CVE Tools

Кибершпионы NightEagle нацелились на производственные и строительные предприятия в России

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedMicrosoft ExchangeNightEagleActive Directory

Our summary

Kaspersky researchers report that NightEagle (APT-Q-95) has targeted Russian manufacturing and construction organizations, marking its first known activity outside Asia. The group used compromised VPN accounts to enter networks, deployed the GhostContainer backdoor on Microsoft Exchange servers, and used tunneling tools to retain covert access. Attackers also abused Active Directory weaknesses and unpatched systems, including CVE-2019-0708, to gain administrator access, extract domain credential hashes, and potentially take over domain controllers.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store