NightEagle Hackers Breach Russian Firms via Microsoft Dev Tunnels, GhostContainer
Key Takeaways The NightEagle APT group has launched a new campaign targeting Russian businesses, leveraging stolen VPN credentials and sophisticated backdoors. Attackers are exploiting Microsoft...
Key Takeaways
- The NightEagle APT group has launched a new campaign targeting Russian businesses, leveraging stolen VPN credentials and sophisticated backdoors.
- Attackers are exploiting Microsoft Exchange servers with a custom backdoor called GhostContainer and abusing legitimate Microsoft Dev Tunnels for covert remote access.
- The campaign involves lateral movement through Active Directory, including exploiting CVE-2019-0708 (BlueKeep) and performing DCSync attacks.
- The threat highlights the risk of compromised credentials and the repurposing of standard administrative tools for malicious ends.
The advanced persistent threat (APT) group known as NightEagle, also identified as APT-Q-95, has significantly broadened its cyber operations, now targeting Russian enterprises. This latest campaign employs a multi-faceted approach, combining stolen virtual private network (VPN) credentials, a custom backdoor for Microsoft Exchange, and stealthy remote-access techniques to infiltrate and maintain persistence within corporate networks.
Table Of Content
This activity underscores a critical trend where attackers repurpose everyday administrative functions and readily available code to forge persistent pathways into victim organizations. NightEagle has been active since at least 2023, with prior operations primarily focused on entities across Asia.
In the recently documented incidents, NightEagle initiated intrusions by authenticating into corporate VPNs using legitimate, albeit compromised, accounts. Once inside, the group systematically escalated privileges, established persistent control, and moved to compromise critical identity management systems. Analysts at Securelist uncovered the details of this campaign during forensic investigations into several breaches.
In a report shared with Cyber Security News (CSN), Kaspersky said NightEagle strategically combined its GhostContainer backdoor with various tunneling tools. This pairing allowed them to maintain covert access while circumventing the overt indicators typically generated by opening new external network ports, thereby enhancing their stealth.
The threat extends beyond a singular malicious file or an isolated exposed service. By integrating a server-side backdoor, remote desktop connections, credential harvesting, and Active Directory exploitation, the attackers could seamlessly transition from an initial compromised machine to systems managing an organization’s user accounts and permissions.
NightEagle Hackers Abuse Microsoft Dev Tunnels
The initial entry point for these attacks typically involved a successful VPN login executed with stolen credentials. The source IP addresses for these connections were traced to Russian locations utilizing Cloudflare WARP tunnels, as well as European virtual infrastructure providers. This method helped the initial stage of the attack blend in with normal network traffic, making it less likely to trigger immediate suspicion.
On targeted Microsoft Exchange servers, the attackers deployed GhostContainer, a .NET backdoor constructed from publicly available components. This sophisticated malware incorporates elements from the Neo-reGeorg tunnel, code exploiting CVE-2020-0688, and the GhostWebShell class.

While researchers could not definitively confirm the exact delivery mechanism, they hypothesize that the attackers likely extracted Exchange cryptographic keys, manipulated the VIEWSTATE, and then executed the payload directly in memory.
GhostContainer possesses several critical capabilities: it can receive commands through Exchange web headers, disable Windows scanning and event logging, and redirect network traffic. These functionalities transform the compromised mail server into a hidden relay within the victim’s network environment.
This attack vector underscores the persistent and urgent security concerns surrounding exposed Exchange servers, particularly those accessible from the internet without stringent monitoring.
After acquiring sufficient privileges, the operators exploited Microsoft Dev Tunnels to expose the compromised system’s Remote Desktop Protocol (RDP) service via tunnel-service addresses. They then combined this with rdp2tcp, an open-source utility designed to tunnel TCP traffic through an existing RDP connection. This combination allowed attackers to maintain a covert entry point into the network without creating a new, easily detectable listening port.
This tactic aligns with a broader trend of abusing legitimate developer features, such as Dev Tunnels, for concealed command-and-control (C2) traffic rather than their intended purpose of testing and development.
Lateral Movement and Detection
The attackers hosted their compressed toolkits in GitHub repositories, carefully naming them and their archive labels to appear legitimate. Similarly, the files contained within these archives were disguised as common software applications.
They utilized the atexec tool to establish scheduled tasks and configure Windows port-forwarding rules, thereby extending their reach across the network through standard system functionalities.
NightEagle then turned its attention to Active Directory, the central service governing user accounts and permissions in many Windows-based networks. In one notable incident, the group exploited BlueKeep (CVE-2019-0708) to create a local account and subsequently elevate its privileges by adding it to the Administrators and Remote Desktop Users groups. This highlights the critical importance of treating patch management and the security of exposed RDP ports as interconnected priorities.
The group also requested Kerberos tickets with an unusual set of flags, followed by an attempt to perform DCSync after obtaining an account with sufficient privileges.
.webp)
DCSync is a technique where an attacker impersonates a domain controller to request sensitive password hashes and other credential material directly from Active Directory. Successful execution of a DCSync attack can grant an attacker long-term access and complete control over the entire domain, as detailed in various explanations of
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.