NightEagle APT Targets China via Zero-Day Exchange Exploits

NightEagle APT Targets Microsoft Exchange Servers in China with Zero-Day Exploits, Focusing on Advanced Technology and Defense Sectors

  • A new threat group known as NightEagle (APT-Q-95) has targeted Microsoft Exchange servers in China using zero-day vulnerabilities.
  • The cyber attacks focus on government, defense, and technology organizations, especially in sectors like semiconductors, quantum technology, Artificial Intelligence, and military research.
  • NightEagle uses a modified version of the open-source Chisel tool, delivered through a custom .NET loader implanted into Microsoft Internet Information Server (IIS).
  • The attackers exploit an Exchange zero-day to obtain key credentials, allowing unauthorized access and data extraction from targeted servers.
  • Security researchers suggest the threat actor operates at night in China and may be based in North America, based on observed attack times.

Researchers have identified a previously unknown cyber espionage group, NightEagle, actively targeting Microsoft Exchange servers in China. This threat actor uses a chain of zero-day exploits to infiltrate organizations in the government, defense, and advanced technology sectors.

- Advertisement -

According to QiAnXin’s RedDrip Team, NightEagle has targeted companies in fields such as semiconductors, quantum technology, artificial intelligence, and military R&D. The group has operated since 2023, moving quickly between different network infrastructures and frequently updating its methods.

The research team began their investigation after finding a custom version of the Chisel penetration tool on a customer system. This tool was set to run automatically every four hours. Analysts explained in their report that the attackers altered the open-source Chisel tool, setting fixed usernames, passwords, and connecting specific ports between the compromised network and their command server.

The initial Malware is delivered through a .NET loader, which is embedded in the Internet Information Server (IIS) of the Exchange server. The attackers leverage an undisclosed flaw—a zero-day vulnerability—to retrieve the server’s machineKey credential. This lets them deserialize and load additional malware into any Exchange server of a compatible version, gaining remote access and the ability to read mailbox data.

A spokesperson for QiAnXin stated, “It seems to have the speed of an eagle and has been operating at night in China,” referencing the group’s operating hours and naming rationale. Based on activity patterns, investigators suspect NightEagle may be based in North America because most attacks occur between 9 p.m. and 6 a.m. Beijing time.

- Advertisement -

The findings were revealed at CYDES 2025, Malaysia’s National Cyber Defence & Security Exhibition and Conference. QiAnXin has notified Microsoft about the research for further action.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Cathie Wood: Trump May Move From Seized BTC to Market Buys!!

Cathie Wood says the administration may buy up to 1 million Bitcoin ahead of...

Zcash developer activity hits lowest since 2021 amid feud now

Developer activity tied to ZCash hit its lowest level since November 2021.The ZEC token...

India Skips BRICS Naval Drill Amid India-China Tensions Grow

India declined to join a BRICS naval exercise off Durban, South Africa, citing political...

Australia warns Grok fuels surge in non-consensual AI images

Australia’s online safety regulator has seen complaints about the Grok chatbot rise sharply, with...

Analyst: XRP Poised for 2026 Breakout Toward $8–$10 +Upside

XRP surged from $0.24 to $2.46 in January 2018, a near 900% rise that...
- Advertisement -

Must Read

Best Metaverse Tokens to Buy on Binance for 10X Gains

Ever since Facebook renamed their company to Meta, as well as their plans to build a metaverse where we can travel into using Virtual...
Bitcoin (BTC) $ 90,411.00 0.43%
Ethereum (ETH) $ 3,095.39 0.57%
XRP (XRP) $ 2.10 0.46%
Bittensor (TAO) $ 285.13 6.34%
Polkadot (DOT) $ 2.08 1.47%
Cardano (ADA) $ 0.392437 0.98%
Chainlink (LINK) $ 13.19 0.05%
Hyperliquid (HYPE) $ 25.55 2.03%
Monero (XMR) $ 457.77 0.89%
Hedera (HBAR) $ 0.119155 0.40%
Toncoin (TON) $ 1.77 3.48%