NightEagle targets Russian companies
AI Summary
NightEagle (APT-Q-95), an advanced persistent threat group active since at least 2023, has expanded its targeting to include Russian organizations. The group initially gains access using compromised credentials and leverages Cloudflare WARP tunnels and European VPS infrastructure. They deploy a .NET-based backdoor called GhostContainer on Microsoft Exchange servers, exploiting CVE-2020-0688 and utilizing cryptographic key extraction from ASP.NET configurations. The backdoor enables command-and-control communication and traffic redirection via proxying. Attackers use legitimate tools such as Microsoft dev tunnels, rdp2tcp, and Impacket utilities for lateral movement and persistence, including exploitation of CVE-2019-0708 (BlueKeep) and DCSync attacks in Active Directory.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 13 extracted
| Type | Value | Detail |
|---|---|---|
| MD5 | 1dcafb7f8448683281106b06dd22409a | Details → |
| Filename | AdobeSync.exe | Details → |
| MD5 | 1f3034b706c78b35d8e34044e68c693a | Details → |
| Filename | adobe_32.exe | Details → |
| MD5 | 3ecd1cd627d0340c92901a478a7caad8 | Details → |
| MD5 | 631fb131a56caf4ca0f287ed73e876ab | Details → |
| Filename | App_Web_Container_1.dll | Details → |
| MD5 | 4aa9fb1bf9223dfcdac920759bc7a3c7 | Details → |
| Filename | 1c-office-plugin.exe | Details → |
| Filename | 1cbroker.exe | Details → |
| Filename | trueconf.exe | Details → |
| GitHub Repo | mirror-js/mirror-js | Details → |
| GitHub Repo | browserthemes/resourcepack | Details → |