BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Sep 18, 2026 · 2 min read · Original story

Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia

Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia
Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia

A cyberespionage group previously known for targeting sensitive technology and defense organizations in China has expanded its operations to Russian companies, according to new research released this week.

The group, known as NightEagle or APT-Q-95, has been active since at least 2023 but had previously focused its attacks in Asia. Over the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.

In most cases, the hackers used stolen credentials to gain access to corporate networks through virtual private networks, or VPNs. Once inside a network, NightEagle targeted Microsoft Exchange email servers and installed a backdoor known as GhostContainer, which allows attackers to remotely control compromised servers, evade some Windows security and logging mechanisms and redirect network traffic.

Kaspersky said it could not determine exactly how the hackers initially planted GhostContainer on the Exchange servers. Researchers believe, however, that the attackers used a technique they had observed previously that involves extracting encryption keys from Exchange and manipulating Microsoft's web application framework to execute the backdoor directly in the server's memory.

The group also used GitHub to store archives containing hacking tools, disguising repositories and files with names designed to resemble legitimate software, including AdobeSync and TrueConf.

After gaining an initial foothold, the hackers exploited weaknesses in Active Directory, Microsoft's system for managing users, computers and permissions across corporate networks, to obtain greater privileges and move between systems.

Those techniques allowed the hackers to maintain access, steal credentials and impersonate legitimate users, according to Kaspersky. The attackers ultimately tried to compromise domain controllers, or servers that play a central role in managing access across an organization's network.

"To expand the geographic scope of its targets, NightEagle is updating its methods and adopting new techniques for persistence and lateral movement," Kaspersky researchers said.

Kaspersky did not identify the Russian companies that were targeted or disclose how many organizations were affected. The company also did not specify the likely motivation behind the attacks.

NightEagle first came to public attention in July 2025, when researchers at Chinese cybersecurity company QiAnXin described a hacking operation they tracked as APT-Q-95. The researchers said the group had been active since at least 2023 and had targeted organizations in China working in strategically sensitive industries, including defense, semiconductors, artificial intelligence and quantum technology.

QiAnXin characterized the activity as cyberespionage and said the hackers had targeted Microsoft Exchange servers using what researchers at the time believed could be a previously unknown vulnerability.

The researchers dubbed the group NightEagle because its operators typically carried out attacks during nighttime hours in China and frequently changed the infrastructure they used to conduct their operations.

Chinese cybersecurity researchers have previously associated the group with North America. Those claims have not been independently confirmed by other researchers, and the group's attribution remains uncertain.

References in this story

  1. APT-группа NightEagle атакует российские организации securelist.ru Эксперты GERT «Лаборатории Касперского» обнаружили новую кампанию APT-группы NightEagle с бэкдором GhostContainer и утилитами с GitHub. Группа также эксплуатирует уязвимости в Active Directory и RDP-протоколе.
  2. 奇安信亮相东盟最大网络安全盛会CYDES2025 www.qianxin.com 奇安信是中国企业级网络安全市场的领军者
  3. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  4. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  5. Daryna Antoniuk (@darynant.bsky.social) bsky.app Cybersecurity Reporter at Recorded Future News. Ex at The Kyiv Independent/Forbes/The Kyiv Post 📍Kyiv, Ukraine

← Back to all news