Hacking group NightEagle expands operations from China to target Russian companies

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

A cyberespionage group known as NightEagle, or APT-Q-95, has expanded its operations from targeting sensitive technology and defense organizations in China to Russian companies, according to new research from Kaspersky. Active since at least 2023, NightEagle had previously focused its attacks in Asia but has recently been implicated in several incidents involving Russian businesses.

In these attacks, the hackers typically used stolen credentials to access corporate networks via virtual private networks (VPNs). Once inside, they targeted Microsoft Exchange email servers and installed a backdoor known as GhostContainer, which enables remote control of compromised servers while evading certain Windows security measures and redirecting network traffic. Kaspersky noted that the exact method of how GhostContainer was initially deployed remains unclear, although researchers suspect it involved extracting encryption keys from Exchange and manipulating Microsoft’s web application framework.

Additionally, NightEagle utilized GitHub to store archives of hacking tools, disguising them with names resembling legitimate software such as AdobeSync and TrueConf. After establishing a foothold, the group exploited vulnerabilities in Active Directory to gain higher privileges and move laterally within networks, allowing them to maintain access, steal credentials, and impersonate legitimate users. Their ultimate goal appeared to be compromising domain controllers, which are critical for managing access across an organization’s network.

Kaspersky researchers indicated that NightEagle is updating its methods to broaden its target scope, adopting new techniques for persistence and lateral movement. However, the specific Russian companies targeted and the number of affected organizations have not been disclosed, nor has the motivation behind these attacks been clarified.

NightEagle first gained attention in July 2025 when researchers from QiAnXin, a Chinese cybersecurity firm, described their operations. They noted that the group had been active since at least 2023, focusing on organizations in China involved in strategically sensitive sectors, including defense and artificial intelligence. The group was named NightEagle due to its tendency to conduct attacks during nighttime hours in China and its frequent changes in operational infrastructure.

For more details, see the full report by The Record.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

North Korean WaterPlum Cyber Group Targets IT Professionals to Steal Cryptocurrency

Recent investigations by the National Police Agency of Japan (NPA), the US Federal Bureau of Investigation (FBI), and other international cybersecurity agencies have revealed...

Air Force plans to field 100 Massed Modular Aircraft drones by 2029

The United States Air Force is advancing its plans for the Massed Modular Aircraft (MMA) unmanned platform, with intentions to field 100 of these...

Surge in AI-Driven Vulnerabilities Leads to Record Number of CVEs, Straining Cybersecurity Resources

Recent developments in cybersecurity have revealed a significant surge in vulnerabilities driven by artificial intelligence (AI), leading to a record number of Common Vulnerabilities...

North Korean hackers steal over $10.5 million in cryptocurrency through ‘WaterPlum’ campaign targeting job seekers across 100 countries

North Korean hackers have reportedly stolen over $10.5 million in cryptocurrency through a campaign known as "WaterPlum," which targets job seekers across more than...