Thehackernews NightEagle APT Targets Russian Enterprises with Advanced Malware
Article Content
- •NightEagle APT (APT-Q-95) targets Russian firms using advanced malware.
- •GhostContainer backdoor allows full control over Microsoft Exchange servers.
- •Attacks coincide with ongoing geopolitical tensions in the region.
The NightEagle APT group (APT-Q-95) has escalated its cyberattacks against Russian organizations, employing sophisticated techniques for persistence and lateral movement. Utilizing stolen credentials, the group gains access to corporate VPNs, often routing through Cloudflare WARP tunnels linked to Russian IPs. The primary tool used is the GhostContainer backdoor, which allows full control over Microsoft Exchange servers. This malware integrates components from various open-source projects and is capable of running arbitrary code, manipulating files, and loading additional modules. Recent reports indicate that NightEagle's tactics have evolved, employing advanced evasion techniques to bypass common defenses. Other groups, including Hacking Cat and Toy Ghouls, are also targeting Russian enterprises, indicating a broader threat landscape amid ongoing geopolitical tensions. The attacks coincide with heightened military conflicts involving Russia and Ukraine, raising concerns about the implications for corporate security in the region.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track Babuk, Apt-q-95 and Bird Agent in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Ransomware Exploits Critical VMware vCenter Vulnerability CVE-2026-59310 On September 15, 2026, CISA confirmed that ransomware gangs are actively exploiting a critical remote code execution vulnerability in VMware vCenter Server, tracked as CVE-2026-59310, which has a CVSS score of 9.8. This flaw, residing in the vCenter Syslog server, allows unauthenticated attackers with network access…
Toy Ghouls Use HiveMQ and Element for New Windows Backdoors The financially motivated group Toy Ghouls has introduced two new Windows backdoors named mqtt-bird-agent and matrix-bird-agent, utilizing HiveMQ and Element messenger for command-and-control communications. This marks a shift from their previous reliance on public tools and ransomware builders. The backdoors are…