NightEagle targets Russian companies

2026-09-17T08:51:49Z•22024666da908a0a03d5019bc8731c7ada502010be24d83bd372eb2759a1e57a
APTActive-DirectoryAfricaAndroidC2FinTechGitHubICSMQTTMatrixMiddle-EastRDPRussiaTrueConfadwareaviationbackdoorcyber-espionageindustrial-control-systemskernel-rootkitmalwareproxy-botnetransomwaresupply-chainunpatched-vulnerability

What happened

Kaspersky Securelist reporting highlights multiple 2026 campaigns involving APT groups and malware targeting Russian organizations, aviation and FinTech, industrial environments, Android vehicle head units, and video-conferencing infrastructure. Key activity includes exploitation of Active Directory, RDP, and unpatched TrueConf servers; backdoors using GitHub, MQTT, and Matrix-based messaging for command and control; kernel-level rootkits; proxy botnets; credential and Telegram data theft; and malware disguised as legitimate software or adware. The feed also includes broader vulnerability, ICS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
22024666da908a0a03d5019bc8731c7ada502010be24d83bd372eb2759a1e57a
Enrichment time
2026-09-17T08:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · NightEagle targets Russian companies · Baitaphish