Find notable cyber news and cases, enriched with sources, timelines, and signals.

NightEagle Russian enterprise VPN GhostContainer campaign

Campaign
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

The NightEagle (APT-Q-95) campaign is actively using compromised VPN credentials and GhostContainer to reach Russian enterprise networks, increasing the risk of persistent access and lateral movement. The operators are combining stolen access with a backdoor that can control Microsoft Exchange Server systems, run code, and load modules. The activity has been active since at least 2023 and was highlighted in July 2025. The operation shows sustained targeting rather than a one-off intrusion.

Related Happenings

Chinese-speaking threat actor Central Asia government campaign

Campaign
H score29 First: 31.07.2026 21:52 Last: 31.07.2026 21:52 Sources 1

About this happening: The Chinese-speaking threat actor is running an active campaign against government organizations in Central Asia and Syria, expanding risk across multiple public-secto...

Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia

Campaign
H score32 First: 28.07.2026 14:55 Last: 28.07.2026 14:55 Sources 1

About this happening: Nimbus Manticore is running a covert-access campaign across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve access insi...

GoSerpent malware activity targeting Southeast Asian entities

Malware Activity
H score26 First: 17.07.2026 11:46 Last: 17.07.2026 11:46 Sources 1

About this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...

GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations

Campaign
H score39 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...

Webworm multi-country targeting campaign against government and enterprise victims

Campaign
H score38 First: 20.05.2026 15:51 Last: 20.05.2026 15:51 Sources 1

About this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...

Timeline

  1. 16.09.2026 18:27 2 articles · 2h ago

    NightEagle targets Russian enterprises with GhostContainer over VPN access

    Initial Disclosure

    Kaspersky identifies NightEagle (APT-Q-95) attacks against Russian enterprises, describing compromised valid VPN credentials used to reach corporate VPNs, GhostContainer deployment on Microsoft Exchange Server, and lateral movement that leverages Microsoft dev tunnels, rdp2tcp, and Active Directory abuse including CVE-2019-0708.

    Show sources