securelist · Crawled Sep 16, 2026

NightEagle targets Russian companies

13 IoCs 1 Actors
Read original article ↗

AI Summary

NightEagle (APT-Q-95), an advanced persistent threat group active since at least 2023, has expanded its targeting to include Russian organizations. The group initially gains access using compromised credentials and leverages Cloudflare WARP tunnels and European VPS infrastructure. They deploy a .NET-based backdoor called GhostContainer on Microsoft Exchange servers, exploiting CVE-2020-0688 and utilizing cryptographic key extraction from ASP.NET configurations. The backdoor enables command-and-control communication and traffic redirection via proxying. Attackers use legitimate tools such as Microsoft dev tunnels, rdp2tcp, and Impacket utilities for lateral movement and persistence, including exploitation of CVE-2019-0708 (BlueKeep) and DCSync attacks in Active Directory.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 13 extracted

Type Value Detail
MD5 1dcafb7f8448683281106b06dd22409a Details →
Filename AdobeSync.exe Details →
MD5 1f3034b706c78b35d8e34044e68c693a Details →
Filename adobe_32.exe Details →
MD5 3ecd1cd627d0340c92901a478a7caad8 Details →
MD5 631fb131a56caf4ca0f287ed73e876ab Details →
Filename App_Web_Container_1.dll Details →
MD5 4aa9fb1bf9223dfcdac920759bc7a3c7 Details →
Filename 1c-office-plugin.exe Details →
Filename 1cbroker.exe Details →
Filename trueconf.exe Details →
GitHub Repo mirror-js/mirror-js Details →
GitHub Repo browserthemes/resourcepack Details →

MITRE ATT&CK TTPs 10 techniques