Threat Actor πΊπΈ United States
NightEagle
Also known as: APT-Q-95
NightEagle is an advanced Threat Actor that targeted China's High-Tech Industry and Military Organisation, leveraging sophisticated techniques, 0 days, and specialized detection avoiding malware. The threat actor seems to have access to significant funding, with dedicated infrastructure, and focuses on low-noise, low-impact intelligence gathering operations. NightEagle is identified as a North-American, state-sponsored or affiliated group that has been active since at least 2023.
Indicators of Compromise 13
Filename 1c-office-plugin.exe Filename 1cbroker.exe Filename AdobeSync.exe Filename App_Web_Container_1.dll Filename adobe_32.exe Filename trueconf.exe GitHub Repo browserthemes/resourcepack GitHub Repo mirror-js/mirror-js MD5 1dcafb7f8448683281106b06dd22409a MD5 1f3034b706c78b35d8e34044e68c693a MD5 3ecd1cd627d0340c92901a478a7caad8 MD5 4aa9fb1bf9223dfcdac920759bc7a3c7 MD5 631fb131a56caf4ca0f287ed73e876ab
MITRE ATT&CK TTPs 10
T1021.001 T1055.001 T1078 T1090 T1110 T1550.002 T1566 T1570 T1589 T1595.002
Remote Desktop Protocol
Lateral Movement
Dynamic-link Library Injection
Defense Evasion
Valid Accounts
Defense Evasion
Proxy
Command And Control
Brute Force
Credential Access
Pass the Hash
Defense Evasion
Phishing
Initial Access
Lateral Tool Transfer
Lateral Movement
Gather Victim Identity Information
Reconnaissance
Vulnerability Scanning
Reconnaissance