NightEagle (APT-Q-95) Expands from Chinese High-Tech Targets to Russian Companies Using GhostContainer Exchange Backdoor and Microsoft Dev Tunnels
Kaspersky attributes intrusions at Russian companies over the past year to the NightEagle espionage group (APT-Q-95), which used stolen VPN credentials, the .NET GhostContainer backdoor on Microsoft Exchange, BlueKeep (CVE-2019-0708) exploitation, DCSync, and…
Kaspersky (its Global Emergency Response Team, reported via Securelist/Securelink analysts) investigated several incidents at Russian businesses over the past year and attributed them to NightEagle (APT-Q-95), a group active since at least 2023. Most reports say the group previously focused on Asian organizations; The Record specifies Chinese defense, semiconductor, AI, and quantum technology targets and notes attribution is uncertain, with Chinese researchers previously associating the group with North America. Initial access came via stolen, valid VPN credentials — Cyber Security News says these derived from Cloudflare WARP and European VPS infrastructure. On Microsoft Exchange servers the operators deployed GhostContainer, a .NET backdoor that reuses code from Neo-reGeorg, ExchangeCmdPy.py (CVE-2020-0688 view state logic), ysoserial, and the GhostWebShell class, is controlled via Exchange web headers, and was reportedly deployed by extracting Exchange encryption keys and executing the payload in memory via Microsoft's web application framework. GhostContainer tampers with AMSI and Windows event logging to evade detection and redirects/proxies network traffic. For lateral movement and persistence, the group abused Microsoft Dev Tunnels paired with rdp2tcp to expose RDP without conspicuous new listening ports, used Impacket atexec and netsh portproxy, and staged tools in GitHub repositories disguised as legitimate software such as AdobeSync and TrueConf. In one incident, operators exploited BlueKeep (CVE-2019-0708) to create an administrator account, then performed or attempted DCSync replication against Active Directory to harvest domain password hashes, moving toward domain controller compromise. Sources disagree on one point: GBHackers' September 21 follow-up describes BlueKeep as the initial access vector, while the other reports state initial access was via stolen VPN credentials, with BlueKeep exploited in a single incident for privilege escalation.
- Attributed by Kaspersky to NightEagle (APT-Q-95), active since at least 2023 and previously focused on Asia — specifically Chinese defense, semiconductor, AI, and quantum organizations per The Record; attribution remains uncertain and…
- Initial access via stolen valid VPN credentials, reportedly sourced from Cloudflare WARP tunnels and European VPS infrastructure (Cyber Security News).
- GhostContainer is a .NET backdoor deployed on Microsoft Exchange servers, reusing code from Neo-reGeorg, ExchangeCmdPy.py (CVE-2020-0688 logic), ysoserial, and the GhostWebShell class, controlled through Exchange web headers; it tampers…
Coverage timelineoldest first · each row is one article
- · 10d agoNightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
GBHackers· 72
Kaspersky links NightEagle (APT-Q-95) intrusions in Russia to stolen VPN credentials, the GhostContainer Exchange backdoor, and Microsoft Dev Tunnels abuse.
- · 10d agoNightEagle Hackers Target Russian Companies Using GhostContainer Backdoor
GBHackers· 74
Kaspersky links NightEagle (APT-Q-95) intrusions in Russia to stolen VPN credentials, the GhostContainer Exchange backdoor, BlueKeep exploitation, and covert tunneling for espionage.
Vulnerabilities in this storyAll →
- CVE-2019-07089.8100%Unauthenticated RCE in Microsoft Remote Desktop Services (BlueKeep)published · Microsoft Remote Desktop Services KEV ransomware PoC ×4