NightEagle Expands From China's High-Tech Sector to Russian Enterprises
Kaspersky reports that the hacking group NightEagle, previously tied to China's high-tech sector, has now been linked to incidents at Russian businesses.
Both sources report Kaspersky findings tying the hacking group NightEagle to Russian enterprises. Recorded Future News frames this as an expansion from the group's known focus on China's high-tech sector, noting that Kaspersky investigated several incidents at Russian businesses over the past year.
The Hacker News places NightEagle in a broader context, describing it as one of three threat clusters—alongside Hacking Cat and Toy Ghouls—identified in Kaspersky's reporting on attacks against Russian enterprises. It also notes that NightEagle is tracked under the alias APT-Q-95.
The two accounts agree on the core development: NightEagle has been active against Russian businesses. They differ in scope, with Recorded Future News emphasizing the group's geographic expansion and The Hacker News highlighting a wider wave of attacks involving backdoors, ransomware, and wipers.
Sources · 2
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.