Threat Advisory

Night Eagle Abuses ASP.NET Virtual Directories in Attacks

Threat: Malware
Threat Actor Name: Night Eagle
Targeted Region: China
Threat Actor Region: North America
Targeted Sector: Technology & IT, Aerospace & Aviation, Government & Defense, Critical Infrastructure
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Night Eagle (APT-Q-95) is a well-funded APT group tracked by Qianxin Pangu, known for using unknown Exchange exploit chains and dynamic infrastructure such as rotating IPs and unique domains per target. Their operations are focused on Chinese sectors including high-tech, semiconductors, AI, and military industries, aiming to steal sensitive data and intellectual property. Attacks occur exclusively during China’s night hours, and the group deletes traces after data exfiltration. Their spoofed domains, like synologyupdates[.]com, resolve to private IPs during inactive periods to avoid detection. The attack was initially discovered through abnormal DNS traffic flagged by Qianxin Tianyan NDR and further analyzed by AISOC and Tianqing EDR platforms.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Night Eagle (APT-Q-95) is a well-funded APT group tracked by Qianxin Pangu, known for using unknown Exchange exploit chains and dynamic infrastructure such as rotating IPs and unique domains per target. Their operations are focused on Chinese sectors including high-tech, semiconductors, AI, and military industries, aiming to steal sensitive data and intellectual property. Attacks occur exclusively during China’s night hours, and the group deletes traces after data exfiltration. Their spoofed domains, like synologyupdates[.]com, resolve to private IPs during inactive periods to avoid detection. The attack was initially discovered through abnormal DNS traffic flagged by Qianxin Tianyan NDR and further analyzed by AISOC and Tianqing EDR platforms.[emaillocker id="1283"]

The group used a modified Chisel tunneling tool disguised as SynologyUpdate.exe, which set up scheduled SOCKS proxies connecting to C&C infrastructure every four hours. It included hard-coded credentials and skipped TLS checks. The compromised host communicated with the internal Exchange server, leading to the discovery of fileless malware loaded via malicious ASP.NET DLLs (App_Web_cn*[.]dll). These created virtual directories (e.g., ~/auth/lang/cn[.]aspx), which triggered the malware in memory using embedded .NET assemblies. Attackers used these paths to execute payloads without writing to disk, avoiding traditional detection. They exploited unknown Exchange vulnerabilities to steal machineKeys, enabling deserialization and remote access to mailbox data across multiple versions of Exchange.

Night Eagle operates during fixed nighttime hours based on UTC-8, pointing to a likely U.S. origin. Their infrastructure includes unique domains registered through Tucows and IPs from providers like DigitalOcean and Akamai. Each attack uses a unique domain and payload, with DNS patterns showing loopback IPs during idle times and U.S.-based IPs during active sessions. Targeting has shifted with geopolitical changes, including attacks on China’s AI and LLM sectors. Spoofed domains like comfyupdate[.]org mirror legitimate tools to blend in. The group’s malware is launched via scheduled tasks at regular intervals, showing disciplined control and a clear focus on long-term.

THREAT PROFILE:

Tactic Technique ID Technique Sub-Technique
Resource Development T1583.001 Acquire Infrastructure Domains
T1587.004 Develop Capabilities Exploits
T1587.001 Malware
T1583.003 Acquire Infrastructure Virtual Private Server
Initial Access T1190 Exploit Public-Facing Application -
Execution T1059.001 Command and Scripting Interpreter PowerShell
T1053.005 Scheduled Task/Job Scheduled Task
Persistence T1505.004 Server Software Component IIS Components
T1053.005 Scheduled Task/Job Scheduled Task
T1505.003 Server Software Component Web Shell
Privilege Escalation T1055.001 Process Injection Dynamic-link Library Injection
T1053.005 Scheduled Task/Job Scheduled Task
Defense Evasion T1070.009 Indicator Removal Clear Persistence
T1055.001 Process Injection Dynamic-link Library Injection
T1070.004 Indicator Removal File Deletion
T1027.011 Obfuscated Files or Information Fileless Storage
T1036.005 Masquerading Match Legitimate Name or Location
T1027 Obfuscated Files or Information -
Discovery T1049 System Network Connections Discovery -
Lateral Movement T1570 Lateral Tool Transfer -
Collection T1114.001 Email Collection Local Email Collection
Command and Control T1572 Protocol Tunneling -
T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1048.001 Exfiltration Over Alternative Protocol Exfiltration Over Symmetric Encrypted Non-C2 Protocol

 

REFERENCES:

  • Eventus Security Threat Research & Development Team
[/emaillocker]
crossmenu