GhostWebShell class, controlled through Exchange web headers. The operators exposed RDP through Microsoft Dev Tunnels paired with rdp2tcp, staged tools in GitHub repositories, and exploited BlueKeep (CVE-2019-0708) to create admin accounts before running DCSync against Active Directory.

New Python-Based Payload MechaFlounder Used by Chafer

Unit 42 identified MechaFlounder, a new Python backdoor used by the Chafer group to target a Turkish government entity via HTTP-based C2.

Unit 42 reports that in November 2018 the Chafer group targeted a Turkish government entity, reusing the win10-update[.]com infrastructure reported earlier in 2018 by ClearSky. The new secondary payload, tracked as MechaFlounder, is Python compiled with PyInstaller and acts as a backdoor supporting file upload/download and command execution. It beacons over HTTP using anomalous GET requests containing the username and hostname, suggesting a custom C2 server rather than a standard web server. Code overlap with OilRig's Clayside VBScript was noted, but Chafer and OilRig remain tracked as separate groups.

Palo Alto Unit 42 · Aug 17, 2026Threat actor

Details emerge on BlackFile's recent attacks on financial companies

BlackFile (UNC6671), a The Com-linked extortion crew, keeps hitting financial and med tech firms with voice-phishing IT-support scams and ~$3 million demands.

Google Threat Intelligence Group (tracking BlackFile as UNC6671, linked to The Com) reports the extortion group remains active, shifting focus to the financial sector and med tech organizations, with new Redact-brand extortion demands issued last week. The group impersonates IT support in voice-phishing attacks using hundreds of recruited callers, targets large firms in what researchers call big-game hunting, and processes an average of 1.5 new victims daily. Extortion demands start around $3 million and are typically negotiated below $1 million; Flashpoint observed infrastructure targeting Blackstone, Bain Capital, Moody's, CME, and Apollo, though compromise is unconfirmed. Mandiant has responded to more than two dozen BlackFile compromises since January, and victims face escalation tactics including swatting.

CyberScoop · Aug 17, 2026Threat actor in the wild