Protect.Computer
NEWS

China's NightEagle APT Expands from Asia to Target Russian Companies

· 1 min read · Network safety
China's NightEagle APT Expands from Asia to Target Russian Companies

A Chinese cyberespionage group known as NightEagle — also tracked as APT-Q-95 — has expanded its targeting beyond Asia to include Russian businesses, according to new research from Kaspersky released this week. The group has been active since at least 2023, initially focusing on sensitive technology and defense organizations in China; it first came to public attention in July 2025 when Chinese firm QiAnXin documented its operations. Now Kaspersky says it has investigated several incidents involving NightEagle at Russian companies, where the group used stolen credentials to access corporate networks over VPN before deploying a custom backdoor called GhostContainer on Microsoft Exchange servers. GhostContainer lets attackers remotely control compromised servers, evade Windows security and logging mechanisms, and redirect network traffic — while executing entirely in the server’s memory, which helps it avoid detection.

Once inside a network, NightEagle exploited weaknesses in Active Directory to escalate privileges and move laterally, ultimately targeting domain controllers — the servers that govern user and computer access across an entire organization. The group used GitHub to store archives of hacking tools, disguising them as legitimate software including names like AdobeSync and TrueConf. Kaspersky researchers assess that NightEagle is updating its techniques to support a broader geographic scope: “To expand the geographic scope of its targets, NightEagle is updating its methods and adopting new techniques for persistence and lateral movement.” The firm did not identify the affected Russian companies or disclose the number of organizations involved.

Sources

Related reading