NightEagle targets Russian companies

Kaspersky Securelist Version 1 original current

Imported from official source

Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.

This version

Version
1 of 1
Recorded
September 20, 2026 19:52
Change
Initial
Content hash
e358dfb864c748aa11fd8ccf04cc766a
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.