CyberSecurity SEE

NightEagle Utilizes BlueKeep and DCSync to Approach Active Directory Domain Controllers

NightEagle Utilizes BlueKeep and DCSync to Approach Active Directory Domain Controllers

NightEagle Expands Espionage Operations, Targeting Russian Organizations

NightEagle, a prominent espionage group also known as APT-Q-95, has recently broadened its scope of operations beyond its traditional Asian targets to also include various Russian organizations. This escalation in activity showcases a sophisticated and layered intrusion methodology that culminates in efforts to compromise Active Directory (AD) domain controllers.

The latest campaign launched by NightEagle highlights a dangerous yet familiar pattern of enterprise compromise. Unlike other high-profile cyberattacks that rely on novel zero-day exploits, these attackers have discovered an effective route to gaining domain-wide control by exploiting exposed remote access, unpatched internal systems, and excessive privileges within Active Directory.

In the incidents investigated, NightEagle secured initial access to networks by employing stolen legitimate credentials specifically targeting corporate Virtual Private Network (VPN) services. This tactic allowed them to bypass traditional security measures with relative ease. Observations recorded connections emanating from Russian internet Protocol (IP) spaces tied to Cloudflare WARP tunnels, as well as from various European virtual private server infrastructures. By blending malicious access with seemingly valid remote logins, the operators could mask their activities within the organization.

Once inside the targeted environment, NightEagle utilized a tool known as GhostContainer on Microsoft Exchange servers, a critical system within many organizations. GhostContainer is a .NET-based implant that incorporates publicly available components, including Neo-reGeorg—a tool associated with exploiting the vulnerability CVE-2020-0688—and the GhostWebShell class from the ysoserial library. Kaspersky, a cybersecurity firm investigating these incidents, raises alarms that the operators have likely extracted ASP.NET cryptographic keys, manipulated the VIEWSTATE parameter, and executed malicious payloads in memory rather than relying on conventional web shells stored on disk.

This methodology not only enhances the effectiveness of their operations but also diminishes detection chances by making it harder for security teams to identify the presence of malware. Given that Exchange servers are typically internet-facing, highly privileged, and trusted within organizations, they serve as strategic footholds that NightEagle successfully exploits.

In their operations, the threat actors disguised GitHub-hosted archives as legitimate software packages to deploy tunneling utilities crucial for their offensive maneuvers. Kaspersky’s Global Emergency Response Team has subsequently linked these activities to the theft of VPN credentials, the GhostContainer Microsoft Exchange backdoor, Remote Desktop Protocol (RDP) tunneling efforts, BlueKeep exploitation, and methods for credential replication via DCSync.

NightEagle effectively combined Microsoft Dev Tunnels, a legitimate developer service used to publish local services through domain connections, with the public utility known as rdp2tcp. This pairing allows attackers to expose or relay RDP traffic covertly while avoiding the need to open new, conspicuous inbound ports on compromised systems. The resulting complexity complicates detection and significantly enhances the attacker’s capability to navigate within the environment undetected.

Defensive teams are urged to scrutinize logs related to RDP events, particularly those within the Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational logs. Specific events, such as the creation and closure of virtual channels, can reveal tunneling activity linked to RDP. Unexpectedly named channels, especially those incorporating terms like "rdp2tcp" can indicate the ongoing tunneling rather than routine RemoteFX use.

An essential element in the intrusion chain involved Active Directory itself. In one of the incidents, NightEagle leveraged the well-known CVE-2019-0708 vulnerability—commonly referred to as BlueKeep—to craft a local account that was subsequently added to both the local Administrators and Remote Desktop Users groups. This strategic move laid the groundwork for lateral movement within compromised networks.

Researchers noted that the actors then initiated requests for Kerberos tickets with an unusual combination of Forwardable, Proxiable, and Renewable flags. Moreover, tactics were observed where the perpetrators attempted to replicate the Active Directory Domain-Password object using DCSync. This method allows an attacker with sufficient replication privileges to impersonate a domain controller and request password data from Active Directory, leading to a potential breach of sensitive information, including password hashes associated with privileged accounts.

To mitigate the risks posed by these sophisticated tactics, organizations are strongly advised to promptly patch systems exposed to BlueKeep vulnerabilities, disable RDP access where possible, and enforce stringent network-level authentication combined with strict segmentation of any remaining RDP services. Increased vigilance surrounding VPN access is crucial, particularly requiring phishing-resistant multi-factor authentication for sensitive services, along with scrutinizing any anomalous logins from anonymizing tunnels or unfamiliar virtual hosting providers.

In summary, this recent campaign underscores a significant shift in NightEagle’s operational focus, highlighting the need for organizations to adapt their defensive strategies to counteract evolving threats. By closely monitoring systems, engaging in proactive security measures, and fortifying their defenses against tactics used by this espionage group, organizations can better protect themselves against potential infiltration and compromise of their critical identity infrastructure.

Source link

Exit mobile version