A cyberespionage group previously known for targeting sensitive technology and defense organizations in China has expanded its operations to Russian companies, according to new research released this week.
The group, known as NightEagle or APT-Q-95, has been active since at least 2023 but had previously focused its attacks in Asia. Over the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.
In most cases, the hackers used stolen credentials to gain access to corporate networks through virtual private networks, or VPNs. Once inside a network, NightEagle targeted Microsoft Exchange email servers and installed a backdoor known as GhostContainer, which allows attackers to remotely control compromised servers, evade some Windows security and logging mechanisms and redirect network traffic.
by The Record – Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia



