Threats & Adversaries · APT / Espionage

NightEagle Reuses Credentials and GitHub Tooling

Kaspersky GERT says NightEagle (APT-Q-95) has shifted its campaign to Russian businesses, using compromised VPN credentials, Cloudflare WARP tunnels, and tools hosted on GitHub. The group has been active since at least 2023 and previously focused on organizations in Asia.

The access path is plain but hard to spot: valid credentials open the VPN, then the operators use Microsoft Exchange as a foothold and move through Active Directory and RDP with downloaded tunneling tools. Kaspersky says GhostContainer can run in memory, proxy traffic, and evade common logging and scanning hooks, which means the intrusion can look like legitimate remote access instead of dropped malware.

The larger lesson is reuse. Because parts of the tradecraft are built from public components, the same Exchange/AD/RDP playbook is easier for other operators to copy or adapt, so environments that treat cloud-tunneled logins and remote admin channels as trusted inherit the same exposure even if NightEagle itself is not present.

1 source · 4h ago

CVE-2019-0708

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: a remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date May 3 · date passed

CVE-2020-0688

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: a remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date May 3 · date passed

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-09-16

Every edition of this story: NightEagle Reuses Credentials and GitHub Tooling

More from today