NightEagle targets Russian companies
2026-09-17T08:51:49Z•22024666da908a0a03d5019bc8731c7ada502010be24d83bd372eb2759a1e57a
APTActive-DirectoryAfricaAndroidC2FinTechGitHubICSMQTTMatrixMiddle-EastRDPRussiaTrueConfadwareaviationbackdoorcyber-espionageindustrial-control-systemskernel-rootkitmalwareproxy-botnetransomwaresupply-chainunpatched-vulnerability
What happened
Kaspersky Securelist reporting highlights multiple 2026 campaigns involving APT groups and malware targeting Russian organizations, aviation and FinTech, industrial environments, Android vehicle head units, and video-conferencing infrastructure. Key activity includes exploitation of Active Directory, RDP, and unpatched TrueConf servers; backdoors using GitHub, MQTT, and Matrix-based messaging for command and control; kernel-level rootkits; proxy botnets; credential and Telegram data theft; and malware disguised as legitimate software or adware. The feed also includes broader vulnerability, ICS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 22024666da908a0a03d5019bc8731c7ada502010be24d83bd372eb2759a1e57a
- Enrichment time
- 2026-09-17T08:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.