NightEagle targets Russian companies
Kaspersky GERT experts have identified a new campaign by the APT group NightEagle that exploits vulnerabilities and tools on GitHub.

Experts from Kaspersky's GERT team have discovered a new attack campaign conducted by the APT group NightEagle. This malicious operation specifically targets Russian companies.
During the investigations, specialists detected the use of the GhostContainer backdoor and various tools hosted on the GitHub platform. Furthermore, the group is actively exploiting certain vulnerabilities present in Active Directory and RDP to carry out its activities.
