Skip to main content

Tag: ghostcontainer

2 articles

Empty corporate office with computers and blurred server room, VPN login screen on laptop.

NightEagle Exploits Legitimate Tools to Target Russian Firms

Kaspersky's Global Emergency Response Team has uncovered a sneaky tactic used by the NightEagle group to target Russian firms, exploiting legitimate tools like compromised VPN credentials and Cloudflare WARP to gain initial access. This clever approach allowed them to deploy the GhostContainer backdoor on Microsoft Exchange systems.

Analyst 207
Empty Russian office interior with cubicles, server room door ajar, and blurred computer screen on a desk near a window.

Russian Enterprises Targeted by Backdoor, Ransomware Attacks from Three Threat Groups

Russian enterprises are under attack by three threat groups, with hackers exploiting compromised credentials to breach corporate VPNs and deploy powerful malware like GhostContainer, a modular backdoor that gives attackers complete control over Microsoft Exchange Servers. This sneaky malware can run arbitrary code, manipulate files, and hide in plain sight, making it a formidable foe for even the most secure systems.

Analyst 207