CVE Tools

NightEagle APT targets Russian organizations

Kaspersky SecurelistBy by Stanislav Larinsky, Kaspersky Security Services6 min read

IncidentExchange ServerNightEagle

Our summary

Kaspersky reports that the NightEagle APT group targeted Russian organizations, using stolen VPN credentials and deploying the GhostContainer backdoor on Microsoft Exchange Server. The attackers used Microsoft dev tunnels, rdp2tcp, and Active Directory techniques to sustain access and move through victim networks, while exploiting CVE-2019-0708 (BlueKeep) in at least one incident. The activity can lead to domain controller compromise and exposure of the wider Active Directory environment.

Read at Kaspersky Securelist

Below is the opening; the full story is at Kaspersky Securelist.

From Kaspersky Securelist

Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia, as we reported previously. We have now identified attacks by the group targeting businesses in Russia. This post examines both known and new tools NightEagle used in its latest campaign.…

Continue at Kaspersky Securelist

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store