NightEagle APT Expands Operations, Targets Russian Enterprises with GhostContainer Backdoor
A sophisticated cyberespionage group, previously known as **NightEagle** or **APT-Q-95**, has broadened its attack scope from sensitive Chinese technology and defense sectors to include Russian companies. New research from **Kaspersky** details how the group leverages stolen credentials, exploits **Microsoft Exchange** servers with a custom backdoor called **GhostContainer**, and abuses legitimate platforms like **GitHub** for its operations.
A cyberespionage group known as **NightEagle** (also tracked as **APT-Q-95**) has significantly expanded its operational reach, moving beyond its initial focus on sensitive technology and defense organizations in China to target Russian enterprises.
Active since at least 2023, **NightEagle**'s shift in focus was highlighted by Russian cybersecurity firm **Kaspersky**, which has investigated several incidents involving the group at various Russian businesses over the past year.
### Infiltration and Persistent Access
In most observed cases, the attackers initiated their compromise by using stolen credentials to gain access to corporate networks via Virtual Private Networks (VPNs). Once inside, **NightEagle** primarily targeted **Microsoft Exchange** email servers.
On these servers, the group deployed a custom backdoor known as **GhostContainer**. This sophisticated malware provides attackers with remote control over compromised servers, enables them to evade certain Windows security and logging mechanisms, and facilitates the redirection of network traffic.
While the exact method for the initial deployment of **GhostContainer** on **Exchange** servers remains elusive, researchers speculate that the attackers may be using a previously observed technique. This involves extracting encryption keys from **Exchange** and manipulating **Microsoft**'s web application framework to execute the backdoor directly in the server's memory.
### Exploiting Active Directory and GitHub
Beyond the initial foothold, **NightEagle** exploits weaknesses in **Active Directory**, **Microsoft**'s system for managing user identities and permissions across corporate networks. This allows them to escalate privileges and move laterally across systems.
These techniques are crucial for maintaining persistent access, stealing additional credentials, and impersonating legitimate users. Ultimately, the attackers aim to compromise domain controllers, which are central to managing access across an organization's entire network.
The group also abuses legitimate platforms, specifically **GitHub**, to host archives of their hacking tools. These repositories and files are often disguised with names designed to mimic legitimate software, such as "AdobeSync" and "TrueConf," to avoid detection.
### Evolving Tactics and Uncertain Attribution
**Kaspersky** researchers noted that "To expand the geographic scope of its targets, **NightEagle** is updating its methods and adopting new techniques for persistence and lateral movement."
Details regarding the specific Russian companies targeted or the total number of affected organizations have not been disclosed by **Kaspersky**, nor has the likely motivation behind these new attacks been specified.
**NightEagle** first came to public attention in July 2023, when Chinese cybersecurity company **QiAnXin** described the group's activities. At that time, **QiAnXin**'s researchers, who tracked the group as **APT-Q-95**, reported that it had been active since at least 2023, targeting strategically sensitive industries in China, including defense, semiconductors, artificial intelligence, and quantum technology.
**QiAnXin** characterized these early operations as cyberespionage, noting that the group had also targeted **Microsoft Exchange** servers, potentially leveraging a previously unknown vulnerability. The name **NightEagle** was coined due to the operators' tendency to conduct attacks during nighttime hours in China and their frequent changes to their operational infrastructure.
While some Chinese cybersecurity researchers have previously linked the group to North America, these claims remain unconfirmed by other researchers, and the ultimate attribution of **NightEagle** continues to be uncertain.