NightEagle targets Russian companies
Executive Summary
Kaspersky GERT experts uncovered a new NightEagle APT campaign targeting Russian companies. The operation uses the GhostContainer backdoor and tools hosted on GitHub, while exploiting Active Directory and RDP vulnerabilities to gain persistence and lateral movement.
Intelligence Metadata - Source Publisher: Securelist - Published Date: 2026-09-16T10:00:11+00:00 - Category: campaigns
Original Description: Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.
"A life spent making mistakes is not only more honourable but more useful than a life spent in doing nothing."
— Bernard Shaw
Source: Securelist