<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftexchange_server2013cumulative_update_23/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 13:12:31 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftexchange_server2013cumulative_update_23/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>NightEagle APT Targets Russian Organizations with GhostContainer Backdoor</title><link>https://feed.craftedsignal.io/briefs/2026-09-nighteagle-attacks/</link><pubDate>Wed, 16 Sep 2026 13:12:31 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-nighteagle-attacks/</guid><description>The NightEagle APT group is actively targeting organizations by exploiting compromised VPN credentials, deploying the memory-resident GhostContainer backdoor on Exchange servers, and utilizing legitimate tunneling tools for lateral movement.</description><content:encoded><![CDATA[<p>The NightEagle APT group (also known as APT-Q-95) has expanded its targeting to include organizations in Russia. Active since 2023, the group employs a sophisticated multi-stage approach, initiating access via compromised VPN credentials. A primary focus of their campaign is the deployment of the GhostContainer backdoor on Microsoft Exchange servers. This backdoor is highly evasive, functioning in-memory by patching amsi.dll and ntdll.dll to circumvent security monitoring. The attackers utilize custom C2 communication headers and frequently abuse legitimate utilities, such as Microsoft Dev Tunnels, to facilitate RDP-based lateral movement. Tools are sourced from GitHub repositories disguised to mimic legitimate software, while the payload delivery often involves sophisticated manipulation of ASP.NET VIEWSTATE parameters. The group’s reliance on dual-use infrastructure and legitimate tunneling services poses significant challenges for traditional perimeter-based defenses.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial access is gained by using compromised valid credentials to authenticate against corporate VPN services.</li>
<li>Attackers extract cryptographic keys from the ASP.NET configuration on Microsoft Exchange servers.</li>
<li>The VIEWSTATE framework parameter is overwritten to inject a payload, facilitating the in-memory execution of the GhostContainer backdoor.</li>
<li>The backdoor establishes persistence in-memory and patches amsi.dll and ntdll.dll to bypass AMSI and Windows Event Log monitoring.</li>
<li>Command-and-control communication is established by parsing specific headers (x-owa-urlpostdata) on the infected Exchange host.</li>
<li>Attackers download malicious toolsets from GitHub repositories, disguised as legitimate software archives (e.g., Adobe or 1C broker software).</li>
<li>Microsoft Dev Tunnels are configured on the compromised system to expose RDP (port 3389) to the internet.</li>
<li>Attackers perform lateral movement throughout the internal network using the established RDP tunnel.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The campaign results in persistent unauthorized access to internal network segments and sensitive Microsoft Exchange environments. By gaining RDP-level access to internal workstations and servers, NightEagle can facilitate data exfiltration, credential harvesting, and long-term surveillance within targeted Russian businesses.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of abnormal RDP tunneling and suspicious memory-injected payloads on Exchange infrastructure.</p>
<ul>
<li>Patch CVE-2020-0688 on all Microsoft Exchange servers immediately.</li>
<li>Hunt for the execution of unauthorized binaries masquerading as legitimate software (e.g., AdobeSync.exe, 1cbroker.exe) originating from unauthorized paths.</li>
<li>Monitor for the creation of Microsoft Dev Tunnels sessions, specifically connections to *.devtunnels.ms.</li>
<li>Restrict and audit the use of VPN credentials, implementing phishing-resistant MFA for all remote access.</li>
<li>Baseline and monitor ASP.NET configuration changes on web servers to detect potential tampering with VIEWSTATE parameters.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>nighteagle</category><category>apt</category><category>exchange</category><category>backdoor</category><category>tunnel</category></item></channel></rss>