Tag
high
threat
NightEagle APT Targets Russian Organizations with GhostContainer Backdoor
3 TTPs 1 CVEThe NightEagle APT group is actively targeting organizations by exploiting compromised VPN credentials, deploying the memory-resident GhostContainer backdoor on Exchange servers, and utilizing legitimate tunneling tools for lateral movement.
Exchange Server
NightEagle
apt
exchange
backdoor
tunnel
3t
1c
high
advisory
Potential Abuse of Cloudflare Tunnels via Cloudflared
2 rules 2 TTPsAttackers are increasingly abusing Cloudflare tunnels, created via the cloudflared client, for establishing stealthy command and control channels and evading network defenses by proxying traffic through Cloudflare's infrastructure.
Cloudflared +3
cloudflare
reverse-proxy
tunnel
command-and-control
2r
2t