GhostContainer backdoor: malware compromising Exchange servers of high-value organizations in Asia
ID: a40a7dde-b6b8-50fd-864c-252baf2428a9
STIX ID: report--a40a7dde-b6b8-50fd-864c-252baf2428a9
Feed Name: Securelist by Kaspersky
Threat Score
GhostContainer (aka NightEagle/APT-Q-95) is a sophisticated .NET backdoor discovered in Exchange environments that provides C2 parsing, shellcode execution, dynamic module loading, AMSI and event-log evasion, and web-proxy/tunneling to reach internal hosts; analysts link its deployment to exploitation of an Exchange N-day (likely CVE-2020-0688) in attacks against government and high-tech targets in Asia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
