North American APT Uses Exchange Zero-Day to Attack China
ID: e589eba7-73d3-50aa-9e26-4b9bb4d4e5fb
STIX ID: report--e589eba7-73d3-50aa-9e26-4b9bb4d4e5fb
Feed Name: Dark Reading
Qianxin Technology's RedDrip team disclosed a year-long espionage campaign attributed to a group they call "NightEagle" (APT-Q-95) that exploited an unknown Microsoft Exchange bug to exfiltrate high-value emails from Chinese military and technology targets. The actors used a custom Golang Chisel-based implant run as a scheduled task, a suspicious DNS domain (synologyupdates.com) for C2, and reportedly stole the Exchange machineKey to decrypt and read mail; Microsoft said it had not identified a new actionable vulnerability at the time of reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
