news.mlab.sh
Back to the feed
threat-intel

Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia

High
Summary

The cyberespionage group NightEagle (APT-Q-95), previously focused on targeting China's high-tech sector (defense, semiconductors, AI, quantum tech), has significantly expanded its operations to Russia, targeting Russian businesses. The group utilizes stolen credentials and exploits vulnerabilities in Microsoft Exchange, deploying a backdoor called GhostContainer to maintain persistent access and control. They also leverage GitHub to distribute malicious tools and exploit Active Directory for lateral movement.

A cyberespionage group known as NightEagle (APT-Q-95), previously active in China targeting sensitive technology and defense organizations, has broadened its operations to Russia. According to research released this week, the group has been targeting Russian businesses since at least 2023.

Researchers at Kaspersky observed the group utilizing stolen credentials to gain access to corporate networks via VPNs. Once inside, NightEagle targeted Microsoft Exchange email servers and installed a backdoor named GhostContainer. This backdoor allows remote server control, evades Windows security mechanisms, and redirects network traffic.

Kaspersky researchers believe NightEagle initially planted GhostContainer by extracting encryption keys from Exchange and manipulating Microsoft's web application framework to execute the backdoor directly in the server's memory. The group also uses GitHub to store hacking tools, disguising repositories and files with names resembling legitimate software, including AdobeSync and TrueConf.

After gaining an initial foothold, NightEagle exploited weaknesses in Active Directory, Microsoft's system for managing users, computers, and permissions, to obtain greater privileges and move between systems. These techniques allowed the hackers to maintain access, steal credentials, and impersonate legitimate users. The attackers ultimately tried to compromise domain controllers, or servers that play a central role in managing access across an organization's network.

NightEagle first gained public attention in July 2025, when researchers at Chinese cybersecurity company QiAnXin described a hacking operation they tracked as APT-Q-95. QiAnXin characterized the activity as cyberespionage and said the hackers had targeted organizations in China working in strategically sensitive industries. Chinese cybersecurity researchers have previously associated the group with North America, but these claims have not been independently confirmed.

Researchers at QiAnXin dubbed the group NightEagle because its operators typically carried out attacks during nighttime hours in China and frequently changed the infrastructure they used to conduct their operations.

Read the full article at The Record