Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia
Cyber-espionage group NightEagle (APT-Q-95), which previously attacked Chinese defense and technology companies, has shifted to Russian organizations. According to Kaspersky, the hackers entered networks via VPN using stolen credentials, then deployed the GhostContainer backdoor on Microsoft Exchange servers.
- Group active since 2023, previously attacked China, now Russia
- Network entry via VPN with stolen credentials
- GhostContainer backdoor gives remote control over Exchange servers
- Tools stored on GitHub under names AdobeSync and TrueConf
Read next
Security