Кибершпионы NightEagle нацелились на производственные и строительные предприятия в России
Reported exploitedMicrosoft ExchangeNightEagleActive DirectoryOur summary
Kaspersky researchers report that NightEagle (APT-Q-95) has targeted Russian manufacturing and construction organizations, marking its first known activity outside Asia. The group used compromised VPN accounts to enter networks, deployed the GhostContainer backdoor on Microsoft Exchange servers, and used tunneling tools to retain covert access. Attackers also abused Active Directory weaknesses and unpatched systems, including CVE-2019-0708, to gain administrator access, extract domain credential hashes, and potentially take over domain controllers.
Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.