NightEagle Hackers Expand from China to Target Russian Firms
The NightEagle cyberespionage group, known for targeting China's high-tech sector, has expanded its operations to Russian companies, using stolen VPN

The NightEagle hacking group has expanded its cyberespionage operations to target Russian businesses. Previously focused on China's high-tech and defense sectors, the group is now using stolen credentials and a sophisticated backdoor to breach corporate networks, according to research from Kaspersky.
Kaspersky investigated several incidents at Russian companies over the past year involving the group, also tracked as APT-Q-95. The hackers typically used stolen credentials to gain initial access through corporate virtual private networks (VPNs).
Initial Access and Backdoor Deployment
Once inside a network, the attackers focused on Microsoft Exchange email servers. They installed a backdoor known as GhostContainer. This tool allows remote control of compromised servers, helps evade some Windows security and logging features, and can redirect network traffic.
Researchers could not pinpoint the exact initial infection vector for GhostContainer. They suspect the hackers used a technique observed in prior attacks. This method involves extracting encryption keys from Exchange and manipulating Microsoft's web application framework to run the backdoor directly in the server's memory.
The group also used GitHub to host archives of its hacking tools. It disguised repositories and files with names like AdobeSync and TrueConf to mimic legitimate software.
Lateral Movement and Persistence
After establishing a foothold, NightEagle exploited weaknesses in Microsoft's Active Directory system. This granted them greater privileges to move laterally across the network. These techniques let the attackers maintain access, steal more credentials, and impersonate legitimate users.
The ultimate goal was often to compromise domain controllers. These servers are central to managing access across an entire organization's network. "To expand the geographic scope of its targets, NightEagle is updating its methods and adopting new techniques for persistence and lateral movement," Kaspersky researchers said.
Kaspersky did not name the affected Russian companies or specify how many were targeted. The firm also did not attribute a clear motivation to the attacks.
Origins and Previous Activity
NightEagle first gained public attention in July 2025. Chinese cybersecurity firm QiAnXin detailed an operation it tracked as APT-Q-95. QiAnXin said the group had been active since at least 2023, targeting Chinese organizations in strategically sensitive fields.
The targeted industries included defense, semiconductors, artificial intelligence, and quantum technology. QiAnXin characterized the activity as cyberespionage. At the time, researchers believed the hackers were targeting Microsoft Exchange servers with a potentially previously unknown vulnerability.
QiAnXin named the group NightEagle because its operators typically attacked during nighttime hours in China and frequently changed their operational infrastructure. Some Chinese researchers have previously linked the group to North America. These claims lack independent confirmation, and the group's true origin remains uncertain.





