NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
Kaspersky links NightEagle (APT-Q-95) intrusions in Russia to stolen VPN credentials, the GhostContainer Exchange backdoor, and Microsoft Dev Tunnels abuse.
Kaspersky's Global Emergency Response Team attributes new intrusions against Russian organizations to NightEagle (APT-Q-95), active since at least 2023 and previously focused on Asia. Initial access uses valid VPN credentials, followed by the .NET GhostContainer backdoor on Microsoft Exchange servers, which abuses ASP.NET view state injection, disables AMSI and event logging, and proxies traffic. Operators moved laterally via RDP, abused Microsoft Dev Tunnels with rdp2tcp, used Impacket atexec and netsh portproxy, and in one case exploited BlueKeep (CVE-2019-0708) to create admin accounts and attempt DCSync.