Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors NightEagle

Also known as: APT-Q-95, sophistication

Description

NightEagle—also identified as APT‑Q‑95—is a state‑sponsored threat actor that began active campaigns against Chinese defense, government, financial‑services, and critical‑infrastructure organizations at least since 2023. The group’s operations are driven by financial gain but also include targeted collection of military and high‑tech data, often via exploitation of Microsoft Exchange Servers using an undisclosed zero‑day unauthenticated remote code execution vulnerability. Once inside a target network, NightEagle installs memory‑only “memory horse” persistence through IIS process injection, leaving little observable footprint. The adversary harvests the Exchange machineKey to enable credential compromise and unauthorized mailbox access, then deploys custom Go‑based trojans (often built on Chisel) for encrypted command and control channels. Additionally, it leverages ReGeorg web‑shell proxies to construct multi‑hop SOCKS tunnels that facilitate lateral movement across compromised hosts. The actor’s operational profile is marked by night‑time activity, rapid infrastructure pivots using purchased VPSs, disposable domains, and constant anti‑forensic measures such as clearing event logs and monitoring debugging tools. These elements combine to create a highly stealthy, low‑impact intelligence gathering campaign that adapts quickly to changes in geopolitical priorities. While details of exact malware code remain limited outside secondary sources, the combination of zero‑day exploitation, fileless persistence, encrypted tunneling, and dynamic infrastructure indicates an organization with advanced scripting, software engineering and operational security capabilities.

Goals & Targeting

Targeted Sectors

Defense
Government
Financial services
Critical infrastructure

Targeted Countries / Regions

CN
IT

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

NightEagle (APT‑Q‑95) is a highly sophisticated nation‑state actor that has exploited an undisclosed zero‑day in Microsoft Exchange Server to infiltrate China’s military, defense and high‑tech sectors. The group uses fileless memory‑horse persistence, Go‑based encrypted tunnels and web‑shell proxies for lateral movement, conducting operations under a strict night‑time schedule aligned with North American time zones. Its stealthy tactics and rapid infrastructure pivots enable low‑noise intelligence gathering across critical sectors.

Goals & Targeting

NightEagle’s strategic objective is dual‑phased: extract high‑value sensitive information—particularly military communications, AI research, and critical infrastructure processes—and monetize these gains through direct financial theft or extortion. The actor specifically targets Chinese entities involved in defense procurement, advanced manufacturing, large language model development, and other technology sectors that can provide actionable intelligence for rival states. Its choice of night‑time operations reduces the risk of detection by typical daytime monitoring regimes while aligning activity with North American business hours to simplify command and control traffic analysis. The targeting also reflects a broader geopolitical agenda, as it has recently focused on large language model organizations amid China’s AI expansion, suggesting adaptability to emerging technological domains. By exploiting Exchange zero‑days, NightEagle can gain broad, privileged access across multiple user accounts, enabling them to harvest emails, documents, and encrypted communications with minimal technical disruption. The actor appears to prefer low‑noise, low‑impact tactics over high‑visibility attacks, likely to maintain long‑term persistence and avoid disrupting the operations of strategic partners that might otherwise alert national defense agencies.

Enhanced Description

Key Capabilities

  • Zero‑day exploitation of Microsoft Exchange for unauthenticated RCE
  • Memory‑horse fileless persistence via IIS process injection
  • Custom Chisel‑based Go trojan for encrypted C2 tunnels
  • ReGeorg web shell proxy for SOCKS-based lateral movement
  • Anti‑forensic tactics including clearing event logs and monitoring debugging tools
  • Rapid infrastructure pivots using VPS resources and disposable dynamic domains
  • Night‑time activity schedule aligned with North American time zones
  • Extraction of Exchange machineKey for credential compromise
  • Harvesting sensitive email content from compromised servers

MITRE ATT&CK Tactics

Initial Access
Persistence
Privilege Escalation
Defense Evasion
Command and Control
Collection
Execution
Exfiltration

ATT&CK Techniques

T1053.005
T1114.001
T1190
T1552.004
T1041
T1090.003
T1055.012
T1027
T1059.006
T1071.001
T1070.001
T1203
T1055
T1550.002

Software / Tooling

Chisel
ReGeorg
Memory Horse (fileless trojan)
Custom Go-based tunnel

Campaigns & Victims

NightEagle demonstrates a pattern of leveraging newly discovered zero‑days—most notably in Microsoft Exchange—to gain initial footholds, followed by rapid pivoting to multiple VPS back‑ends and disposable domains that rotate frequently. Victim organizations are typically large Chinese military or high‑tech entities, especially those involved in AI and defense manufacturing. The group's operational tempo is measured; each campaign unfolds over weeks of stealthy exfiltration rather than immediate disruptive damage. Past operations have shown a focus on acquiring credential material (e.g., Exchange machineKeys) and sensitive email contents, while avoiding large‑scale sabotage. Notably, the actor has adapted to new targets such as AI companies, indicating a responsive threat landscape aligned with geopolitical developments. Campaigns employ low‑noise activity during overnight hours, limiting visibility by conventional monitoring solutions. The use of fileless persistence means that logs and indicators are often sparse; investigators must look for subtle signs like unusual out‑bound traffic patterns (Go tunnels) or rapid domain changes.

IOC Patterns

  • Exchange EWS/OWA HTTP request exploitation
  • Memory-only persistence in IIS process pool
  • Encrypted tunnel over TCP/UDP using Go-based C2
  • ReGeorg‑generated SOCKS proxy on compromised servers
  • Zero‑day vulnerability in Microsoft Exchange Server
  • Extraction of Exchange machineKey for credential compromise
  • Use of disposable domains and VPS dynamic IPs
  • Harvesting sensitive email content from mailboxes

Recommended Actions

  • Apply all available patches to Microsoft Exchange immediately, specifically covering any announced zero‑days.
  • Restrict inbound access to Exchange web services (EWS/OWA) using network segmentation or firewall rules.
  • Deploy EDR solutions that detect fileless persistence and process injection within IIS.
  • Monitor outbound traffic for encrypted tunnel patterns (Go tunnels) and unexpected SOCKS proxy connections.
  • Disable or tightly monitor the creation of scheduled tasks; alert on new tasks spawned by non‑trusted processes.
  • Implement continuous monitoring of Microsoft Exchange authentication logs to flag anomalous use of machineKeys.
  • Use dynamic DNS analytics and domain reputation services to detect rapid domain/IP rotations linked to VPS pivots.
  • Enable comprehensive logging for Windows event logs to capture log clearing or tampering events.
  • Conduct regular security awareness training focused on phishing resilience and credential protection.
  • Establish an incident response playbook that includes procedures for investigating and mitigating Exchange-based zero‑day exploitation.

Suggested Tags

APT-Q-95
NightEagle
Microsoft Exchange Zero-Day Exploit
Zero-Day Vulnerability
Fileless Malware
Memory Horse Persistence
Chisel C2 Tunnel
ReGeorg Proxy
VPS Pivoting
Disposable Domains
China Military Targeting
High-Tech Sector
Financial Theft
Cyber Espionage
North America Timezone Operations
Low-Noise Persistence

Confidence Assessment

The assessment is derived mainly from secondary intelligence reports and public disclosures, which provide a high‑level overview of NightEagle’s tactics but lack corroborating technical artifacts. While the use of Exchange zero‑days, memoryhorse persistence, and Chisel tunnels are well described across sources, direct evidence such as malware samples or verified CVE details remains limited. Consequently, confidence is moderate: we can affirm the actor’s general capabilities and targeting approach, but uncertainty persists regarding specific exploit details, full extent of infrastructure, and evolving toolsets. Information gaps include precise CVE identifiers, detailed payload implementations, and long‑term persistence mechanisms beyond the initial intrusion stages. Further on‑ground evidence or verified threat intel would improve confidence in both mitigation strategies and attribution certainty.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 13 Email Address 1 Filename 3 IPv4 Address 2 SHA-256 Hash 1

References

  1. www.inceptionsecurity.com — Cited by web research for: T1190
  2. thehackernews.com — Cited by web research for: Trojan
  3. thecyberthrone.in — Cited by web research for: PowerShell
  4. innovirtuoso.com — Cited by web research for: Zero-day exploits
  5. gbhackers.com — Cited by web research for: Phantom Stealer
  6. dailysecurityreview.com — Cited by web research for: CVE-2026-58644
  7. bitnewsbot.com — Cited by web research for: CVE-2026-16723
  8. cybersecurityhunter.com — Cited by web research for: Hunter
  9. https://malpedia.caad.fkie.fraunhofer.de/actor/nighteagle — Cited by AI analysis.

Intel Summary

14

Techniques

42

Tools

0

Campaigns

34

IOCs

0

Observed Data

9

Tactics

Tags

APT
Government Targeting
APT-Q-95
NightEagle
Microsoft Exchange Zero-Day Exploit
Zero-Day Vulnerability
Fileless Malware
Memory Horse Persistence
Chisel C2 Tunnel
ReGeorg Proxy
VPS Pivoting
Disposable Domains
China Military Targeting
High-Tech Sector
Financial Theft
Cyber Espionage
North America Timezone Operations
Low-Noise Persistence

Details

Type
Nation-State
Primary Motivation
Financial gain
Country of Origin
U
Confidence
25%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.