Skip to main content

Kaspersky identifies NightEagle campaign targeting organizations in Russia

September 18, 2026

Kaspersky's Global Emergency Response Team identified a cyberespionage campaign by the NightEagle group targeting manufacturing and construction organizations in Russia. The attackers used compromised VPN credentials, deployed a stealthy backdoor on Microsoft Exchange servers and used legitimate developer tools to navigate corporate networks and compromise core identity infrastructure.

Over the past year, Kaspersky researchers investigated several intrusions involving NightEagle, also tracked as APT-Q-95. Discovered in 2025, the group was previously observed operating only in Asia. This campaign marks its first known shift to a new region. In most incidents, the attackers bypassed perimeter defenses using stolen, valid VPN credentials. They also masked their locations by routing internet traffic through Cloudflare WARP tunnels and European virtual infrastructure providers.

Once inside the network, NightEagle installed a custom backdoor program, dubbed GhostContainer, on the organizations' Microsoft Exchange email servers. Kaspersky assesses with high confidence that instead of dropping traditional files onto the hard drive, the attackers injected their malicious code directly into the servers' memory. Once running, the backdoor gave them remote control, disguised their commands as normal web traffic and disabled Windows' built-in security scanning and logging mechanisms to stay invisible.

To move deeper into the compromised organizations, the group abused legitimate tools to blend in with daily administrative work. NightEagle stored its hacking tools on GitHub and renamed its files to look like legitimate business software. The attackers also hijacked Microsoft features designed for software testing. By combining these features with public remote-access tools, the attackers successfully routed their traffic through the network without triggering alarms.

The group also exploited older, unpatched software flaws on internal computers to create unauthorized administrator accounts. The attack chain ultimately led to the compromise of the central system that manages all network identities, passwords and permissions, giving the attackers control over the victims' entire IT environments.

What stands out about this campaign is how heavily NightEagle relies on using the victim's own infrastructure against them. They interact with normal network services to move around and they leave breadcrumbs in standard system logs. By hunting for these administrative anomalies with Kaspersky Next EDR Expert, defenders can intercept this group long before the core identity network is compromised," commented Stanislav Larinsky, expert at Kaspersky's Global Emergency Response Team.

Kaspersky products detect the GhostContainer backdoor as Trojan.MSIL.GhostContainer.gen.

The full technical report on Securelist provides indicators of compromise and further detection details.

To protect against threats like NightEagle, Kaspersky experts recommend that organizations:

  • Require multifactor authentication for all VPN and administrator accounts, disable unused profiles and investigate logins arriving through anonymizing services or unfamiliar hosting providers.
  • Patch internal systems, because the attackers exploited years-old flaws on internal machines. Apply security updates everywhere, retire unsupported systems and restrict remote desktop access to monitored administrative hosts.
  • Detect stealthy behavior on endpoints with Kaspersky Next EDR Expert. It correlates suspicious activity such as unexpected scheduled tasks, unauthorized administrator accounts, unusual remote desktop connections that individually might pass for routine IT work.
  • Monitor network traffic with Kaspersky Anti Targeted Attack (KATA). The platform spots connections to unauthorized tunneling services, exploitation attempts against legacy flaws and abnormal requests to identity systems that signal a deep network breach.
  • Secure containerized workloads from malicious files hidden on public repositories (like GitHub) and disguised as legitimate business software. Kaspersky Container Security (KCS) safeguards the entire application lifecycle, defending environments from development to operation.

Kaspersky identifies NightEagle campaign targeting organizations in Russia

Kaspersky's Global Emergency Response Team identified a cyberespionage campaign by the NightEagle group targeting manufacturing and construction organizations in Russia. The attackers used compromised VPN credentials, deployed a stealthy backdoor on Microsoft Exchange servers and used legitimate developer tools to navigate corporate networks and compromise core identity infrastructure.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases