Executive Summary
The NightEagle APT group, also known as APT-Q-95, has expanded its operations from Asia to target organizations within Russia. This campaign leverages compromised VPN credentials and exploits known vulnerabilities in Microsoft Exchange (CVE-2020-0688) and RDP (CVE-2019-0708) to establish a foothold. The primary payload is the GhostContainer backdoor, a .NET-based assembly that facilitates C2 communication and traffic redirection while evading AMSI and event logging.
Technically, the group demonstrates high proficiency in maintaining persistence by combining legitimate services, such as Microsoft Dev Tunnels, with specialized tools like rdp2tcp to tunnel RDP traffic over non-standard channels. Once inside, the group employs DCSync and Kerberos ticket manipulation to compromise Active Directory infrastructure. This shift in targeting and the use of sophisticated evasion techniques pose a significant risk to Russian enterprise environments and critical infrastructure.
Immediate patching of legacy vulnerabilities and enhanced monitoring of RDP virtual channels and Exchange server configuration changes are critical to mitigating this threat.
Key Details
Threat Name
NightEagle (APT-Q-95)
Affects
Microsoft Exchange servers, Remote Desktop Services, Windows
Adversary
NightEagle Other Adversaries and Aliases: Mirage Kitten; HoneyMyte; Armored Likho
Malware/Tools
GhostContainer, rdp2tcp, atexec, NodeRabbit, PollCat, CoolClient, Still Toolkit, NightLedger, ArcBridge, BridgeHead
