Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russianew
Kaspersky reports the NightEagle espionage group (APT-Q-95) expanded from China-focused targets to Russian companies, backdooring Microsoft Exchange servers with GhostContainer using stolen VPN credentials.
Kaspersky investigated several incidents over the past year at Russian businesses attributed to NightEagle (APT-Q-95), a group active since at least 2023 and previously focused on Chinese defense, semiconductor, AI, and quantum technology targets. Hackers used stolen credentials to access corporate networks through VPNs, targeted Microsoft Exchange servers, and installed the GhostContainer backdoor, believed deployed by extracting Exchange encryption keys and executing the payload in memory via Microsoft's web application framework. The group stored hacking tools in GitHub repositories disguised as legitimate software such as AdobeSync and TrueConf, exploited Active Directory weaknesses for privilege escalation and lateral movement, and targeted domain controllers. Attribution remains uncertain; Chinese researchers previously associated the group with North America.