securityonline.info 21 Sept 2026, 07:15 UTC

NightEagle Hackers Target Russian Firms With GhostContainer Backdoor

NightEagle Hackers Target Russian Firms With GhostContainer Backdoor
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown
Threat Actor
🇺🇸 NightEagle

KASPERSKY’S Global Emergency Response Team has identified a cyber-espionage campaign attributed to NightEagle, also known as APT-Q-95, targeting businesses in Russia. The group, active since at least 2023 and previously focused on Asia, reportedly gained access using compromised VPN credentials routed through Cloudflare WARP tunnels and European virtual infrastructure providers. Attackers then installed GhostContainer, a backdoor on Microsoft Exchange servers.

The malware combines elements of open-source projects including Neo-reGeorg and ysoserial, and includes exploitation of CVE-2020-0688. Researchers believe the attackers extracted ASP.NET cryptographic keys and altered the VIEWSTATE parameter to execute the backdoor in memory.

GhostContainer processes commands through custom HTTP headers, attempts to bypass the Antimalware Scan Interface and Windows Event Log by modifying system-library memory addresses, redirects web requests through virtual paths, and proxies network traffic. Kaspersky detects the variant as Trojan.MSIL.GhostContainer.gen.

After gaining higher privileges, the attackers reportedly used RDP for lateral movement, tunnelling tools disguised as legitimate software, Microsoft dev tunnels and rdp2tcp to expose port 3389, and Impacket’s atexec utility to schedule tasks. They also exploited BlueKeep (CVE-2019-0708), created local administrator accounts, requested unusual Kerberos tickets and used DCSync techniques to extract domain password hashes, potentially compromising entire Active Directory environments.

The number of affected organisations was not disclosed. Kaspersky recommends monitoring scheduled tasks and unexpected RDP activity, enforcing multi-factor authentication for remote access, and patching Exchange and other systems affected by older vulnerabilities.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline