INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Targets Russian Enterprises with Backdoors and Ransomware
| 2026-09-16 15:27 HIGH HIGH RANSOMWARE & EXTORTION MALWARE & BOTNETS STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
The threat landscape is increasingly complex, with multiple groups targeting Russian enterprises using advanced tactics and techniques. The most recent incidents include the deployment of custom backdoors by Toy Ghouls (aka Bearlyfy, [IOC HIDDEN • LOGIN REQUIRED], and Feral Wolf), a ransomware strain dubbed Monkey that has been used in attacks since late summer 2025, and a new variant of the same malware known as ClearWater. These threats are linked to pro-Ukrainian hacktivist entities such as Hacking Cat and Cyber Anarchy Squad, which have been observed teaming up with each other to deliver ransomware strains like Monkey. The use of custom backdoors by Toy Ghouls has also raised concerns about the potential for full-fledged wiper malware to be deployed in future attacks.
Technical Mitigations AI-generated
* Implement a robust network segmentation strategy to isolate critical infrastructure and limit the spread of malware.
* Conduct regular vulnerability assessments and penetration testing on Microsoft Exchange servers to identify potential entry points for NightEagle attacks.
* Use secure authentication protocols, such as multi-factor authentication (MFA), to prevent attackers from gaining access to corporate VPNs or internal networks.
* Monitor network traffic patterns and log analysis can help detect suspicious activity that may indicate a NightEagle attack.
* Regularly update and patch operating systems, applications, and services to ensure they have the latest security patches and features.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
op•••••.evtx
ex•••••.tcp
ap•••••.ipify
tr•••••.gen
1c•••••.exe
1c•••••.exe
Ad•••••.exe
ad•••••.exe
10.0.•••.•••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Neo-reGeorgNeo-reGeorgBabukBabukWiperWiper
CVE-2020-0688CVE-2020-0688
CVE-2019-0708CVE-2019-0708
CVE-2026-42897CVE-2026-42897
CVE-2021-26855CVE-2021-26855
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
technologytechnology
governmentgovernment
Incident Timeline
February 2024
The threat actor deployed a wiper malware called Nemo Wiper, which overwrites files with random bytes and fills the remaining free disk space with files containing random alphanumeric names and the .lock extension.
Click on any entity below to view its context and source!
source_region
Russian Federation
The second group to single out Russian enterprises is Hacking Cat, a pro-Ukrainian hacktivist entity with a history of conducting website defacements and data breaches since February 2024.
organisation
the First Time
Rounding
Deploys Custom Backdoor for the First Time
Rounding off the list of groups targeting Russian organizations is Toy Ghouls (aka Bearlyfy, Laboo.boo, and Feral Wolf), which has moved from using leaked Babuk and LockBit ransomware builders to its own custom
GenieLocker
ransomware and now to a bespoke backdoor.
organisation
Bearlyfy
Deploys Custom Backdoor for the First Time
Rounding off the list of groups targeting Russian organizations is Toy Ghouls (aka Bearlyfy, Laboo.boo, and Feral Wolf), which has moved from using leaked Babuk and LockBit ransomware builders to its own custom
GenieLocker
ransomware and now to a bespoke backdoor.
organisation
Laboo.boo
Deploys Custom Backdoor for the First Time
Rounding off the list of groups targeting Russian organizations is Toy Ghouls (aka Bearlyfy, Laboo.boo, and Feral Wolf), which has moved from using leaked Babuk and LockBit ransomware builders to its own custom
GenieLocker
ransomware and now to a bespoke backdoor.
organisation
LockBit
Deploys Custom Backdoor for the First Time
Rounding off the list of groups targeting Russian organizations is Toy Ghouls (aka Bearlyfy, Laboo.boo, and Feral Wolf), which has moved from using leaked Babuk and LockBit ransomware builders to its own custom
GenieLocker
ransomware and now to a bespoke backdoor.
infrastructure
Windows
Also delivered by the threat actor are multiple variants of a ransomware family dubbed Monkey that are written in Rust, .NET, C++, and Golang to target Windows, Linux, and VMware ESXi systems.
It's equipped to escalate privileges and disable Windows recovery mechanisms, extract Microsoft Outlook credentials and send them to the C2 server, delete files with .bak, .backup, .bkf, .bck
The C++ variant offers similar functionality, but can establish persistence via a scheduled task or a
RunOnce
registry key, clear system logs, disable logging, wipe PowerShell Command History and Windows Command Prompt, bypass AMSI, turn off Event Tracing for Windows (ETW), configure Microsoft Defender exclusions for the encryptor, make Registry modifications to disable Task Manager and Windows Command Prompt, obtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, and recovery mechanisms, including the Volume Shadow Copy Service (VSS).
infrastructure
Linux
Also delivered by the threat actor are multiple variants of a ransomware family dubbed Monkey that are written in Rust, .NET, C++, and Golang to target Windows, Linux, and VMware ESXi systems.
The Golang variant, which is mainly used to target Linux and ESXi systems, establishes persistence via a crontab entry, disables SELinux and AppArmor, and attempts to delete volume shadow copies.
"This [Golang] version also includes functionality for removing shadow volume copies, which serves no purpose in Linux and ESXi environments – a fact that suggests the attackers were careless and likely used AI in developing the toolkit," Kaspersky theorized.
organisation
Golang
Also delivered by the threat actor are multiple variants of a ransomware family dubbed Monkey that are written in Rust, .NET, C++, and Golang to target Windows, Linux, and VMware ESXi systems.
organisation
VMware
Also delivered by the threat actor are multiple variants of a ransomware family dubbed Monkey that are written in Rust, .NET, C++, and Golang to target Windows, Linux, and VMware ESXi systems.
organisation
Microsoft Outlook
It's equipped to escalate privileges and disable Windows recovery mechanisms, extract Microsoft Outlook credentials and send them to the C2 server, delete files with .bak, .backup, .bkf, .bck
organisation
AMSI
The C++ variant offers similar functionality, but can establish persistence via a scheduled task or a
RunOnce
registry key, clear system logs, disable logging, wipe PowerShell Command History and Windows Command Prompt, bypass AMSI, turn off Event Tracing for Windows (ETW), configure Microsoft Defender exclusions for the encryptor, make Registry modifications to disable Task Manager and Windows Command Prompt, obtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, and recovery mechanisms, including the Volume Shadow Copy Service (VSS).
organisation
RunOnce
The C++ variant offers similar functionality, but can establish persistence via a scheduled task or a
RunOnce
registry key, clear system logs, disable logging, wipe PowerShell Command History and Windows Command Prompt, bypass AMSI, turn off Event Tracing for Windows (ETW), configure Microsoft Defender exclusions for the encryptor, make Registry modifications to disable Task Manager and Windows Command Prompt, obtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, and recovery mechanisms, including the Volume Shadow Copy Service (VSS).
organisation
Event Tracing for
The C++ variant offers similar functionality, but can establish persistence via a scheduled task or a
RunOnce
registry key, clear system logs, disable logging, wipe PowerShell Command History and Windows Command Prompt, bypass AMSI, turn off Event Tracing for Windows (ETW), configure Microsoft Defender exclusions for the encryptor, make Registry modifications to disable Task Manager and Windows Command Prompt, obtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, and recovery mechanisms, including the Volume Shadow Copy Service (VSS).
organisation
ETW
The C++ variant offers similar functionality, but can establish persistence via a scheduled task or a
RunOnce
registry key, clear system logs, disable logging, wipe PowerShell Command History and Windows Command Prompt, bypass AMSI, turn off Event Tracing for Windows (ETW), configure Microsoft Defender exclusions for the encryptor, make Registry modifications to disable Task Manager and Windows Command Prompt, obtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, and recovery mechanisms, including the Volume Shadow Copy Service (VSS).
organisation
Task
The C++ variant offers similar functionality, but can establish persistence via a scheduled task or a
RunOnce
registry key, clear system logs, disable logging, wipe PowerShell Command History and Windows Command Prompt, bypass AMSI, turn off Event Tracing for Windows (ETW), configure Microsoft Defender exclusions for the encryptor, make Registry modifications to disable Task Manager and Windows Command Prompt, obtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, and recovery mechanisms, including the Volume Shadow Copy Service (VSS).
organisation
Windows Command Prompt
The C++ variant offers similar functionality, but can establish persistence via a scheduled task or a
RunOnce
registry key, clear system logs, disable logging, wipe PowerShell Command History and Windows Command Prompt, bypass AMSI, turn off Event Tracing for Windows (ETW), configure Microsoft Defender exclusions for the encryptor, make Registry modifications to disable Task Manager and Windows Command Prompt, obtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, and recovery mechanisms, including the Volume Shadow Copy Service (VSS).
organisation
TCP
Once launched, the malware establishes a connection with a remote server, registers the victim, and awaits further instructions that allow it to run arbitrary commands, enumerate processes, gather system information, upload/download files, and open or close a TCP tunnel.
organisation
Hacking Cat
Hacking Cat has also been observed teaming up with the
Cyber Anarchy Squad
, another pro-Ukraine hacktivist group, to deliver a different ransomware strain known as ClearWater by means of a batch script.
organisation
ClearWater
Hacking Cat has also been observed teaming up with the
Cyber Anarchy Squad
, another pro-Ukraine hacktivist group, to deliver a different ransomware strain known as ClearWater by means of a batch script.
organisation
ChaCha20-Poly1305
"A Rust-based variant of Monkey Ransomware generates a 32-byte key and encrypts the victim's files using ChaCha20-Poly1305," Kaspersky said.
data_breach
32 byte
"A Rust-based variant of Monkey Ransomware generates a 32-byte key and encrypts the victim's files using ChaCha20-Poly1305," Kaspersky said.
"
Some of the notable features spread across the other three variants are listed below -
The .NET variant generates a 32-byte key, sends it to the command-and-control (C2) server, and encrypts victim files using AES-256-CBC.
organisation
SELinux
The Golang variant, which is mainly used to target Linux and ESXi systems, establishes persistence via a crontab entry, disables SELinux and AppArmor, and attempts to delete volume shadow copies.
organisation
AppArmor
The Golang variant, which is mainly used to target Linux and ESXi systems, establishes persistence via a crontab entry, disables SELinux and AppArmor, and attempts to delete volume shadow copies.
organisation
AES-256-CBC
"
Some of the notable features spread across the other three variants are listed below -
The .NET variant generates a 32-byte key, sends it to the command-and-control (C2) server, and encrypts victim files using AES-256-CBC.
organisation
the Ukrainian
In another collaborative operation with the Ukrainian Cyber Alliance, the threat actor is said to have deployed a wiper malware called Nemo Wiper that overwrites files with random bytes and fills the remaining free disk space with files containing random alphanumeric names and the .lock extension.
organisation
Exchange
Attacks mounted by the group have weaponized vulnerabilities in Exchange servers (e.g.,
CVE-2021-26855
and
CVE-2026-42897
) to deliver a Go-based remote access trojan dubbed Gorilla RAT, which can tunnel traffic to allow the operator to access the victim's internal network.
organisation
Cyber Anarchy Squad
"Hacking Cat actively collaborates with other hacktivists such as Cyber Anarchy Squad and the Ukrainian Cyber Alliance, which can complicate the attribution of tools to specific attackers," Kaspersky
said
.
organisation
Cyber Alliance
"Hacking Cat actively collaborates with other hacktivists such as Cyber Anarchy Squad and the Ukrainian Cyber Alliance, which can complicate the attribution of tools to specific attackers," Kaspersky
said
.
organisation
Toy Ghouls
"
Toy Ghouls
July 2025
Threat actors used Microsoft dev tunnels and rdp2tcp to deliver GhostContainer, a known modular backdoor, to target victim's Microsoft Exchange servers.
Click on any entity below to view its context and source!
organisation
Microsoft Exchange
"
The attacks, as highlighted in July 2025, involve the deployment of
GhostContainer
, a known modular backdoor that grants the operators complete access to a victim's Microsoft Exchange Server, as well as run arbitrary code, perform file operations, and load additional modules.
tactic
T1584.004 - Server
"
The attacks, as highlighted in July 2025, involve the deployment of
GhostContainer
, a known modular backdoor that grants the operators complete access to a victim's Microsoft Exchange Server, as well as run arbitrary code, perform file operations, and load additional modules.
organisation
ASP.NET
"
The exact method used by the attackers to deliver GhostContainer to Microsoft Exchange servers is unknown, although it's believed to have involved the extraction of cryptographic keys used by the server from the ASP.NET configuration, followed by overwriting the VIEWSTATE framework parameter, and injecting a payload into it, causing the backdoor to be launched in memory.
organisation
GhostContainer
"
The exact method used by the attackers to deliver GhostContainer to Microsoft Exchange servers is unknown, although it's believed to have involved the extraction of cryptographic keys used by the server from the ASP.NET configuration, followed by overwriting the VIEWSTATE framework parameter, and injecting a payload into it, causing the backdoor to be launched in memory.
organisation
VIEWSTATE
"
The exact method used by the attackers to deliver GhostContainer to Microsoft Exchange servers is unknown, although it's believed to have involved the extraction of cryptographic keys used by the server from the ASP.NET configuration, followed by overwriting the VIEWSTATE framework parameter, and injecting a payload into it, causing the backdoor to be launched in memory.
organisation
Active Directory
The end goal is to establish persistence in the victim infrastructure, get password hashes for domain accounts, use long-lived Kerberos tickets to gain legitimate access to target resources, and ultimately break into domain controllers and the victim's entire Active Directory infrastructure.
organisation
the Administrators and Remote Desktop Users
"
This includes the exploitation of
CVE-2019-0708
(aka
BlueKeep
) to create a local account on the system and add it to the Administrators and Remote Desktop Users groups.
organisation
Microsoft
To move laterally within the internal network, NightEagle has been observed downloading tunneling tools to redirect network traffic via RDP using
Microsoft dev tunnels
and an open-source program called
rdp2tcp
.
organisation
Pro-Ukrainian Hacking Cat Deploys Gorilla
Pro-Ukrainian Hacking Cat Deploys Gorilla RAT and Monkey Ransomware
late summer 2025
Threat actors used ransomware to target Russian enterprises with backdoors and wipers.
Click on any entity below to view its context and source!
tactic
Ransomware
The earliest Monkey ransomware artifact dates back to late summer 2025.
July 2026
Threat actors used Windows Remote Management to deliver the Bird Agent backdoor and its configuration files to compromised systems.
Click on any entity below to view its context and source!
infrastructure
Windows
The backdoor, first detected in July 2026, appears in two variants -
mqtt-bird-agent 0.1.0, which uses HiveMQ MQTT broker for C2
matrix-bird-agent 0.1.0, which uses Element, a Matrix-based end-to-end encrypted messenger app, for C2
"In this campaign, the attackers use Windows Remote Management (WinRM) to deliver the backdoors and their configuration files to compromised systems," Kaspersky
said
.
"
The Bird Agent backdoor can run within an interactive command-line session, as well as set up persistence as a Windows service.
The malware then proceeds to read the file and partially encrypts it with a key derived from the victim machine's MachineGuid value stored in the Windows Registry so that the configuration is bound to that specific system.
The Element variant of Bird Agent is functionally similar to its HiveMQ counterpart, the main difference being that the received commands are executed through the Windows command-line interface (CLI) and send the command output back to the C2 server.
organisation
0.1.0
The backdoor, first detected in July 2026, appears in two variants -
mqtt-bird-agent 0.1.0, which uses HiveMQ MQTT broker for C2
matrix-bird-agent 0.1.0, which uses Element, a Matrix-based end-to-end encrypted messenger app, for C2
"In this campaign, the attackers use Windows Remote Management (WinRM) to deliver the backdoors and their configuration files to compromised systems," Kaspersky
said
.
tactic
T1021.006 - Windows Remote Management
The backdoor, first detected in July 2026, appears in two variants -
mqtt-bird-agent 0.1.0, which uses HiveMQ MQTT broker for C2
matrix-bird-agent 0.1.0, which uses Element, a Matrix-based end-to-end encrypted messenger app, for C2
"In this campaign, the attackers use Windows Remote Management (WinRM) to deliver the backdoors and their configuration files to compromised systems," Kaspersky
said
.
organisation
Bird
"
The Bird Agent backdoor can run within an interactive command-line session, as well as set up persistence as a Windows service.
organisation
the Windows Registry
The malware then proceeds to read the file and partially encrypts it with a key derived from the victim machine's MachineGuid value stored in the Windows Registry so that the configuration is bound to that specific system.
organisation
CLI
The Element variant of Bird Agent is functionally similar to its HiveMQ counterpart, the main difference being that the received commands are executed through the Windows command-line interface (CLI) and send the command output back to the C2 server.
organisation
HiveMQ
Once the connection is established, the backdoor proceeds to send system information and issues HTTP GET requests to the HiveMQ broker to fetch commands from the C2 server, execute them via PowerShell in hidden mode (-NonInteractive -NoProfile -Command), and transmit the results back to the server.
2026/09/16
Threat actors used compromised valid credentials to gain access to corporate VPNs.
2026/09/16
NightEagle exploited CVE-2019-0708 (BlueKeep) vulnerabilities in Microsoft RDP implementations to gain access and create backdoors on targeted Russian enterprises.
Click on any entity below to view its context and source!
organisation
NightEagle
NightEagle targets Russian companies.
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as
NightEagle
,
Hacking Cat
, and
Toy Ghouls
, according to multiple reports from Kaspersky.
organisation
Ransomware
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers.
organisation
Wipers
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers.
organisation
Kaspersky
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as
NightEagle
,
Hacking Cat
, and
Toy Ghouls
, according to multiple reports from Kaspersky.
Kaspersky products detect the GhostContainer backdoor as Trojan.MSIL.GhostContainer.gen.
organisation
IP
VPN connections originated from IP addresses in the Russian segment linked to Cloudflare WARP tunnels, as well as from IP addresses associated with European virtual infrastructure providers.
"VPN connections originated from IP addresses in the Russian segment linked to Cloudflare WARP tunnels, as well as from IP addresses associated with European virtual infrastructure providers.
organisation
Cloudflare
VPN connections originated from IP addresses in the Russian segment linked to Cloudflare WARP tunnels, as well as from IP addresses associated with European virtual infrastructure providers.
"VPN connections originated from IP addresses in the Russian segment linked to Cloudflare WARP tunnels, as well as from IP addresses associated with European virtual infrastructure providers.
organisation
ASP.NET
We believe with a high degree of confidence that they applied a
technique already familiar to us
: extracting the cryptographic keys used by Microsoft Exchange from the ASP.NET configuration, overwriting the
VIEWSTATE
framework parameter, and injecting a payload into it, which then launched the GhostContainer backdoor in memory.
organisation
GhostContainer
We believe with a high degree of confidence that they applied a
technique already familiar to us
: extracting the cryptographic keys used by Microsoft Exchange from the ASP.NET configuration, overwriting the
VIEWSTATE
framework parameter, and injecting a payload into it, which then launched the GhostContainer backdoor in memory.
organisation
Kaspersky Threat Analysis
Traffic
GhostContainer samples identified by the Similarity technology from Kaspersky Threat Analysis
Traffic redirection
Once the attackers gain sufficient privileges during an attack, they leverage RDP to move laterally within the internal network segment.
infrastructure
Windows
These tasks enabled network port forwarding through standard Windows functionality:
netsh
interface
portproxy
add
v4tov4
listenport
=
443
connectaddress
=
10.0.12.101
connectport
=
445
Lateral movement
To obtain elevated privileges and move laterally through the network, NightEagle exploited various vulnerabilities in Active Directory.
The backdoor is a .NET assembly containing three classes that implement its core functionality:
Stub
: processes C2 commands delivered to the infected system through the
x-owa-urlpostdata
headers and evades detection by the Antimalware Scan Interface (AMSI) and Windows Event Log mechanisms by overwriting addresses in
amsi.dll
and
ntdll.dll
.
App_Web_843e75cf5b63
: accepts the
fakePath
and
fakePageName
parameters and creates virtual paths that redirect requests to the
App_Web_8c9b251fb5b3
class.
When virtual channels are opened and closed, corresponding events with IDs 132 (channel opened) and 148 (channel closed) are logged in the
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational.evtx
Windows log.
These events contain the names of the channels (such as XPSRD, cliprdr, Microsoft::Windows::RDS::DisplayControl, and others) used by the RemoteFX module, which extends the capabilities of the RDP protocol.
organisation
Active Directory
These tasks enabled network port forwarding through standard Windows functionality:
netsh
interface
portproxy
add
v4tov4
listenport
=
443
connectaddress
=
10.0.12.101
connectport
=
445
Lateral movement
To obtain elevated privileges and move laterally through the network, NightEagle exploited various vulnerabilities in Active Directory.
organisation
APT
The cybersecurity vendor said it has
identified attacks
mounted by
NightEagle
(aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
This toolkit also includes the analytical solution
Kaspersky Threat Attribution Engine
(KTAE), which helps SOC analysts and incident responders determine which APT groups malware can be attributed to.
organisation
the Antimalware Scan Interface
The backdoor is a .NET assembly containing three classes that implement its core functionality:
Stub
: processes C2 commands delivered to the infected system through the
x-owa-urlpostdata
headers and evades detection by the Antimalware Scan Interface (AMSI) and Windows Event Log mechanisms by overwriting addresses in
amsi.dll
and
ntdll.dll
.
App_Web_843e75cf5b63
: accepts the
fakePath
and
fakePageName
parameters and creates virtual paths that redirect requests to the
App_Web_8c9b251fb5b3
class.
organisation
AMSI
The backdoor is a .NET assembly containing three classes that implement its core functionality:
Stub
: processes C2 commands delivered to the infected system through the
x-owa-urlpostdata
headers and evades detection by the Antimalware Scan Interface (AMSI) and Windows Event Log mechanisms by overwriting addresses in
amsi.dll
and
ntdll.dll
.
App_Web_843e75cf5b63
: accepts the
fakePath
and
fakePageName
parameters and creates virtual paths that redirect requests to the
App_Web_8c9b251fb5b3
class.
organisation
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
When virtual channels are opened and closed, corresponding events with IDs 132 (channel opened) and 148 (channel closed) are logged in the
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational.evtx
Windows log.
organisation
XPSRD
These events contain the names of the channels (such as XPSRD, cliprdr, Microsoft::Windows::RDS::DisplayControl, and others) used by the RemoteFX module, which extends the capabilities of the RDP protocol.
organisation
RDP
These events contain the names of the channels (such as XPSRD, cliprdr, Microsoft::Windows::RDS::DisplayControl, and others) used by the RemoteFX module, which extends the capabilities of the RDP protocol.
organisation
Domain-Password
Contents of a system memory dump showing artifacts of the CVE-2019-0708 exploit
The attackers also requested Kerberos tickets with a non-standard combination of flags (
Forwardable
,
Proxiable
,
Renewable
) and attempted to replicate the
Domain-Password
object from the Active Directory database to impersonate the domain controller (a technique known as DCSync) after obtaining an account with sufficient privileges.
organisation
the Active Directory
Contents of a system memory dump showing artifacts of the CVE-2019-0708 exploit
The attackers also requested Kerberos tickets with a non-standard combination of flags (
Forwardable
,
Proxiable
,
Renewable
) and attempted to replicate the
Domain-Password
object from the Active Directory database to impersonate the domain controller (a technique known as DCSync) after obtaining an account with sufficient privileges.
organisation
Kaspersky Research Sandbox
Execution graph of adobe_32.exe in Kaspersky Research Sandbox
rdp2tcp
This is a
publicly available tool
for tunneling TCP traffic over an established RDP connection.
organisation
TCP
Execution graph of adobe_32.exe in Kaspersky Research Sandbox
rdp2tcp
This is a
publicly available tool
for tunneling TCP traffic over an established RDP connection.
organisation
Microsoft
Microsoft dev tunnels
This is a
legitimate Microsoft mechanism
that allows local web services to be published for internet access on
*.*.devtunnels.ms
domains.
organisation
Global Emergency Response Team
Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95).
organisation
GERT
Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95).
organisation
APT-Q-95
Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95).
organisation
GhostContainer on Microsoft Exchange
GhostContainer on Microsoft Exchange
Both during the initial access stage and as the attack progressed, the attackers deployed the
GhostContainer backdoor
on Microsoft Exchange servers.
organisation
Microsoft Exchange
GhostContainer on Microsoft Exchange
Both during the initial access stage and as the attack progressed, the attackers deployed the
GhostContainer backdoor
on Microsoft Exchange servers.
organisation
Trojan.MSIL.GhostContainer.gen
Kaspersky products detect the GhostContainer backdoor as Trojan.MSIL.GhostContainer.gen.
organisation
GitHub
The attackers used GitHub repositories to host their archived tools.
organisation
the Administrators and Remote Desktop Users
They used the vulnerable mechanism to create a local account on the system and add it to the Administrators and Remote Desktop Users groups.
organisation
Kaspersky Threat Analysis
We showed examples above of how
Kaspersky Threat Analysis
detects samples of the GhostContainer backdoor and the tunneling utility.
organisation
Kaspersky Threat Attribution Engine
This toolkit also includes the analytical solution
Kaspersky Threat Attribution Engine
(KTAE), which helps SOC analysts and incident responders determine which APT groups malware can be attributed to.
organisation
KTAE
This toolkit also includes the analytical solution
Kaspersky Threat Attribution Engine
(KTAE), which helps SOC analysts and incident responders determine which APT groups malware can be attributed to.
organisation
KTAE
However
Backdoor analysis with KTAE
However, detection scenarios for this kind of attacks are not limited to file analysis.
organisation
Kaspersky Endpoint Detection and
Deploying a backdoor on a target host produces numerous characteristic artifacts, which allow
Kaspersky Endpoint Detection and Response Expert
to alert users to anomalies in the infrastructure in a timely manner.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
These tasks enabled network port forwarding through standard Windows functionality:
netsh
interface
portproxy
add
v4tov4
listenport
=
443
connectaddress
=
10.0.12.101
connectport
=
445
Lateral movement
To obtain elevated privileges and move laterally through the network, NightEagle exploited various vulnerabilities in Active Directory.
The backdoor is a .NET assembly containing three classes that implement its core functionality:
Stub
: processes C2 commands delivered to the infected system through the
x-owa-urlpostdata
headers and evades detection by the Antimalware Scan Interface (AMSI) and Windows Event Log mechanisms by overwriting addresses in
amsi.dll
and
ntdll.dll
.
App_Web_843e75cf5b63
: accepts the
fakePath
and
fakePageName
parameters and creates virtual paths that redirect requests to the
App_Web_8c9b251fb5b3
class.
When virtual channels are opened and closed, corresponding events with IDs 132 (channel opened) and 148 (channel closed) are logged in the
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational.evtx
Windows log.
These events contain the names of the channels (such as XPSRD, cliprdr, Microsoft::Windows::RDS::DisplayControl, and others) used by the RemoteFX module, which extends the capabilities of the RDP protocol.
Also delivered by the threat actor are multiple variants of a ransomware family dubbed Monkey that are written in Rust, .NET, C++, and Golang to target Windows, Linux, and VMware ESXi systems.
It's equipped to escalate privileges and disable Windows recovery mechanisms, extract Microsoft Outlook credentials and send them to the C2 server, delete files with .bak, .backup, .bkf, .bck
The C++ variant offers similar functionality, but can establish persistence via a scheduled task or a
RunOnce
registry key, clear system logs, disable logging, wipe PowerShell Command History and Windows Command Prompt, bypass AMSI, turn off Event Tracing for Windows (ETW), configure Microsoft Defender exclusions for the encryptor, make Registry modifications to disable Task Manager and Windows Command Prompt, obtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, and recovery mechanisms, including the Volume Shadow Copy Service (VSS).
The backdoor, first detected in July 2026, appears in two variants -
mqtt-bird-agent 0.1.0, which uses HiveMQ MQTT broker for C2
matrix-bird-agent 0.1.0, which uses Element, a Matrix-based end-to-end encrypted messenger app, for C2
"In this campaign, the attackers use Windows Remote Management (WinRM) to deliver the backdoors and their configuration files to compromised systems," Kaspersky
said
.
"
The Bird Agent backdoor can run within an interactive command-line session, as well as set up persistence as a Windows service.
The malware then proceeds to read the file and partially encrypts it with a key derived from the victim machine's MachineGuid value stored in the Windows Registry so that the configuration is bound to that specific system.
The Element variant of Bird Agent is functionally similar to its HiveMQ counterpart, the main difference being that the received commands are executed through the Windows command-line interface (CLI) and send the command output back to the C2 server.
Metrics
infrastructure
Linux
Affected Product
Also delivered by the threat actor are multiple variants of a ransomware family dubbed Monkey that are written in Rust, .NET, C++, and Golang to target Windows, Linux, and VMware ESXi systems.
The Golang variant, which is mainly used to target Linux and ESXi systems, establishes persistence via a crontab entry, disables SELinux and AppArmor, and attempts to delete volume shadow copies.
"This [Golang] version also includes functionality for removing shadow volume copies, which serves no purpose in Linux and ESXi environments – a fact that suggests the attackers were careless and likely used AI in developing the toolkit," Kaspersky theorized.
Metrics
data_breach
32
Byte
"A Rust-based variant of Monkey Ransomware generates a 32-byte key and encrypts the victim's files using ChaCha20-Poly1305," Kaspersky said.
"
Some of the notable features spread across the other three variants are listed below -
The .NET variant generates a 32-byte key, sends it to the command-and-control (C2) server, and encrypts victim files using AES-256-CBC.
Intelligence Sources
Kaspersky
2026-09-16
NightEagle targets Russian companies
Kaspersky
The Hacker News
2026-09-16
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-17T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
64x
organisation
Identified Entity
NightEagle
entity
8x
timeline
Temporal Reference
10.0.12.101
date
4x
tactic
Cyber Operation Type
Lateral Movement
tactic
4x
vulnerability
Exploited CVE
CVE-2019-0708
cve
4x
tactic
MITRE ATT&CK Technique
T1003.006 - DCSync
technique
3x
malware
Malware Payload
Neo-reGeorg
tool
2x
target region
Target Country
Russian Federation
country
2x
source region
Origin Country
Russian Federation
country
2x
industry
Targeted Sector
Technology
sector
2x
infrastructure
Affected Product
Windows
software
Contextual Telemetry
Context Block
7 METRICS
general metric
Connectaddress
443
connectaddress
general metric
Lateral Movement
445
lateral movement
general metric
Ids
132
ids
general metric
Channel Closed
148
channel closed
general metric
Known Rdp Implementation Vulnerability
708
known rdp implementation vulnerability
general metric
Port
3,389
port
data breach
Byte
32
byte
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.