NightEagle APT Uses GhostContainer and Tunneling Tools in Attacks on Russian Organizations

Summary
Kaspersky describes NightEagle attacks on Russian organizations, detailing the GhostContainer backdoor, tunneling tools, exploited vulnerabilities, and techniques used to move through networks and compromise Active Directory.
Key points
- Kaspersky reports investigating several NightEagle (APT-Q-95) incidents over the past year, including attacks on businesses in Russia.
- Attackers typically gained initial access to corporate VPNs with compromised valid credentials.
- The group deployed GhostContainer on Microsoft Exchange servers; Kaspersky suspects it used stolen Exchange cryptographic keys and a modified VIEWSTATE parameter to launch the backdoor in memory.
- For network access and lateral movement, attackers combined Microsoft dev tunnels, rdp2tcp, RDP, and Windows port forwarding; RDP virtual channel log events 132 and 148 can reveal rdp2tcp use.
- NightEagle exploited CVE-2019-0708 (BlueKeep) in one incident and used Kerberos ticket techniques and DCSync attempts to obtain credentials and compromise Active Directory.
- Kaspersky lists detection rules and network signatures for GhostContainer, tunneling, Impacket activity, DCSync, and BlueKeep exploitation.
Article Details
- Attack Vectors
- Compromised valid credentials provided access to corporate VPNs. Connections originated from Russian IP addresses linked to Cloudflare WARP tunnels and addresses associated with European virtual infrastructure providers.
- The attackers deployed an in-memory backdoor on email servers. Researchers could not establish the delivery method, but assessed with high confidence that extracted ASP.NET cryptographic keys and a modified VIEWSTATE parameter enabled payload execution.
- Archived tunneling utilities hosted in repositories were disguised with legitimate-looking repository, archive, and executable names.
- Network tunnels, TCP forwarding, and remote desktop connections enabled access to internal systems and lateral movement.
- Exploitation of a remote desktop implementation vulnerability enabled creation of a local account and assignment to privileged groups.
- After obtaining sufficient privileges, the attackers attempted directory replication to obtain domain password hashes and used long-lived Kerberos tickets to access target resources.
- Defensive Notes
- Monitor remote desktop operational events 132 and 148 for virtual channel names such as rdp2tcp or unexpected alphanumeric names.
- Monitor DNS access to tunneling domains, traffic redirection, and unusual remote desktop activity; the described tunnels maintained access without opening additional suspicious ports.
- Monitor scheduled-task creation, network port-forwarding configuration, suspicious utility downloads, credential-dumping file artifacts, and directory replication attempts.
- Monitor suspicious .NET assembly loading through PowerShell reflection and other host artifacts associated with backdoor deployment.
- The source recommends timely anomaly detection and well-configured infrastructure monitoring because the attackers use legitimate utilities and known vulnerabilities.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| MD5 | 1dcafb7f8448683281106b06dd22409a | Listed attack artifact hash associated with AdobeSync.exe. |
| MD5 | 1f3034b706c78b35d8e34044e68c693a | Listed attack artifact hash associated with adobe_32.exe. |
| MD5 | 3ecd1cd627d0340c92901a478a7caad8 | Hash listed in the article's indicators of compromise without an associated filename. |
| MD5 | 4aa9fb1bf9223dfcdac920759bc7a3c7 | Listed attack artifact hash associated with 1c-office-plugin.exe, 1cbroker.exe, and trueconf.exe. |
| MD5 | 631fb131a56caf4ca0f287ed73e876ab | Listed attack artifact hash associated with App_Web_Container_1.dll. |
| URL | hxxps[:]//github[.]com/browserthemes/resourcepack | Repository used by the attackers to store network tools and explicitly listed as an indicator of compromise. |
| URL | hxxps[:]//github[.]com/browserthemes/resourcepack/releases/download/main/resource-pack[.]zip | Archive URL used by the attackers to host tunneling and traffic-redirection tools. |
| URL | hxxps[:]//github[.]com/mirror-js/mirror-js | Repository used by the attackers to store network tools and explicitly listed as an indicator of compromise. |
| URL | hxxps[:]//github[.]com/mirror-js/mirror-js/refs/heads/main/js/js-webpack[.]zip | Archive URL used by the attackers to host tunneling and traffic-redirection tools. |
| URL | hxxps[:]//github[.]com/mirror-js/mirror-js/refs/heads/main/js/jsonp-pack[.]zip | Archive URL used by the attackers to host tunneling and traffic-redirection tools. |
MITRE ATT&CK
T1003.006 · DCSyncAfter obtaining sufficient privileges, NightEagle attempted DCSync replication of the Domain-Password object to obtain domain account password hashes.T1021.001 · Remote Desktop ProtocolThe attackers used RDP to move laterally within victims' internal networks.T1036.005 · Match Legitimate Resource Name or LocationTool repositories and archives had legitimate-looking names, and executable files mimicked legitimate software with names such as AdobeSync.exe and trueconf.exe.T1053.005 · Scheduled TaskNightEagle used Impacket's atexec utility to create scheduled tasks that configured network port forwarding.T1078 · Valid AccountsNightEagle used compromised valid credentials to access corporate VPNs in most investigated incidents.T1090 · ProxyGhostContainer provides network traffic redirection and socket forwarding, while netsh portproxy forwards traffic between internal ports and systems.T1105 · Ingress Tool TransferThe attackers downloaded archived tunneling and traffic-redirection tools from GitHub repositories onto compromised systems.T1133 · External Remote ServicesCorporate VPN connections provided initial access to victim networks.T1136.001 · Local AccountThe attackers created a local account through the BlueKeep exploit and added it to Administrators and Remote Desktop Users.T1210 · Exploitation of Remote ServicesIn one incident, the attackers exploited CVE-2019-0708 in RDP to create an account and grant privileged group membership.T1562.001 · Disable or Modify ToolsGhostContainer overwrites addresses in amsi.dll to evade AMSI detection.T1562.002 · Disable Windows Event LoggingGhostContainer overwrites addresses in ntdll.dll to evade Windows Event Log mechanisms.T1572 · Protocol TunnelingNightEagle combined Microsoft dev tunnels with rdp2tcp to expose RDP and tunnel TCP traffic over established RDP connections.
CVE
CVE-2019-0708In one incident, they exploited a well-known RDP implementation vulnerability, CVE-2019-0708 (BlueKeep).CVE-2020-0688It incorporates components from several open-source projects, including the Neo-reGeorg tunnel, an exploit for the CVE-2020-0688 vulnerability, and the GhostWebShell class from the ysoserial utility.
Threat Actors
Malware
Vendors
CloudflareVPN connections originated from IP addresses in the Russian segment linked to Cloudflare WARP tunnels, as well as from IP addresses associated with European virtual infrastructure providers.GitHubAll of these components are publicly available on GitHub.KasperskyKaspersky products detect the GhostContainer backdoor as Trojan.MSIL.GhostContainer.gen.MicrosoftGhostContainer on Microsoft Exchange
Products
Active DirectoryTo obtain elevated privileges and move laterally through the network, NightEagle exploited various vulnerabilities in Active Directory.Cloudflare WARPVPN connections originated from IP addresses in the Russian segment linked to Cloudflare WARP tunnels, as well as from IP addresses associated with European virtual infrastructure providers.Kaspersky Anti Targeted AttackKaspersky Anti Targeted Attack (KATA) detects this malicious activity in network traffic.Kaspersky Endpoint Detection and Response ExpertDeploying a backdoor on a target host produces numerous characteristic artifacts, which allow Kaspersky Endpoint Detection and Response Expert to alert users to anomalies in the infrastructure in a timely manner.Kaspersky Threat AnalysisGhostContainer samples identified by the Similarity technology from Kaspersky Threat AnalysisKaspersky Threat Attribution EngineThis toolkit also includes the analytical solution Kaspersky Threat Attribution Engine (KTAE), which helps SOC analysts and incident responders determine which APT groups malware can be attributed to.Microsoft dev tunnelsMicrosoft dev tunnelsMicrosoft Exchange ServerGhostContainer on Microsoft ExchangeMicrosoft Windowsthrough the x-owa-urlpostdata headers and evades detection by the Antimalware Scan Interface (AMSI) and Windows Event Log mechanisms by overwriting addresses in amsi.dll and ntdll.dll.PowerShellDetection of a malicious DLL’s .NET assembly being loaded via PowerShell: suspicious_assembly_loading_into_powershell_via_reflection
Tools
atexecThe attackers also used the atexec utility from the Impacket toolkit to create scheduled tasks on target systems.ImpacketThe attackers also used the atexec utility from the Impacket toolkit to create scheduled tasks on target systems.Neo-reGeorgIt incorporates components from several open-source projects, including the Neo-reGeorg tunnel, an exploit for the CVE-2020-0688 vulnerability, and the GhostWebShell class from the ysoserial utility.netshnetsh interface portproxy add v4tov4 listenport=443 connectaddress=10.0.12.101 connectport=445rdp2tcprdp2tcpysoserialIt incorporates components from several open-source projects, including the Neo-reGeorg tunnel, an exploit for the CVE-2020-0688 vulnerability, and the GhostWebShell class from the ysoserial utility.