NightEagle targets Russian companies
2026-09-16T20:51:46Z•be5ad3df27ec652d287419cd92202cdb3256328b276961d19c59df756f6083f8
APTActive DirectoryAndroidC2ElementGitHubICSJavaScriptMQTTMatrixNode.jsRDPTelegramTrueConfbackdoorcyber-espionageindustrial-control-systemskernel rootkitmalwareproxy botnetransomwarevulnerability exploitation
What happened
Kaspersky Securelist RSS entries report multiple 2026 threat campaigns, including NightEagle exploitation of Active Directory and RDP, Toy Ghouls backdoors using MQTT and Matrix-based command and control, Mirage Kitten malware targeting aviation and FinTech, ValleyRAT distributed as adware, Android proxy-botnet malware, HoneyMyte’s kernel-level rootkit, Armored Likho Telegram espionage, and Head Mare exploitation of unpatched TrueConf servers. The feed also includes industrial-threat and vulnerability trend reports. Specific CVE identifiers are not provided in the supplied summaries.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- be5ad3df27ec652d287419cd92202cdb3256328b276961d19c59df756f6083f8
- Enrichment time
- 2026-09-16T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.