NightEagle, also known as APT-Q-95, has expanded its operations to target Russian businesses following a previous focus on organizations in Asia This article explores security utilities nighteagle. . The threat group has been active since at least 2023 and is now using compromised VPN credentials, Microsoft Exchange backdoors, RDP tunneling tools, and Active Directory attack techniques to gain and maintain access.

Kaspersky's Global Emergency Response Team found that NightEagle combines legitimate tools with public offensive-security utilities. NightEagle Targets Russian Networks The VPN sessions originated from Russian IP addresses linked to Cloudflare WARP tunnels and European virtual private server infrastructures. GhostContainer, a .NET-based malware, incorporates elements from publicly available projects, including Neo-reGeorg, a CVE-2020-0688 exploit, and the GhostWebShell component from ysoserial.

However, they suspect the attackers likely extracted Exchange cryptographic keys from ASP.NET configuration files, modified the VIEWSTATE parameter, and injected a payload that executed GhostContainer directly in memory. Simultaneously, rdp2tcp tunnels traffic through an existing RDP session, enabling the group to gain access to internal systems without creating obvious new ports. Events 132 and 148 may indicate the presence of a virtual channel named rdp2tcp or a suspiciously named random alphanumeric string, as noted by Securelist.