Overview
Malware / implants:GhostContainer
ATT&CK software:Neo-reGeorg · rdp2tcp · Microsoft Dev Tunnels · ysoserial
Initial access:External Remote Services · Exploit Public-Facing Application · Valid Accounts
Primary objectives:Espionage/Backdoor deployment
Target sectors:Government · High-tech
Tracked victims:
2
Operational Activity
Recent Observations
Deployment of GhostContainer backdoor
The threat actor deploys the GhostContainer backdoor specifically targeting Microsoft Exchange servers to establish persistence and facilitate unauthorized access.
TTPs
ATT&CK coverage:
18 techniques
T1133
External Remote Services
VERIFIEDThe actor uses compromised valid credentials to gain access to corporate VPNs, often routing traffic through Cloudflare WARP tunnels or European virtual infrastructure providers to bypass geographic restrictions.
T1505.003
Server Software Component: Web Shell
VERIFIEDDelivery of GhostContainer involves extracting cryptographic keys from ASP.NET configuration and overwriting the __VIEWSTATE framework parameter to inject and execute the backdoor in memory.
T1071.001
Application Layer Protocol: Web Protocols
PROBABLEGhostContainer C2 traffic is concealed within ordinary Exchange web requests, acting as a proxy or tunnel.
Show more TTPs (15)
T1572
Protocol Tunneling
VERIFIEDThe actor utilizes Microsoft Dev Tunnels, rdp2tcp, and native Windows port-forwarding to facilitate lateral movement and remote access.
T1003.003
OS Credential Dumping: NTDS
VERIFIEDThe actor performs DCSync attacks to harvest Active Directory credentials and achieve domain dominance.
T1210
Exploitation of Remote Services
VERIFIEDThe actor exploits known vulnerabilities including CVE-2019-0708 (BlueKeep) to assist in lateral movement and environment compromise.
T1190
Exploit Public-Facing Application
VERIFIEDExploitation of vulnerabilities in internet-facing Microsoft Exchange servers for initial access and backdoor deployment (observed via ViewState tampering and CVE-2020-0688 components).
T1053.005
Scheduled Task/Job
VERIFIEDUse of atexec from Impacket toolkit to create scheduled tasks for port forwarding and persistence; also referenced in other analyses for reactivation every four hours.
T1055
Process Injection
VERIFIEDIn-memory injection of GhostContainer backdoor into IIS worker processes (w3wp.exe) and memory horse techniques.
T1027
Obfuscated Files or Information
VERIFIEDMasquerading tools and payloads as legitimate business software (e.g., Adobe, TrueConf, 1C); fileless in-memory execution.
T1070.001
Indicator Removal: Clear Windows Event Logs
VERIFIEDPatching/disabling Windows security scanning, logging mechanisms, and AMSI/ETW evasion by overwriting addresses in amsi.dll and ntdll.dll.
T1552.004
Unsecured Credentials: Private Keys
VERIFIEDExtraction of ASP.NET cryptographic keys (machineKey) from server configuration for ViewState tampering and deserialization attacks.
T1083
File and Directory Discovery
PROBABLEEnumeration and discovery activities implied in lateral movement and AD compromise phases.
T1486
Data Encrypted for Impact
PROBABLEContextual ransomware-related behaviors noted in broader ecosystem reporting, though primary NightEagle focus is espionage; some analyses reference encryption/impact elements.
T1090.003
Proxy: Multi-hop Proxy
VERIFIEDUse of Neo-reGeorg and ReGeorg for proxying/tunneling; Microsoft Dev Tunnels (*.devtunnels.ms) combined with rdp2tcp for RDP traffic redirection.
T1041
Exfiltration Over C2 Channel
VERIFIEDData exfiltration via established C2 channels and tunneling tools.
T1078
Valid Accounts
VERIFIEDAbuse of compromised valid credentials for VPN access and subsequent Kerberos ticket requests with non-standard flags.
T1003
OS Credential Dumping
VERIFIEDDCSync attacks to replicate Domain-Password objects from Active Directory database.
Observed behaviors
GhostContainer delivery
VERIFIEDGhostContainer delivery involving extracting cryptographic keys from ASP.NET configuration and overwriting VIEWSTATE framework parameters.
CVEs
Remote Desktop Services Remote Code Execution Vulnerability (BlueKeep); exploited by NightEagle in one incident to create local administrator account and add to Administrators/Remote Desktop Users groups for lateral movement.
Microsoft Exchange Server Remote Code Execution Vulnerability; exploit components from this CVE incorporated into GhostContainer backdoor (alongside Neo-reGeorg and ysoserial GhostWebShell) for deployment on Microsoft Exchange servers.
Infrastructure
Tool hosting
The group hosts components of their toolset, including open-source projects used for backdoors and tunneling, on GitHub.
Attribution
APT-Q-95
VERIFIED
Vendor tracking name
Internal designation for the NightEagle threat actor.
APT-C-78
PROBABLE
Vendor tracking name
Secondary tracking designation reported in association with NightEagle.
Timeline
2026-09-16
Disclosure of Russian campaign
Kaspersky discloses a campaign by NightEagle targeting Russian manufacturing and construction organizations, utilizing compromised VPN credentials, GhostContainer backdoors, and Active Directory exploitation.
2025-07
GhostContainer activity observed
Historical analysis highlights NightEagle's use of the GhostContainer modular backdoor, which grants operators access to Microsoft Exchange Servers. These activities were previously identified in incidents targeting Asian government and high-tech sectors.
2023-01-01
NightEagle begins operations
NightEagle (also tracked as APT-Q-95) begins operations, initially focusing on targeting organizations in Asia, including government agencies and high-tech companies.
Sources
GhostContainer
Mallory.ai
Show more sources (8)
Understanding NightEagle: An In-Depth Analysis of APT-Q-95
Inception Security
APT Group NightEagle (APT-Q-95) - Advanced Exchange Zero-Day Exploitation Campaign
AlienVault OTX / LevelBlue