NightEagle targets Russian companies


Over the past year, Kaspersky Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia. Kaspersky researchers have now identified attacks by the group targeting businesses in Russia. This post examines both known and new tools NightEagle used in its latest campaign.

In most incidents, the attackers used compromised valid credentials to gain access to corporate VPNs. VPN connections originated from IP addresses in the Russian segment linked to Cloudflare WARP tunnels, as well as from IP addresses associated with European virtual infrastructure providers.

Read more… 
Source:  Kaspersky


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Atomic macOS (AMOS) Stealer Activity

    September 16, 2026

    This article reviews an Atomic macOS (AMOS) stealer malware infection generated in a lab environment. While several sources have published articles analyzing AMOS stealer, the associated indicators constantly change. This article presents a snapshot of indicators seen in early August 2026 and is designed to help readers better understand AMOS stealer. AMOS stealer is an information ...

  • NightEagle targets Russian companies

    September 16, 2026

    Over the past year, Kaspersky Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia. Kaspersky researchers have now identified attacks by the group targeting businesses in Russia. This post examines both known and new ...

  • Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database

    September 16, 2026

    The ShinyHunters hacking group has published hundreds of thousands of files from a Florida state database of vehicles and driver information. The hackers said they published the stolen data on its leak site “because the victim did not pay a ransom or cooperate and comply” with the hackers’ demands. The hackers said they breached the database, ...

  • Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products

    September 15, 2026

    Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino’s history. While this CVE count is hardly notable compared to some vendors – hello, Microsoft’s record-breaking 974 bugs disclosed earlier this month – it does set a company record for ...

  • Iranian Cyber Targeting of Dissidents, Activists and Journalists

    September 15, 2026

    CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025. CHOSEN BRICK enables Iranian state cyber actors to collect information on a target’s contacts, emails and social media messages, which could enable tracking of their movements. Iran almost ...

  • ClickFix attacks are tricking Mac and Windows users into hacking themselves

    September 14, 2026

    If you clicked on an HBO Max ad on Reddit over the past week, you might want to check your computer for malware. These so-called “ClickFix” attacks have quickly become one of the rising cybersecurity threats of 2026, and they’re getting both sneakier and compromising people’s devices with greater frequency. Until recently, ClickFix attacks were a ...