Threat Advisory

NightEagle Group Deploys GhostContainer Backdoor on Microsoft Exchange Servers

Threat: Vulnerability
Threat Actor Name: NightEagle group (APT-Q-95)
Targeted Region: Asia, Europe, Russia
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The NightEagle group, also known as APT-Q-95, has been active since at least and initially targeted organizations in Asia. The group's latest campaign involves attacks on businesses in Russia. The attackers used compromised valid credentials to gain access to corporate VPNs. They deployed the GhostContainer backdoor on Microsoft Exchange servers, which incorporates components from several open-source projects, including the Neo-reGeorg tunnel and the GhostWebShell class. The backdoor is assembly containing three classes that implement its core functionality: Stub, App_Web_843e75cf5b63, and App_Web_8c9b251fb5b3.

Once the attackers gain sufficient privileges during an attack, they leverage RDP to move laterally within the internal network segment using legitimate services such as Microsoft dev tunnels and rdp2tcp. They also used the atexec utility from the Impacket toolkit to create scheduled tasks on target systems for network port forwarding. The NightEagle group is updating its methods to expand its geographic scope, adopting new techniques for persistence and lateral movement.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The NightEagle group, also known as APT-Q-95, has been active since at least and initially targeted organizations in Asia. The group's latest campaign involves attacks on businesses in Russia. The attackers used compromised valid credentials to gain access to corporate VPNs. They deployed the GhostContainer backdoor on Microsoft Exchange servers, which incorporates components from several open-source projects, including the Neo-reGeorg tunnel and the GhostWebShell class. The backdoor is assembly containing three classes that implement its core functionality: Stub, App_Web_843e75cf5b63, and App_Web_8c9b251fb5b3.

Once the attackers gain sufficient privileges during an attack, they leverage RDP to move laterally within the internal network segment using legitimate services such as Microsoft dev tunnels and rdp2tcp. They also used the atexec utility from the Impacket toolkit to create scheduled tasks on target systems for network port forwarding. The NightEagle group is updating its methods to expand its geographic scope, adopting new techniques for persistence and lateral movement.[emaillocker id="1283"]

The attackers rely on known legitimate tools and infrastructure vulnerabilities, making timely detection of anomalies combined with a comprehensive approach to infrastructure protection crucial in hindering their goals. :Vulnerability, and the GhostWebShell class from the ysoserial utility. All of these components are publicly available on GitHub. (BlueKeep). They used the vulnerable mechanism to create a local account on the system and add it to the Administrators and Remote Desktop Users groups.

RECOMMENDATION:

We recommend you to refer below link: https://github.com/MrTiz/CVE-2020-0688 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0708

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Execution T1059.006 Command and Scripting Interpreter Python
Persistence T1543.003 Create or Modify System Process Windows Service
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Lateral Movement T1021.001 Remote Services Remote Desktop Protocol
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu