Back to knowledge center
NewProduct updates·From the official source·1 min read·0 views

NightEagle targets Russian companies with GhostContainer backdoor

Kaspersky GERT experts have uncovered a new NightEagle APT campaign targeting Russian companies. The campaign features the GhostContainer backdoor and GitHub-hosted tools, and exploits vulnerabilities in Active Directory and RDP.

Kaspersky

Kaspersky has reported that its GERT experts uncovered a new campaign by the NightEagle APT group targeting Russian companies.

According to the source, the campaign features a backdoor known as GhostContainer along with tools hosted on GitHub that are used in intrusion and control operations.

The group is also exploiting vulnerabilities in Active Directory and in Remote Desktop Protocol (RDP) as part of its methods in this campaign.

These details matter to security teams because they combine a dedicated backdoor, publicly available GitHub-hosted tools, and exploitation of highly sensitive enterprise services such as Active Directory and RDP.

Readers should consult the official Securelist publication for the full details, including any CVE identifiers and the detection and containment guidance provided by the source, and should check for later updates to the report.

Original publication date

September 16, 2026

Open the official source