NightEagle, also known as APT-Q-95, is a cyberespionage threat actor active since at least 2023. It has targeted Chinese government, defense, semiconductor, artificial-intelligence, quantum-technology, and other high-technology organizations, and later expanded operations to Russian enterprises, including manufacturing and construction organizations. NightEagle has used compromised VPN credentials for initial access and deployed the GhostContainer .NET backdoor on Microsoft Exchange servers. Its operations combine custom malware with public and legitimate tools, including Microsoft Dev Tunnels, RDP-based tunneling, scheduled tasks, and Windows port forwarding, to maintain covert remote access and move laterally. The group has pursued Active Directory compromise through exploitation of CVE-2019-0708, Kerberos ticket abuse, and DCSync attempts, enabling privilege escalation, credential theft, persistence, and potential domain-controller compromise. GhostContainer supports command execution, traffic proxying and forwarding, and evasion of Windows security-scanning and event-logging mechanisms. NightEagle has also stolen email data from compromised Exchange environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Например, в одном из инцидентов NightEagle воспользовалась нашумевшим багом CVE-2019-0708 (BlueKeep), чтобы создать локальную учетную запись и добавить ее в группы администраторов и пользователей удаленного рабочего стола.
The value element in the XML starts with a hardcoded string /wEPDwUKLTcyODc4 , and the same string is used in another open-source project, ExchangeCmdPy.py , to exploit the Exchange vulnerability CVE-2020-0688... We suspect that the vulnerability exploited in the Exchange attack may be related to CVE-2020-0688.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting cyberespionage against Russian manufacturing and construction enterprises. The group gains initial access through VPN accounts with valid compromised credentials, deploys the GhostContainer backdoor to Microsoft Exchange servers, and moves laterally to compromise Active Directory and domain controllers.
Cyberespionage activity active since at least 2023. The group has targeted strategically sensitive Chinese defense and technology organizations and, over the past year, Russian companies. It uses stolen credentials for VPN access, compromises Exchange infrastructure, escalates Active Directory privileges, moves laterally, steals credentials, impersonates users, and seeks to compromise domain controllers.
Conducting intrusions against Russian businesses by authenticating to corporate VPNs with stolen credentials, deploying the GhostContainer backdoor on Microsoft Exchange, establishing covert RDP access through Microsoft Dev Tunnels and rdp2tcp, and pursuing Active Directory compromise and DCSync credential theft.
Conducting intrusions against Russian businesses, beginning with valid stolen VPN credentials and progressing through Exchange-server backdoors, tunneled RDP access, lateral movement, Active Directory abuse, credential theft, and attempted domain compromise.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.