The NightEagle group, also known as APT-Q-95, has been active since at least and initially targeted organizations in Asia. The group's latest campaign involves attacks on businesses in Russia. The attackers used compromised valid credentials to gain access to corporate VPNs. They deployed the GhostContainer backdoor on Microsoft Exchange servers, which incorporates components from several open-source projects, including the Neo-reGeorg tunnel and the GhostWebShell class. The backdoor is assembly containing three classes that implement its core functionality: Stub, App_Web_843e75cf5b63, and App_Web_8c9b251fb5b3.
Once the attackers gain sufficient privileges during an attack, they leverage RDP to move laterally within the internal network segment using legitimate services such as Microsoft dev tunnels and rdp2tcp. They also used the atexec utility from the Impacket toolkit to create scheduled tasks on target systems for network port forwarding. The NightEagle group is updating its methods to expand its geographic scope, adopting new techniques for persistence and lateral movement.[/subscribe_to_unlock_form]
The NightEagle group, also known as APT-Q-95, has been active since at least and initially targeted organizations in Asia. The group's latest campaign involves attacks on businesses in Russia. The attackers used compromised valid credentials to gain access to corporate VPNs. They deployed the GhostContainer backdoor on Microsoft Exchange servers, which incorporates components from several open-source projects, including the Neo-reGeorg tunnel and the GhostWebShell class. The backdoor is assembly containing three classes that implement its core functionality: Stub, App_Web_843e75cf5b63, and App_Web_8c9b251fb5b3.
Once the attackers gain sufficient privileges during an attack, they leverage RDP to move laterally within the internal network segment using legitimate services such as Microsoft dev tunnels and rdp2tcp. They also used the atexec utility from the Impacket toolkit to create scheduled tasks on target systems for network port forwarding. The NightEagle group is updating its methods to expand its geographic scope, adopting new techniques for persistence and lateral movement.[emaillocker id="1283"]
The attackers rely on known legitimate tools and infrastructure vulnerabilities, making timely detection of anomalies combined with a comprehensive approach to infrastructure protection crucial in hindering their goals. :Vulnerability, and the GhostWebShell class from the ysoserial utility. All of these components are publicly available on GitHub. (BlueKeep). They used the vulnerable mechanism to create a local account on the system and add it to the Administrators and Remote Desktop Users groups.
We recommend you to refer below link: https://github.com/MrTiz/CVE-2020-0688 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0708
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Execution | T1059.006 | Command and Scripting Interpreter | Python |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Defence Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Lateral Movement | T1021.001 | Remote Services | Remote Desktop Protocol |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
The following reports contain further technical details:
[/emaillocker]