Malaysia Sun
07 Jul 2025, 06:23 GMT+10
At the recently held 2025 International Defense Cybersecurity Exhibition (CYDES 2025), Qianxin, a leading Chinese cybersecurity company, released a significant report that exposed an advanced persistent threat (APT) group known as 'Night Eagle' (APT-Q-95). This group leverages high-risk vulnerabilities in Microsoft Exchange to launch sophisticated cyber attacks against government agencies, military units, high-tech companies, and research institutions worldwide.
National hacker groups surfaced
According to Gu Liang, head of the threat intelligence team at Qianxin, the "Night Hawk" group shows clear characteristics of a state-level hacking operation:
The attack time is highly regular (from 21:00 to 6:00 the next day)
The dynamic C2 architecture is adopted and IP such as DigitalOcean, an American cloud service provider, is used for jumping
Specifically targeted to the Microsoft Exchange mail system vulnerability implementation of intrusions
Have a deep understanding of the underlying Exchange code and authentication protocol
Such attacks are not only technologically advanced but also clearly state-sponsored cyber espionage operations that have been meticulously planned over a long period, Gu Liang stressed. 'Once the email server, which serves as the core communication hub for government and enterprise institutions, is breached, it will result in the comprehensive leakage of sensitive data, including business, financial, and customer relationship information.'
Attack methods and hazards
The analysis shows that the Night Hawk group carries out attacks mainly in the following ways:
Exploiting the remote code execution vulnerability in Microsoft Exchange Server
Use malicious domain names (such as synologyupdates.com, app.flowgw.com) to establish C2 channels
It has been lurking in the target system for a long time to steal and monitor data
The group has been involved in attacks on a large number of high-tech companies, research institutions and sensitive sectors in China, and its arsenal of zero-day vulnerabilities makes it one of the most dangerous and active APT groups today.
Southeast Asian countries face serious threats
Qianxin has warned that Malaysia and other ASEAN countries could be the next targets of the Night Hawk group. The company has made public relevant attack signature indicators (IOCs) to help regional enterprises carry out targeted detection and defense.
AI empowers cyber security defense
During the exhibition, Qianxin demonstrated its AI-driven security solutions:
Security Operations Center (SOC) system based on machine learning
Automated threat detection and response capabilities
It can process millions of security alerts per day
The underreporting rate is kept at a very low level (less than 10^-6)
"In the face of increasingly complex cyber threats, traditional defense methods have been overwhelmed." Gu Liang said, "AI technology not only greatly improves the efficiency of security engineers, but also enables accurate threat hunting and rapid emergency response."
Call for international cooperation
With the exposure of the Night Hawk group, cyber security experts have called on countries to strengthen cooperation and jointly deal with state-level cyber threats. Qianxin said it will continue to expand its business in southeast Asia and work with regional partners to build a stronger cyber security defense line.
Get a daily dose of Malaysia Sun news through our daily email, its complimentary and keeps you fully up to date with world and business news as well.
Publish news of your business, community or sports group, personnel appointments, major event and more by submitting a news release to Malaysia Sun.
More InformationWASHINGTON, D.C.: President Donald Trump says the United States could soon reach a trade deal with India. He believes this deal would...
Nearly three months after a devastating earthquake struck Myanmar, the country remains trapped in a deepening crisis, compounded by...
China ready to promote flagship Belt and Road project, boost trade, investment with Ethiopia -- Premier Li China stands ready to...
Rio de Janeiro [Brazil], July 7 (ANI): External Affairs Minister S Jaishankar held a meeting with his Russian counterpart Sergey Lavrov...
Rio de Janeiro [Brazil], July 7 (ANI): Leaders of the BRICS nations welcomed Indonesia as a member of the group, while 10 nations,...
Birmingham [UK], July 7 (ANI): Following a historic outing with the bat at Birmingham, Indian skipper Shubman Gill reflected on changes...
MILAN, Italy: Italian regulators have flagged four non-EU countries—including Russia—as carrying systemic financial risk for domestic...
NEW YORK CITY, New York: With just weeks to spare before a potential government default, U.S. lawmakers passed a sweeping tax and spending...
PARIS, France: Fast-fashion giant Shein has been fined 40 million euros by France's antitrust authority over deceptive discount practices...
PALO ALTO/TEL AVIV: The battle for top AI talent has claimed another high-profile casualty—this time at Safe Superintelligence (SSI),...
FRANKLIN, Tennessee: Hundreds of thousands of Nissan and Infiniti vehicles are being recalled across the United States due to a potential...
REDMOND, Washington: Microsoft is the latest tech giant to announce significant job cuts, as the financial strain of building next-generation...