Kaspersky's Global Emergency Response Team identified a cyberespionage campaign by the NightEagle group targeting manufacturing and construction organizations in Russia. The attackers used compromised VPN credentials, deployed a stealthy backdoor on Microsoft Exchange servers and used legitimate developer tools to navigate corporate networks and compromise core identity infrastructure.
Over the past year, Kaspersky researchers investigated several intrusions involving NightEagle, also tracked as APT-Q-95. Discovered in 2025, the group was previously observed operating only in Asia. This campaign marks its first known shift to a new region. In most incidents, the attackers bypassed perimeter defenses using stolen, valid VPN credentials. They also masked their locations by routing internet traffic through Cloudflare WARP tunnels and European virtual infrastructure providers.
Once inside the network, NightEagle installed a custom backdoor program, dubbed GhostContainer, on the organizations' Microsoft Exchange email servers. Kaspersky assesses with high confidence that instead of dropping traditional files onto the hard drive, the attackers injected their malicious code directly into the servers' memory. Once running, the backdoor gave them remote control, disguised their commands as normal web traffic and disabled Windows' built-in security scanning and logging mechanisms to stay invisible.
To move deeper into the compromised organizations, the group abused legitimate tools to blend in with daily administrative work. NightEagle stored its hacking tools on GitHub and renamed its files to look like legitimate business software. The attackers also hijacked Microsoft features designed for software testing. By combining these features with public remote-access tools, the attackers successfully routed their traffic through the network without triggering alarms.
The group also exploited older, unpatched software flaws on internal computers to create unauthorized administrator accounts. The attack chain ultimately led to the compromise of the central system that manages all network identities, passwords and permissions, giving the attackers control over the victims' entire IT environments.
“What stands out about this campaign is how heavily NightEagle relies on using the victim's own infrastructure against them. They interact with normal network services to move around and they leave breadcrumbs in standard system logs. By hunting for these administrative anomalies with Kaspersky Next EDR Expert, defenders can intercept this group long before the core identity network is compromised," commented Stanislav Larinsky, expert at Kaspersky's Global Emergency Response Team.
Kaspersky products detect the GhostContainer backdoor as Trojan.MSIL.GhostContainer.gen.
The full technical report on Securelist provides indicators of compromise and further detection details.
To protect against threats like NightEagle, Kaspersky experts recommend that organizations:
- Require multifactor authentication for all VPN and administrator accounts, disable unused profiles and investigate logins arriving through anonymizing services or unfamiliar hosting providers.
- Patch internal systems, because the attackers exploited years-old flaws on internal machines. Apply security updates everywhere, retire unsupported systems and restrict remote desktop access to monitored administrative hosts.
- Detect stealthy behavior on endpoints with Kaspersky Next EDR Expert. It correlates suspicious activity such as unexpected scheduled tasks, unauthorized administrator accounts, unusual remote desktop connections that individually might pass for routine IT work.
- Monitor network traffic with Kaspersky Anti Targeted Attack (KATA). The platform spots connections to unauthorized tunneling services, exploitation attempts against legacy flaws and abnormal requests to identity systems that signal a deep network breach.
- Secure containerized workloads from malicious files hidden on public repositories (like GitHub) and disguised as legitimate business software. Kaspersky Container Security (KCS) safeguards the entire application lifecycle, defending environments from development to operation.