NightEagle APT Targets Russian Organizations via GhostContainer
Score: 9/10

NightEagle APT Targets Russian Organizations via GhostContainer

The NightEagle APT group (APT-Q-95) is targeting Russian businesses by deploying the GhostContainer backdoor on Microsoft Exchange servers and utilizing legitimate tunneling tools for lateral movement.

Executive Summary

The NightEagle APT group, also known as APT-Q-95, has expanded its operations from Asia to target organizations within Russia. This campaign leverages compromised VPN credentials and exploits known vulnerabilities in Microsoft Exchange (CVE-2020-0688) and RDP (CVE-2019-0708) to establish a foothold. The primary payload is the GhostContainer backdoor, a .NET-based assembly that facilitates C2 communication and traffic redirection while evading AMSI and event logging.

Technically, the group demonstrates high proficiency in maintaining persistence by combining legitimate services, such as Microsoft Dev Tunnels, with specialized tools like rdp2tcp to tunnel RDP traffic over non-standard channels. Once inside, the group employs DCSync and Kerberos ticket manipulation to compromise Active Directory infrastructure. This shift in targeting and the use of sophisticated evasion techniques pose a significant risk to Russian enterprise environments and critical infrastructure.

Immediate patching of legacy vulnerabilities and enhanced monitoring of RDP virtual channels and Exchange server configuration changes are critical to mitigating this threat.

Key Details

Threat Name

NightEagle (APT-Q-95)

Affects

Microsoft Exchange servers, Remote Desktop Services, Windows

Adversary

NightEagle Other Adversaries and Aliases: Mirage Kitten; HoneyMyte; Armored Likho

Malware/Tools

GhostContainer, rdp2tcp, atexec, NodeRabbit, PollCat, CoolClient, Still Toolkit, NightLedger, ArcBridge, BridgeHead

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance7
Enterprise Relevance10
Clarity & Structure9
Technical Depth8

Sources