Overview

Malware / implants:GhostContainer
ATT&CK software:Neo-reGeorg · rdp2tcp · Microsoft Dev Tunnels · ysoserial
Initial access:External Remote Services · Exploit Public-Facing Application · Valid Accounts
Primary objectives:Espionage/Backdoor deployment
Target sectors:Government · High-tech
Tracked victims: 2

Operational Activity

Recent Observations

Deployment of GhostContainer backdoor
The threat actor deploys the GhostContainer backdoor specifically targeting Microsoft Exchange servers to establish persistence and facilitate unauthorized access.

TTPs

ATT&CK coverage: 18 techniques
T1133 External Remote Services
VERIFIED
The actor uses compromised valid credentials to gain access to corporate VPNs, often routing traffic through Cloudflare WARP tunnels or European virtual infrastructure providers to bypass geographic restrictions.
T1505.003 Server Software Component: Web Shell
VERIFIED
Delivery of GhostContainer involves extracting cryptographic keys from ASP.NET configuration and overwriting the __VIEWSTATE framework parameter to inject and execute the backdoor in memory.
T1071.001 Application Layer Protocol: Web Protocols
PROBABLE
GhostContainer C2 traffic is concealed within ordinary Exchange web requests, acting as a proxy or tunnel.
Show more TTPs (15)
T1572 Protocol Tunneling
VERIFIED
The actor utilizes Microsoft Dev Tunnels, rdp2tcp, and native Windows port-forwarding to facilitate lateral movement and remote access.
T1003.003 OS Credential Dumping: NTDS
VERIFIED
The actor performs DCSync attacks to harvest Active Directory credentials and achieve domain dominance.
T1210 Exploitation of Remote Services
VERIFIED
The actor exploits known vulnerabilities including CVE-2019-0708 (BlueKeep) to assist in lateral movement and environment compromise.
T1190 Exploit Public-Facing Application
VERIFIED
Exploitation of vulnerabilities in internet-facing Microsoft Exchange servers for initial access and backdoor deployment (observed via ViewState tampering and CVE-2020-0688 components).
T1053.005 Scheduled Task/Job
VERIFIED
Use of atexec from Impacket toolkit to create scheduled tasks for port forwarding and persistence; also referenced in other analyses for reactivation every four hours.
T1055 Process Injection
VERIFIED
In-memory injection of GhostContainer backdoor into IIS worker processes (w3wp.exe) and memory horse techniques.
T1027 Obfuscated Files or Information
VERIFIED
Masquerading tools and payloads as legitimate business software (e.g., Adobe, TrueConf, 1C); fileless in-memory execution.
T1070.001 Indicator Removal: Clear Windows Event Logs
VERIFIED
Patching/disabling Windows security scanning, logging mechanisms, and AMSI/ETW evasion by overwriting addresses in amsi.dll and ntdll.dll.
T1552.004 Unsecured Credentials: Private Keys
VERIFIED
Extraction of ASP.NET cryptographic keys (machineKey) from server configuration for ViewState tampering and deserialization attacks.
T1083 File and Directory Discovery
PROBABLE
Enumeration and discovery activities implied in lateral movement and AD compromise phases.
T1486 Data Encrypted for Impact
PROBABLE
Contextual ransomware-related behaviors noted in broader ecosystem reporting, though primary NightEagle focus is espionage; some analyses reference encryption/impact elements.
T1090.003 Proxy: Multi-hop Proxy
VERIFIED
Use of Neo-reGeorg and ReGeorg for proxying/tunneling; Microsoft Dev Tunnels (*.devtunnels.ms) combined with rdp2tcp for RDP traffic redirection.
T1041 Exfiltration Over C2 Channel
VERIFIED
Data exfiltration via established C2 channels and tunneling tools.
T1078 Valid Accounts
VERIFIED
Abuse of compromised valid credentials for VPN access and subsequent Kerberos ticket requests with non-standard flags.
T1003 OS Credential Dumping
VERIFIED
DCSync attacks to replicate Domain-Password objects from Active Directory database.

Observed behaviors

GhostContainer delivery
VERIFIED
GhostContainer delivery involving extracting cryptographic keys from ASP.NET configuration and overwriting VIEWSTATE framework parameters.

CVEs

Remote Desktop Services Remote Code Execution Vulnerability (BlueKeep); exploited by NightEagle in one incident to create local administrator account and add to Administrators/Remote Desktop Users groups for lateral movement.
Microsoft Exchange Server Remote Code Execution Vulnerability; exploit components from this CVE incorporated into GhostContainer backdoor (alongside Neo-reGeorg and ysoserial GhostWebShell) for deployment on Microsoft Exchange servers.

Infrastructure

Tool hosting
The group hosts components of their toolset, including open-source projects used for backdoors and tunneling, on GitHub.

Attribution

APT-Q-95 VERIFIED
Vendor tracking name
Internal designation for the NightEagle threat actor.
APT-C-78 PROBABLE
Vendor tracking name
Secondary tracking designation reported in association with NightEagle.

Timeline

2026-09-16
Disclosure of Russian campaign
Kaspersky discloses a campaign by NightEagle targeting Russian manufacturing and construction organizations, utilizing compromised VPN credentials, GhostContainer backdoors, and Active Directory exploitation.
2025-07
GhostContainer activity observed
Historical analysis highlights NightEagle's use of the GhostContainer modular backdoor, which grants operators access to Microsoft Exchange Servers. These activities were previously identified in incidents targeting Asian government and high-tech sectors.
2023-01-01
NightEagle begins operations
NightEagle (also tracked as APT-Q-95) begins operations, initially focusing on targeting organizations in Asia, including government agencies and high-tech companies.

Sources