NightEagle, also known as APT-Q-95, has expanded its cyberespionage operations from China to Russian companies, using stolen VPN credentials, Microsoft Exchange abuse, and the GhostContainer backdoor to infiltrate networks. The group also relied on GitHub for tool storage and exploited Active Directory to deepen access, steal credentials, and attempt control of domain controllers. #NightEagle #APT-Q-95 #GhostContainer #MicrosoftExchange #ActiveDirectory #Kaspersky #QiAnXin
Keypoints
- NightEagle has expanded operations from China to Russian companies.
- The attackers used stolen VPN credentials to enter corporate networks.
- GhostContainer was installed on Microsoft Exchange servers for remote control and stealth.
- The group used GitHub repositories to hide hacking tools and supporting files.
- They exploited Active Directory to move laterally, steal credentials, and target domain controllers.
Read More: https://therecord.media/hacking-group-nighteagle-expands-russia-china