logo

GhostContainer backdoor: malware compromising Exchange servers of high-value organizations in Asia

ID: a40a7dde-b6b8-50fd-864c-252baf2428a9

STIX ID: report--a40a7dde-b6b8-50fd-864c-252baf2428a9

Feed Name: Securelist by Kaspersky

Threat Score
82/100

Date Published: 2025-07-17

Date Updated: 2026-04-29

Author: GReAT

...
...

GhostContainer (aka NightEagle/APT-Q-95) is a sophisticated .NET backdoor discovered in Exchange environments that provides C2 parsing, shellcode execution, dynamic module loading, AMSI and event-log evasion, and web-proxy/tunneling to reach internal hosts; analysts link its deployment to exploitation of an Exchange N-day (likely CVE-2020-0688) in attacks against government and high-tech targets in Asia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.