NightEagle targets Russian companies


Over the past year, Kaspersky Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia. Kaspersky researchers have now identified attacks by the group targeting businesses in Russia. This post examines both known and new tools NightEagle used in its latest campaign.

In most incidents, the attackers used compromised valid credentials to gain access to corporate VPNs. VPN connections originated from IP addresses in the Russian segment linked to Cloudflare WARP tunnels, as well as from IP addresses associated with European virtual infrastructure providers.

Read more… 
Source:  Kaspersky


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction

    August 14, 2026

    Microsoft has recently fixed a vulnerability that allowed threat actors to bypass advanced security measures, disable antivirus software, and expose the target device to full system takeover. All of this, it seems, could have been possible with a very simple script, and a single click from the victim’s side. Luckily, the vulnerability was discovered by white hat hackers, ...

  • APT group HoneyMyte upgrades CoolClient

    August 14, 2026

    CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It supports such capabilities as keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions. Since its first public disclosure by Sophos in 2022 and subsequent ...

  • New Android malware lets criminals use your bank card in real time

    August 13, 2026

    Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it “WindRelay.” NFC (Near Field Communication) is wireless technology that allows devices such as smartphones, payment cards, and payment terminals to communicate when they’re very close together. So, ...

  • Armored Likho expands its cyber-espionage toolkit

    August 13, 2026

    In May 2026, Kaspersky researches discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, ...

  • Uber Freight reportedly investigating after hacking group claims data breach

    August 12, 2026

    A hacking and extortion gang has taken credit for a cyberattack and data breach at Uber Freight, the ridesharing giant’s logistics subsidiary. A spokesperson for Uber Freight told Reuters, which first reported the incident, that there was no effect on its business operations and that its systems were running normally. (The company did not immediately respond to ...

  • Fake CCleaner installs GhostDesk Chrome spyware

    August 11, 2026

    A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which acts as spyware inside the browser. With more than 2 billion downloads worldwide, CCleaner is one of the best-known Windows utilities, making it an attractive target for cybercriminals looking to distribute ...