NightEagle Threat Group Has Expanded Targets to Russia
The persistent threat actor has moved its operations to target Russian infrastructure after previous campaigns in Asia.
Updated on Sept. 21, 2026 in Cybersecurity

The cyber threat group NightEagle, also known as APT-Q-95, has expanded its reach to target organizations located within Russia. This shift follows previous activity concentrated in Asia.
Why it matters
The group's expansion signifies a geographical shift in its operational focus, potentially placing new organizations at risk from its documented intrusion techniques. This move underscores the evolving geopolitical reach of state-aligned or sophisticated threat actors.
NightEagle targets Active Directory domain controllers, the central databases that manage user permissions and access, using BlueKeep and DCSync exploits.
The players
NightEagle
A sophisticated threat actor, also tracked as APT-Q-95, that employs multi-stage intrusion chains to target critical network infrastructure.
The details
NightEagle, also designated as APT-Q-95, utilizes a layered intrusion chain to gain unauthorized access to corporate networks. The group specifically targets Active Directory domain controllers through the use of BlueKeep—a vulnerability affecting remote desktop services—and DCSync, a technique that allows unauthorized parties to mimic the behavior of a domain controller to extract password data.
The Tech Race
The expansion of NightEagle follows patterns categorized within the MITRE ATT&CK framework regarding how threat groups adapt their lateral movement techniques. This operational shift reflects broader industry trends in how advanced persistent threats scale their campaigns across new geographical theaters.
Organizations operating in the region should prioritize auditing domain controller access and patching against known remote service vulnerabilities. System administrators can mitigate risks by monitoring for unauthorized directory synchronization requests consistent with DCSync attacks.
The takeaway
Security teams should focus on hardening Active Directory environments against credential extraction techniques to defend against groups like NightEagle. Keep monitoring security bulletins for new indicators of compromise related to APT-Q-95 activity.
Further reading
For broader trends in global threat intelligence, consult our Cybersecurity section.






