The NightEagle threat group, also known as APT-Q-95, has expanded its operations from Asia to target businesses in Russia, utilizing a sophisticated toolkit for persistence and lateral movement. The group typically gains initial access through compromised VPN credentials before deploying the GhostContainer backdoor on Microsoft Exchange servers. This backdoor is particularly effective as it operates in-memory and employs techniques to bypass the Antimalware Scan Interface (AMSI) and Windows Event Log mechanisms.
Once established, the attackers utilize legitimate services like Microsoft dev tunnels and tools such as rdp2tcp to tunnel traffic through RDP connections without opening suspicious ports. Their lateral movement strategy involves exploiting Active Directory vulnerabilities, including the BlueKeep exploit (CVE-2019-0708) and DCSync attacks, to escalate privileges and compromise domain controllers. Monitoring for anomalous RDP channel names and non-standard Kerberos ticket flags is recommended for detection.
Top comments (0)