Summary
- Kaspersky says NightEagle has targeted Russian manufacturing and construction organisations after previously being observed in Asia.
- Investigated intrusions began with compromised VPN credentials and used the GhostContainer backdoor on Microsoft Exchange servers.
- The campaign relied heavily on legitimate services and older internal vulnerabilities before reaching core identity infrastructure.
A cyberespionage group previously observed operating against organisations in Asia has expanded into Russian manufacturing and construction, according to Kaspersky, which says investigated intrusions ultimately reached the systems controlling network identities and permissions.
Kaspersky tracks the group as NightEagle, also known as APT-Q-95. The company said its Global Emergency Response Team had investigated several intrusions over the past year and assessed the Russian campaign as the group’s first known move into a new region.
NightEagle is a researcher-assigned threat-actor designation. Kaspersky’s report describes the observed tools, infrastructure, and behaviour but does not provide a public government attribution of the activity to a specific state.
In most investigated incidents, the attackers entered organisations using stolen, valid VPN credentials. They then attempted to disguise their apparent location through Cloudflare WARP tunnels and European virtual-infrastructure providers.
Kaspersky said the attackers installed a custom backdoor called GhostContainer on Microsoft Exchange servers. The company assesses with high confidence that the malicious code was injected directly into server memory rather than installed as a conventional file on disk.
The backdoor provided remote control and attempted to make malicious commands resemble normal web traffic, according to the researchers. Kaspersky also said it interfered with Windows security scanning and logging.
NightEagle then used legitimate tools to move further into compromised networks. Its operators stored tools on GitHub, renamed files to resemble ordinary business software, and abused Microsoft development functionality alongside public remote-access utilities.
Older unpatched vulnerabilities on internal systems were also used to create unauthorised administrator accounts. Kaspersky said the attack chain ultimately reached the central infrastructure responsible for identities, passwords, and permissions, giving the attackers extensive control over victim environments.
The combination is notable because relatively little of the operation depends on highly exotic technology. Stolen VPN credentials, legitimate development services, remote-access tooling, Exchange servers, and old internal vulnerabilities can all be present in ordinary enterprise estates.
That makes the campaign an example of why perimeter security and vulnerability severity cannot be considered separately from identity. A valid VPN account can move an attacker past controls intended to stop unauthenticated access, after which weaknesses in internal systems become more valuable than vulnerabilities visible from the internet.
The choice of Russian manufacturing and construction organisations also places industrial businesses inside a cyberespionage context rather than the ransomware-driven disruption more commonly associated with attacks on the sector. The likely objective in such intrusions can include persistent access and information collection rather than immediate operational interruption.
Kaspersky’s visibility is limited to incidents it investigated, so the finding does not establish the full geographic scope of NightEagle activity. The company describes Russia as the first known expansion beyond Asia, which leaves open the possibility of activity elsewhere that has not been observed or publicly attributed.
The shift is nevertheless material for threat tracking. Actor profiles built around a familiar country or sector can become stale when operators acquire new access, customers, objectives, or infrastructure. NightEagle’s movement into a different region suggests that historic victimology should be treated as evidence of past behaviour rather than a fixed boundary around future targets.





