Threat Advisory

Customized Chisel Variant Enables Internal Network Penetration

Threat: Malware Campaign
Threat Actor Name: NightEagle
Targeted Region: China
Threat Actor Region: North America
Targeted Sector: Technology & IT, Government & Defense
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The APT group, dubbed NightEagle Known for its stealth and speed, the group has executed cyber-espionage campaigns mainly targeting China's top-tier sectors, including artificial intelligence, semiconductor industries, quantum technology, and military domains. Their operation is notably methodical and well-funded, using a unique domain and IP switching mechanism for each target, often leveraging freshly purchased VPS infrastructure. NightEagle’s ability to rapidly switch infrastructure and employ tailored tactics for each victim showcases advanced planning and execution, akin to the speed and precision of a nocturnal eagle—hence the name. The group’s strategy includes exploiting unknown vulnerabilities in Microsoft Exchange servers and using obfuscated command and control methods to evade detection.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The APT group, dubbed NightEagle Known for its stealth and speed, the group has executed cyber-espionage campaigns mainly targeting China's top-tier sectors, including artificial intelligence, semiconductor industries, quantum technology, and military domains. Their operation is notably methodical and well-funded, using a unique domain and IP switching mechanism for each target, often leveraging freshly purchased VPS infrastructure. NightEagle’s ability to rapidly switch infrastructure and employ tailored tactics for each victim showcases advanced planning and execution, akin to the speed and precision of a nocturnal eagle—hence the name. The group’s strategy includes exploiting unknown vulnerabilities in Microsoft Exchange servers and using obfuscated command and control methods to evade detection.[emaillocker id="1283"]

The breakdown begins with the detection of suspicious DNS queries to synologyupdates.com, a fake domain spoofing the legitimate Synology service. Analysis revealed that compromised internal hosts were making DNS requests every four hours due to a scheduled execution of SynologyUpdate.exe, which was identified as a customized Chisel variant. This tool was designed for internal network tunneling using a SOCKS proxy over HTTPS to an attacker-controlled domain. Further investigation uncovered memory-resident malware within the Exchange server, delivered via a .NET-based ASP.NET loader . These loaders dynamically created virtual directories to stealthily execute payloads on IIS. Notably, attackers had used a yet-unknown zero-day vulnerability to extract the Exchange machineKey, enabling deserialization-based exploitation and access to email data. They brute-forced Exchange versions until a match was found, enabling near-universal email theft capability across targeted entities. Attack logs showed data exfiltration occurring over a prolonged period, emphasizing the silent persistence of this intrusion. NightEagle also employed highly adaptive infrastructure—each domain used once per victim—with obfuscation methods such as redirecting DNS to local addresses during dormant phases and using well-known U.S.-based cloud providers during active C2 sessions.

NightEagle represents a textbook example of a high-level, well-resourced APT group with focused geopolitical motives and a high degree of operational maturity. The threat actors operate during a fixed time window aligned with the Western U.S. time zone, never working outside their designated hours—a strong indicator of state backing and organizational discipline. Their cyber weapon arsenal includes custom-built malware, precise exploitation tactics, and strategic targeting aligned with global developments, such as China's rise in AI innovation. Domain name analysis further revealed consistent patterns, such as use of the Tucows registrar and infrastructure tied to U.S. cloud providers. Qianxin’s layered security ecosystem—comprising AISOC, EDR, NDR, TIP, and SOAR—proved instrumental in not only detecting and containing the attack but also mapping the adversary's infrastructure and behavioral patterns. To counter similar threats, Qianxin released a self-check tool and provided detailed forensic guidelines for detecting infected Exchange servers, such as checking for specific DLL naming patterns and suspicious User-Agent strings.

THREAT PROFILE:

Tactic Technique ID Technique Sub-Technique
Initial Access T1190 Exploit Public-Facing Application -
T1195.002 Supply Chain Compromise Compromise Software Supply Chain
Execution T1059.005 Command and Scripting Interpreter Visual Basic
T1203 Exploitation for Client Execution -
Persistence T1505.003 Server Software Component Web Shell
Defense Evasion T1140 Deobfuscate Decode Files or Info -
Credential Access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Discovery T1083 File and Directory Discovery -
Lateral Movement T1570 Lateral Tool Transfer -
Command and Control T1090.003 Proxy Multi-hop Proxy
T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -
Impact T1485 Data Destruction -

MBC MAPPING:

Objective Behavior ID Behavior
Execution E1203 Sysinternals
Defense Evasion E1014 Rootkit
Lateral Movement B0026 Malicious Network Driver
Collection E1560 Encryption
Communication Micro-objective C0014 Echo Request

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu