Skip to content
NightEagle APT Targets Russian Enterprises with GhostContainer Backdoor

NightEagle APT Targets Russian Enterprises with GhostContainer Backdoor

First seen 16 Sep 2026, 16:30 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 16:33 UTC
  • NightEagle APT targets Russian organizations using GhostContainer backdoor.
  • Attacks exploit compromised VPN credentials and involve lateral movement techniques.
  • GhostContainer utilizes components from open-source projects to evade detection.

The NightEagle group (APT-Q-95) has expanded its operations to target Russian enterprises, utilizing compromised valid credentials to access corporate VPNs. Recent attacks involved deploying the GhostContainer backdoor on Microsoft Exchange servers, which allows for full control over the system. The attackers employed techniques such as extracting cryptographic keys from ASP.NET configurations and injecting malicious payloads. The backdoor, which incorporates components from open-source projects, enables lateral movement within networks using tools for tunneling and traffic redirection. Kaspersky has confirmed that these attacks also exploit vulnerabilities in Active Directory, aiming to establish persistence and access sensitive data. The group has been active since at least 2023, previously focusing on Asian organizations. Current investigations are ongoing to assess the full scope of the impact.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2019-05-16
CVE-2019-0708 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-03-02
CVE-2021-26855 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-01-01
NightEagle APT identified
NightEagle group began operations, initially targeting organizations in Asia.
Securelist
2025-07-01
NightEagle attacks highlighted
Kaspersky reported on NightEagle's evolving tactics and targets, including Russian enterprises.
Thehackernews
2026-05-14
CVE-2026-42897 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-15
CVE-2020-0688 added to CISA KEV
CISA listed CVE-2020-0688 for active exploitation, relevant to NightEagle's tactics.
Known CVE Dates
2026-09-16
Current attacks reported
Kaspersky confirms ongoing NightEagle attacks against Russian enterprises using GhostContainer.
Securelist

More articles in this cluster (2)