16-09-2026
NightEagle targets Russian companies
https://securelist.com/tr/nighteagle-apt-ghostcontainer-and-tunneling/121323/
Report completeness: High
Actors/Campaigns:
Nighteagle
Threats:
Ghostcontainer
Neo-regeorg_tool
Ysoserial_tool
Dev_tunnels_tool
Rdp2tcp_tool
Atexec_tool
Impacket_tool
Bluekeep_vuln
Dcsync_technique
Victims:
Russian businesses
Geo:
Asia, Russia, Russian
CVEs:
CVE-2019-0708 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- microsoft windows_7 (-)
- microsoft windows_server_2008 (-, r2)
CVE-2020-0688 [Vulners]
CVSS V3.1: 8.8,
Vulners: Exploitation: True
Soft:
- microsoft exchange_server (2010, 2013, 2016, 2019)
TTPs:
Tactics: 2
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1003, T1003.006, T1021.001, T1053.005, T1059.001, T1078, T1090, T1098, T1133, T1136.001, have more...
IOCs:
File: 5
Command: 1
Hash: 5
Url: 2
Soft:
Microsoft Exchange, trueconf, Active Directory
Algorithms:
zip
Win API:
NET
Languages:
powershell
Links:
https://github.com/V-E-O/rdp2tcp