Thehackernews NightEagle APT Targets Russian Enterprises with GhostContainer Backdoor
Article Content
- •NightEagle APT targets Russian organizations using GhostContainer backdoor.
- •Attacks exploit compromised VPN credentials and involve lateral movement techniques.
- •GhostContainer utilizes components from open-source projects to evade detection.
The NightEagle group (APT-Q-95) has expanded its operations to target Russian enterprises, utilizing compromised valid credentials to access corporate VPNs. Recent attacks involved deploying the GhostContainer backdoor on Microsoft Exchange servers, which allows for full control over the system. The attackers employed techniques such as extracting cryptographic keys from ASP.NET configurations and injecting malicious payloads. The backdoor, which incorporates components from open-source projects, enables lateral movement within networks using tools for tunneling and traffic redirection. Kaspersky has confirmed that these attacks also exploit vulnerabilities in Active Directory, aiming to establish persistence and access sensitive data. The group has been active since at least 2023, previously focusing on Asian organizations. Current investigations are ongoing to assess the full scope of the impact.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…