EXECUTIVE SUMMARY
Night Eagle (APT-Q-95) is a well-funded APT group tracked by Qianxin Pangu, known for using unknown Exchange exploit chains and dynamic infrastructure such as rotating IPs and unique domains per target. Their operations are focused on Chinese sectors including high-tech, semiconductors, AI, and military industries, aiming to steal sensitive data and intellectual property. Attacks occur exclusively during China’s night hours, and the group deletes traces after data exfiltration. Their spoofed domains, like synologyupdates[.]com, resolve to private IPs during inactive periods to avoid detection. The attack was initially discovered through abnormal DNS traffic flagged by Qianxin Tianyan NDR and further analyzed by AISOC and Tianqing EDR platforms.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Night Eagle (APT-Q-95) is a well-funded APT group tracked by Qianxin Pangu, known for using unknown Exchange exploit chains and dynamic infrastructure such as rotating IPs and unique domains per target. Their operations are focused on Chinese sectors including high-tech, semiconductors, AI, and military industries, aiming to steal sensitive data and intellectual property. Attacks occur exclusively during China’s night hours, and the group deletes traces after data exfiltration. Their spoofed domains, like synologyupdates[.]com, resolve to private IPs during inactive periods to avoid detection. The attack was initially discovered through abnormal DNS traffic flagged by Qianxin Tianyan NDR and further analyzed by AISOC and Tianqing EDR platforms.[emaillocker id="1283"]
The group used a modified Chisel tunneling tool disguised as SynologyUpdate.exe, which set up scheduled SOCKS proxies connecting to C&C infrastructure every four hours. It included hard-coded credentials and skipped TLS checks. The compromised host communicated with the internal Exchange server, leading to the discovery of fileless malware loaded via malicious ASP.NET DLLs (App_Web_cn*[.]dll). These created virtual directories (e.g., ~/auth/lang/cn[.]aspx), which triggered the malware in memory using embedded .NET assemblies. Attackers used these paths to execute payloads without writing to disk, avoiding traditional detection. They exploited unknown Exchange vulnerabilities to steal machineKeys, enabling deserialization and remote access to mailbox data across multiple versions of Exchange.
Night Eagle operates during fixed nighttime hours based on UTC-8, pointing to a likely U.S. origin. Their infrastructure includes unique domains registered through Tucows and IPs from providers like DigitalOcean and Akamai. Each attack uses a unique domain and payload, with DNS patterns showing loopback IPs during idle times and U.S.-based IPs during active sessions. Targeting has shifted with geopolitical changes, including attacks on China’s AI and LLM sectors. Spoofed domains like comfyupdate[.]org mirror legitimate tools to blend in. The group’s malware is launched via scheduled tasks at regular intervals, showing disciplined control and a clear focus on long-term.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-Technique |
| Resource Development | T1583.001 | Acquire Infrastructure | Domains |
| T1587.004 | Develop Capabilities | Exploits | |
| T1587.001 | Malware | ||
| T1583.003 | Acquire Infrastructure | Virtual Private Server | |
| Initial Access | T1190 | Exploit Public-Facing Application | - |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| T1053.005 | Scheduled Task/Job | Scheduled Task | |
| Persistence | T1505.004 | Server Software Component | IIS Components |
| T1053.005 | Scheduled Task/Job | Scheduled Task | |
| T1505.003 | Server Software Component | Web Shell | |
| Privilege Escalation | T1055.001 | Process Injection | Dynamic-link Library Injection |
| T1053.005 | Scheduled Task/Job | Scheduled Task | |
| Defense Evasion | T1070.009 | Indicator Removal | Clear Persistence |
| T1055.001 | Process Injection | Dynamic-link Library Injection | |
| T1070.004 | Indicator Removal | File Deletion | |
| T1027.011 | Obfuscated Files or Information | Fileless Storage | |
| T1036.005 | Masquerading | Match Legitimate Name or Location | |
| T1027 | Obfuscated Files or Information | - | |
| Discovery | T1049 | System Network Connections Discovery | - |
| Lateral Movement | T1570 | Lateral Tool Transfer | - |
| Collection | T1114.001 | Email Collection | Local Email Collection |
| Command and Control | T1572 | Protocol Tunneling | - |
| T1071.001 | Application Layer Protocol | Web Protocols | |
| Exfiltration | T1048.001 | Exfiltration Over Alternative Protocol | Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
REFERENCES: