{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftexchange_server2019cumulative_update_4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["NightEagle"],"_cs_cpes":["cpe:2.3:a:microsoft:exchange_server:*:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:exchange_server:2010:sp3_rollup_30:*:*:*:*:*:*","cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*","cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:*","cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:*","cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:*","cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2020-0688"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Exchange Server"],"_cs_severities":["high"],"_cs_tags":["nighteagle","apt","exchange","backdoor","tunnel"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eThe NightEagle APT group (also known as APT-Q-95) has expanded its targeting to include organizations in Russia. Active since 2023, the group employs a sophisticated multi-stage approach, initiating access via compromised VPN credentials. A primary focus of their campaign is the deployment of the GhostContainer backdoor on Microsoft Exchange servers. This backdoor is highly evasive, functioning in-memory by patching amsi.dll and ntdll.dll to circumvent security monitoring. The attackers utilize custom C2 communication headers and frequently abuse legitimate utilities, such as Microsoft Dev Tunnels, to facilitate RDP-based lateral movement. Tools are sourced from GitHub repositories disguised to mimic legitimate software, while the payload delivery often involves sophisticated manipulation of ASP.NET VIEWSTATE parameters. The group’s reliance on dual-use infrastructure and legitimate tunneling services poses significant challenges for traditional perimeter-based defenses.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is gained by using compromised valid credentials to authenticate against corporate VPN services.\u003c/li\u003e\n\u003cli\u003eAttackers extract cryptographic keys from the ASP.NET configuration on Microsoft Exchange servers.\u003c/li\u003e\n\u003cli\u003eThe VIEWSTATE framework parameter is overwritten to inject a payload, facilitating the in-memory execution of the GhostContainer backdoor.\u003c/li\u003e\n\u003cli\u003eThe backdoor establishes persistence in-memory and patches amsi.dll and ntdll.dll to bypass AMSI and Windows Event Log monitoring.\u003c/li\u003e\n\u003cli\u003eCommand-and-control communication is established by parsing specific headers (x-owa-urlpostdata) on the infected Exchange host.\u003c/li\u003e\n\u003cli\u003eAttackers download malicious toolsets from GitHub repositories, disguised as legitimate software archives (e.g., Adobe or 1C broker software).\u003c/li\u003e\n\u003cli\u003eMicrosoft Dev Tunnels are configured on the compromised system to expose RDP (port 3389) to the internet.\u003c/li\u003e\n\u003cli\u003eAttackers perform lateral movement throughout the internal network using the established RDP tunnel.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign results in persistent unauthorized access to internal network segments and sensitive Microsoft Exchange environments. By gaining RDP-level access to internal workstations and servers, NightEagle can facilitate data exfiltration, credential harvesting, and long-term surveillance within targeted Russian businesses.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of abnormal RDP tunneling and suspicious memory-injected payloads on Exchange infrastructure.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2020-0688 on all Microsoft Exchange servers immediately.\u003c/li\u003e\n\u003cli\u003eHunt for the execution of unauthorized binaries masquerading as legitimate software (e.g., AdobeSync.exe, 1cbroker.exe) originating from unauthorized paths.\u003c/li\u003e\n\u003cli\u003eMonitor for the creation of Microsoft Dev Tunnels sessions, specifically connections to *.devtunnels.ms.\u003c/li\u003e\n\u003cli\u003eRestrict and audit the use of VPN credentials, implementing phishing-resistant MFA for all remote access.\u003c/li\u003e\n\u003cli\u003eBaseline and monitor ASP.NET configuration changes on web servers to detect potential tampering with VIEWSTATE parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T13:12:31Z","date_published":"2026-09-16T13:12:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nighteagle-attacks/","summary":"The NightEagle APT group is actively targeting organizations by exploiting compromised VPN credentials, deploying the memory-resident GhostContainer backdoor on Exchange servers, and utilizing legitimate tunneling tools for lateral movement.","title":"NightEagle APT Targets Russian Organizations with GhostContainer Backdoor","url":"https://feed.craftedsignal.io/briefs/2026-09-nighteagle-attacks/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}