NightEagle Russian enterprise VPN GhostContainer campaign
Campaign
Summary
Hide ▲
Show ▼
The NightEagle (APT-Q-95) campaign is actively using compromised VPN credentials and GhostContainer to reach Russian enterprise networks, increasing the risk of persistent access and lateral movement. The operators are combining stolen access with a backdoor that can control Microsoft Exchange Server systems, run code, and load modules. The activity has been active since at least 2023 and was highlighted in July 2025. The operation shows sustained targeting rather than a one-off intrusion.
Related Happenings
Chinese-speaking threat actor Central Asia government campaign
Campaign
H score29
First: 31.07.2026 21:52
Last: 31.07.2026 21:52
Sources 1
About this happening:
The Chinese-speaking threat actor is running an active campaign against government organizations in Central Asia and Syria, expanding risk across multiple public-secto...
Chinese-speaking threat actor Central Asia government campaign
CampaignAbout this happening: The Chinese-speaking threat actor is running an active campaign against government organizations in Central Asia and Syria, expanding risk across multiple public-secto...
Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
Campaign
H score32
First: 28.07.2026 14:55
Last: 28.07.2026 14:55
Sources 1
About this happening:
Nimbus Manticore is running a covert-access campaign across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve access insi...
Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
CampaignAbout this happening: Nimbus Manticore is running a covert-access campaign across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve access insi...
GoSerpent malware activity targeting Southeast Asian entities
Malware Activity
H score26
First: 17.07.2026 11:46
Last: 17.07.2026 11:46
Sources 1
About this happening:
GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
GoSerpent malware activity targeting Southeast Asian entities
Malware ActivityAbout this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
Campaign
H score39
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
CampaignAbout this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
Webworm multi-country targeting campaign against government and enterprise victims
Campaign
H score38
First: 20.05.2026 15:51
Last: 20.05.2026 15:51
Sources 1
About this happening:
Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Webworm multi-country targeting campaign against government and enterprise victims
CampaignAbout this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Timeline
-
16.09.2026 18:27 2 articles · 2h ago
NightEagle targets Russian enterprises with GhostContainer over VPN access
Initial DisclosureKaspersky identifies NightEagle (APT-Q-95) attacks against Russian enterprises, describing compromised valid VPN credentials used to reach corporate VPNs, GhostContainer deployment on Microsoft Exchange Server, and lateral movement that leverages Microsoft dev tunnels, rdp2tcp, and Active Directory abuse including CVE-2019-0708.
Show sources
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers — thehackernews.com — 16.09.2026 18:27
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers — thehackernews.com — 16.09.2026 18:27