← NEWS & INSIGHTS

NEWS / RESEARCH & ANALYSIS

NightEagle investigation connects identity, Exchange and network evidence

Kaspersky describes several incidents involving valid VPN credentials, the GhostContainer backdoor on Exchange and network-tunneling tools.

Source published 2026-09-16Digital forensicsResearch briefing
Original publication preview: NightEagle investigation connects identity, Exchange and network evidence
Kaspersky / Securelist ↗

Findings and evidence

Kaspersky describes several incidents involving valid VPN credentials, the GhostContainer backdoor on Exchange and network-tunneling tools. The report distinguishes observed artifacts from its assessment of how the backdoor reached the servers.

Why it matters

An investigation should join identity events, server evidence and outbound network records into one timeline. Retaining only workstation alerts can leave gaps when the activity is concentrated on shared infrastructure.

Scope and limits

The researchers could not determine the precise delivery method in every case. Their proposed explanation and attribution remain assessments, not independently proven facts about every affected environment.

Primary source

Kaspersky / Securelist: original publication. Source published 2026-09-16. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.

Search the lab

NEWS / FORENSICS / FIELD GUIDES ESC