Security News

China-Linked Hacking Group NightEagle Expands Attacks to Russian Businesses

The Record · 18 Sept 2026
Key Takeaway Businesses using Microsoft Exchange and VPN access should enforce strong credential hygiene, monitor for unusual Active Directory activity, and patch and audit Exchange servers regularly to reduce exposure to backdoor attacks like this one.

A hacking group known as NightEagle, or APT-Q-95, which has historically targeted sensitive technology and defense organisations in China, has broadened its reach to Russian businesses, according to new research from Kaspersky. The group has been active since at least 2023 and, over the past year, has been linked to several incidents at Russian companies.

In most observed cases, the attackers used stolen credentials to gain access through VPNs. Once inside a network, they targeted Microsoft Exchange email servers, installing a backdoor called GhostContainer that lets attackers remotely control compromised servers, evade certain Windows security and logging tools, and redirect network traffic. Kaspersky was unable to confirm exactly how the backdoor was first planted, but believes the group used a previously observed technique involving manipulation of Exchange encryption keys and Microsoft's web application framework.

The hackers also disguised hacking tools in GitHub repositories using names that resembled legitimate software, and exploited weaknesses in Active Directory to gain higher privileges and move across systems, ultimately attempting to compromise domain controllers. Kaspersky did not name the affected Russian organisations or the number impacted, and has not confirmed the group's motivation.

cyberespionage Microsoft Exchange APT credential theft Active Directory

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.