China-Linked Hacking Group NightEagle Expands Attacks to Russian Businesses
A hacking group known as NightEagle, or APT-Q-95, which has historically targeted sensitive technology and defense organisations in China, has broadened its reach to Russian businesses, according to new research from Kaspersky. The group has been active since at least 2023 and, over the past year, has been linked to several incidents at Russian companies.
In most observed cases, the attackers used stolen credentials to gain access through VPNs. Once inside a network, they targeted Microsoft Exchange email servers, installing a backdoor called GhostContainer that lets attackers remotely control compromised servers, evade certain Windows security and logging tools, and redirect network traffic. Kaspersky was unable to confirm exactly how the backdoor was first planted, but believes the group used a previously observed technique involving manipulation of Exchange encryption keys and Microsoft's web application framework.
The hackers also disguised hacking tools in GitHub repositories using names that resembled legitimate software, and exploited weaknesses in Active Directory to gain higher privileges and move across systems, ultimately attempting to compromise domain controllers. Kaspersky did not name the affected Russian organisations or the number impacted, and has not confirmed the group's motivation.