Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia
A cyberespionage group previously known for targeting sensitive technology and defense organizations in China has expanded its operations to Russian companies, according to new research released this week.
The group, known as NightEagle or APT-Q-95, has been active since at least 2023 but had previously focused its attacks in Asia. Over the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.
In most cases, the hackers used stolen credentials to gain access to corporate networks through virtual private networks, or VPNs. Once inside a network, NightEagle targeted Microsoft Exchange email servers and installed a backdoor known as GhostContainer, which allows attackers to remotely control compromised servers, evade some Windows security and logging mechanisms and redirect network traffic.
Kaspersky said it could not determine exactly how the hackers initially planted GhostContainer on the Exchange servers. Researchers believe, however, that the attackers used a technique they had observed previously that involves extracting encryption keys from Exchange and manipulating Microsoft's web application framework to execute the backdoor directly in the server's memory.
The group also used GitHub to store archives containing hacking tools, disguising repositories and files with names designed to resemble legitimate software, including AdobeSync and TrueConf.
After gaining an initial foothold, the hackers exploited weaknesses in Active Directory, Microsoft's system for managing users, computers and permissions across corporate networks, to obtain greater privileges and move between systems.
Those techniques allowed the hackers to maintain access, steal credentials and impersonate legitimate users, according to Kaspersky. The attackers ultimately tried to compromise domain controllers, or servers that play a central role in managing access across an organization's network.
"To expand the geographic scope of its targets, NightEagle is updating its methods and adopting new techniques for persistence and lateral movement," Kaspersky researchers said.
Kaspersky did not identify the Russian companies that were targeted or disclose how many organizations were affected. The company also did not specify the likely motivation behind the attacks.
NightEagle first came to public attention in July 2025, when researchers at Chinese cybersecurity company QiAnXin described a hacking operation they tracked as APT-Q-95. The researchers said the group had been active since at least 2023 and had targeted organizations in China working in strategically sensitive industries, including defense, semiconductors, artificial intelligence and quantum technology.
QiAnXin characterized the activity as cyberespionage and said the hackers had targeted Microsoft Exchange servers using what researchers at the time believed could be a previously unknown vulnerability.
The researchers dubbed the group NightEagle because its operators typically carried out attacks during nighttime hours in China and frequently changed the infrastructure they used to conduct their operations.
Chinese cybersecurity researchers have previously associated the group with North America. Those claims have not been independently confirmed by other researchers, and the group's attribution remains uncertain.
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.



