Skip to content
NightEagle APT Targets Russian Enterprises with Advanced Malware

NightEagle APT Targets Russian Enterprises with Advanced Malware

First seen 16 Sep 2026, 16:30 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 15:48 UTC

The NightEagle APT group (APT-Q-95) has escalated its cyberattacks against Russian organizations, employing sophisticated techniques for persistence and lateral movement. Utilizing stolen credentials, the group gains access to corporate VPNs, often routing through Cloudflare WARP tunnels linked to Russian IPs. The primary tool used is the GhostContainer backdoor, which allows full control over Microsoft Exchange servers. This malware integrates components from various open-source projects and is capable of running arbitrary code, manipulating files, and loading additional modules. Recent reports indicate that NightEagle's tactics have evolved, employing advanced evasion techniques to bypass common defenses. Other groups, including Hacking Cat and Toy Ghouls, are also targeting Russian enterprises, indicating a broader threat landscape amid ongoing geopolitical tensions. The attacks coincide with heightened military conflicts involving Russia and Ukraine, raising concerns about the implications for corporate security in the region.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2019-05-16
CVE-2019-0708 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-02-11
CVE-2020-0688 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-03-02
CVE-2021-26855 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-01-01
NightEagle APT identified
NightEagle APT (APT-Q-95) becomes active, initially targeting organizations in Asia.
Securelist
2025-07-01
Notable attacks reported
Kaspersky documents significant attacks involving GhostContainer backdoor against Russian enterprises.
The Hacker News
2026-05-14
CVE-2026-42897 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
Kaspersky report published
Kaspersky releases detailed findings on NightEagle, Hacking Cat, and Toy Ghouls targeting Russian firms.
WebProNews
2026-09-17
Current attacks ongoing
Ongoing cyberattacks against Russian enterprises by multiple threat groups, including NightEagle.
Ground.News

More articles in this cluster (12)

Following this threat?

Track Babuk, Apt-q-95 and Bird Agent in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed