Skip to main content
← Back to Demos
Malware intermediate · 15 min

Kaspersky: NightEagle's GhostContainer Backdoor Takes Over Microsoft Exchange Servers — Sandbox Detonates the Exchange Implant's Network Stage (2026-09-17 CISO Daily Digest)

The 2026-09-17 CISO Daily Digest covered Kaspersky GReAT's analysis of three threat clusters hitting Russian enterprises — NightEagle, Hacking Cat and Toy Ghouls — and the standout chain belongs to NightEagle (tracked as APT-Q-95, active since at least 2023): the attackers signed in to corporate VPNs with compromised valid credentials, with connections arriving from Russian-segment IP addresses linked to Cloudflare WARP tunnels and European virtual infrastructure providers, and then deployed GhostContainer, a modular backdoor that gives its operators complete access to the victim's Microsoft Exchange Server — running arbitrary code, performing file operations, loading additional modules and acting as a traffic redirection or tunnel — while masquerading as a common server component to blend in with regular operations. Kaspersky believes with a high degree of confidence that the backdoor was launched in memory: cryptographic keys used by Exchange were extracted from the ASP.NET configuration, the VIEWSTATE framework parameter was overwritten, and a payload was injected into it; the toolkit reuses components publicly available on GitHub, including the Neo-reGeorg tunnel, an exploit for CVE-2020-0688, and the GhostWebShell class from the ysoserial utility. Lateral movement added tunneling tools — Microsoft dev tunnels and rdp2tcp for RDP redirection — plus Active Directory abuse including CVE-2019-0708 (BlueKeep) and DCSync, with the end goal of breaking into domain controllers and the victim's entire Active Directory infrastructure; prior GhostContainer attacks targeted a government agency and a high-tech company in Asia, and Kaspersky detects the backdoor as Trojan.MSIL.GhostContainer.gen. This demo safely reproduces the post-compromise network stage of such a server-side intrusion: malicious-payload.sh performs a benign loopback-only beacon — three HTTP requests to http://127.0.0.1:9/beacon, a stand-in for the communication channel an attacker-held server-side implant relies on, with nothing ever leaving the machine — and opens the calculator as its only visible impact (no real malware, nothing destructive); malicious-win.cmd reproduces the same impact for Windows hosts, and clean-payload.sh is the control sample with the attack sequence removed. The defender takeaway matches the campaign: an in-memory backdoor assembled from open-source tools is invisible to file scanning, so MetaDefender Sandbox detonates the sample in an isolated environment and surfaces the implant's behavior — network activity, process chain and command flow — with no signature required (MITRE ATT&CK T1071.001 — Application Layer Protocol: Web Protocols).

Attack Technique

Server-side Exchange backdoor and tunneling (Kaspersky GReAT: GhostContainer deployed by NightEagle / APT-Q-95 — full Exchange control, arbitrary code, file operations, additional modules, traffic redirection; masquerading as a legitimate server component; believed in-memory launch via ASP.NET key extraction and VIEWSTATE overwrite) — sandbox detonation of an implant's network stage demonstrates call-home/beacon behavior surfaced without signatures (T1071.001 Application Layer Protocol: Web Protocols)

MITRE ATT&CK

T1071.001 ↗

Platforms

linux

File Types

.cmd.sh

MetaDefender Capabilities

MetaDefender Sandbox

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---