Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia
Over the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.
A cyberespionage group previously known for targeting sensitive technology and defense organizations in China has expanded its operations to Russian companies, according to new research released this week.
The group, known as NightEagle or APT-Q-95, has been active since at least 2023 but had previously focused its attacks in Asia. Over the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.
In most cases, the hackers used stolen credentials to gain access to corporate networks through virtual private networks, or VPNs. Once inside a network, NightEagle targeted Microsoft Exchange email servers and installed a backdoor known as GhostContainer, which allows attackers to remotely control compromised servers, evade some Windows security and logging mechanisms and redirect network traffic.
Source: https://therecord.media/hacking-group-nighteagle-expands-russia-china
Related breach coverage
- Hackers claim breach of Russian election systems days before parliamentary vote2026-09-17
An anonymous hacking group claimed to have broken into computer systems connected to Russia’s election infrastructure just days before the country begins voting for a new parliament.
- SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets2026-09-17
Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher Guy Yasur have traced a tight cluster of SpiceRAT command‑and‑control servers that predate and extend Bitdefender’s August 2026 SilkParasite report. The work doesn’t dissect malware samples; it maps the network side of the […]
- SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 1152026-09-20
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot […]
- Google Gemini also Broke Out of Its Test Environment2026-09-19
Google Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into the systems of three real companies during a cybersecurity test in May. The incident is the first publicly known case in which a Google […]