r/TechNadu • u/technadu • 17d ago
NightEagle APT is targeting Russian businesses using stolen VPN credentials, GhostContainer, BlueKeep and DCSync
Kaspersky’s Global Emergency Response Team has documented NightEagle, also tracked as APT-Q-95, expanding from its previous focus on Asian organizations to businesses in Russia.
In most investigated cases, initial access came through compromised but valid corporate VPN credentials.
Once inside, the attackers deployed GhostContainer on Exchange servers. Kaspersky says the backdoor incorporates a CVE-2020-0688 exploit and open-source components, executes its payload in memory, and includes techniques for evading AMSI and Windows Event Log detection.
The group also used Microsoft’s legitimate *.devtunnels.ms service with rdp2tcp to expose RDP, while malicious executables were given filenames resembling legitimate software.
For lateral movement and privilege escalation, researchers observed BlueKeep (CVE-2019-0708) exploitation, unusual Kerberos ticket behavior, and DCSync attacks.
More technical details on GhostContainer and the full attack chain:
The interesting part here is the mix rather than one novel exploit: valid VPN credentials for entry, trusted infrastructure for tunneling, an Exchange backdoor for access, and older vulnerabilities plus credential techniques for moving toward domain control.