GhostContainer samples | Image: Kaspersky Labs
At a Glance
- Actor or group: NightEagle (also tracked as APT-Q-95).
- Activity type: Cyberespionage, tunneling, and Active Directory compromise.
- Targets or victims: Businesses in Russia (previously focused on Asia).
- Scale: Undisclosed number of compromised organizations.
- Jurisdiction or law-enforcement status: Suspected state-sponsored espionage group.
- Source: Kaspersky Global Emergency Response Team (GERT).
Executive Summary
Security analysts recently identified a new cyberespionage campaign where the NightEagle APT targets Russian businesses. The NightEagle APT GhostContainer attacks utilized compromised VPN credentials to breach internal corporate networks. Once inside, they deployed a stealthy backdoor and exploited older system vulnerabilities to seize complete control of central identity servers.
What Happened During the Breach
The intrusions started with compromised virtual private network accounts. In most incidents, the attackers gained initial access through valid VPN credentials. They routed these connections through Cloudflare WARP tunnels and European virtual infrastructure providers.
After breaching the perimeter, the hackers installed a backdoor on Microsoft Exchange servers. They named this malicious tool GhostContainer. The backdoor merges components from several open-source projects, including Neo-reGeorg and the ysoserial utility. In addition, it contains an exploit for the CVE-2020-0688 vulnerability. Kaspersky researchers believe the attackers extracted cryptographic keys from the ASP.NET configuration. They then overwrote the VIEWSTATE parameter to execute the backdoor directly in memory.
Once executed, the malware uses three primary classes to function. The first class processes command instructions delivered through custom HTTP headers. It evades the Antimalware Scan Interface and Windows Event Log mechanisms by overwriting memory addresses in system libraries. The second class creates virtual paths to redirect incoming web requests. Finally, the third class handles network traffic proxying and socket forwarding operations. Kaspersky security products now detect this specific malware variant as Trojan.MSIL.GhostContainer.gen.
Who is Behind It
Investigators attribute this campaign to the NightEagle group. Researchers also track this suspected threat actor as APT-Q-95. The group has remained active since at least 2023. Originally, the hackers focused exclusively on organizations located in Asia. Now, they have expanded their geographic scope to target businesses in Russia. Chinese cybersecurity firm QiAnXin previously linked this group to North American interests, though independent experts have not confirmed this attribution.
Impact and Scale of the Intrusions
Once the attackers gained sufficient privileges, they used Remote Desktop Protocol (RDP) to move laterally. They downloaded tunneling tools from GitHub repositories disguised as legitimate software. For instance, they used archives named “jsonp-pack.zip” and files like “adobe_32.exe” or “trueconf.exe” to blend in.
Furthermore, the intruders combined Microsoft dev tunnels with a public tool called rdp2tcp. This combination exposed port 3389 without opening suspicious new network ports. When virtual channels opened, the system logged corresponding event IDs in the Windows event viewer. These events contained random alphanumeric channel names associated with the malicious traffic.
The hackers also deployed the atexec utility from the Impacket toolkit to schedule tasks. These tasks forwarded network ports using standard Windows commands. Next, the intruders exploited the BlueKeep vulnerability (CVE-2019-0708) to create local administrator accounts. They requested unusual Kerberos tickets with specific forwardable and renewable flags. Ultimately, they executed DCSync techniques to extract domain password hashes and compromise entire Active Directory infrastructures.
How to Stay Protected
The NightEagle APT updates its methods to maintain persistence and evade detection. As stated in the primary report, “To expand the geographic scope of its targets, NightEagle is updating its methods and adopting new techniques for persistence and lateral movement.” Therefore, security teams must monitor internal networks closely. Administrators should require multi-factor authentication for all remote access portals. Security operations centers must investigate scheduled tasks and unexpected RDP connections.
Because the attackers rely on older flaws, patching systems remains critical. Organizations must secure Microsoft Exchange servers against known vulnerabilities immediately. Timely detection of administrative anomalies can stop these breaches before they compromise core identity systems.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!