Learn how the NightEagle APT GhostContainer attacks exploit Exchange servers in Russia. Protect your network from the NightEagle APT.

Learn how the NightEagle APT GhostContainer attacks exploit Exchange servers in Russia. Protect your network from the NightEagle APT.
NightEagle, also tracked as APT-Q-95, has expanded from China to Russian firms, using stolen VPN creds, Exchange abuse, and GhostContainer to infiltrate networks and deepen access. #Russia #NightEagle #APTQ95
NightEagle, Hacking Cat & Toy Ghouls hit Russian firms with custom backdoors & ransomware—exchanges compromised. #Cybersecurity #Ransomware #ThreatIntel #NightEagle #HackingCat #ToyGhouls thedailytechfeed.com/three-threat...
~Kaspersky~
NightEagle uses GhostContainer, tunnels and AD exploits for Russian intrusions.
-
IOCs: github[.]com/mirror-js/mirror-js, github[.]com/browserthemes/resourcepack, CVE-2019-0708
-
#APT #NightEagle #ThreatIntel
NightEagle (APT-Q-95) has expanded from Asia to Russian companies, using stolen VPN credentials, GhostContainer on Exchange, BlueKeep exploitation, and tunneling to persist and move laterally. #Russia #NightEagle #APTQ95