Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-19 · updated: 2026-09-19 · tags: [incident, defence, espionage] · confidence: high · severity: high · affected_sectors: [defence] · au_impact: true

NightEagle (APT-Q-95), an espionage group active since at least 2023 that had focused on sensitive technology and defence organisations in China, has expanded into Russian companies, according to Kaspersky investigations over the past year. Initial access in most cases came from stolen credentials used over VPNs; inside the network the group targeted Microsoft Exchange servers and deployed GhostContainer, a backdoor that allows remote control, evades Windows security and logging mechanisms, and redirects network traffic. Kaspersky could not establish how the backdoor was first planted, but believes the group used a technique it has observed before: extracting encryption keys from Exchange and manipulating Microsoft's web application framework to run the implant in server memory. The actors stored tooling in GitHub repositories disguised as legitimate software, including names resembling AdobeSync and TrueConf, and exploited Active Directory weaknesses after establishing a foothold.

Attribute Detail
Sector Defence
Date 2026-09-19
Source The Record
Reliability Tier 2