Sunday, 20 July

Monday, 7 July2025

NightEagle APT Exploits Microsoft Exchange Zero‑Day to Spy on China’s Tech and Military

NightEagle APT Exploits Microsoft Exchange Zero‑Day to Spy on China’s Tech and Military
Security researchers have uncovered NightEagle (aka APTQ95), a new advanced persistent threat targeting Microsoft Exchange zero-days. Active since 2023, it injects a custom .NET loader into Exchange IIS, steals machineKey, deserializes servers, and accesses mailboxes. Leveraging Go-based Chisel for intranet penetration, it focuses on Chinas government, military, AI, quantum, semiconductors, and defense sectorsoperating stealthily by night and rapidly swapping infrastructure.

Subscribe To Our Newsletter.

Full Name
Email