Russian Hacker Sells Company Access, Spies on Ukrainian Military
Key Takeaways A Russian-speaking hacker engaged in a dual operation: selling corporate access to ransomware groups and conducting espionage against Ukrainian military and defense organizations. The...
Key Takeaways
- A Russian-speaking hacker engaged in a dual operation: selling corporate access to ransomware groups and conducting espionage against Ukrainian military and defense organizations.
- The hacker exploited at least 12 known vulnerabilities in widely used network appliances and applications, including products from Fortinet, F5, and Citrix.
- Affected sectors include education, healthcare, financial services, telecommunications, and government, across multiple countries.
- The attacker achieved full Active Directory compromise in some corporate breaches, extracting Kerberos authentication keys.
- The Ukraine-focused activities involved deploying Sliver C2, accessing source code repositories, and collecting visual intelligence from IP cameras and remote desktop sessions.
A sophisticated Russian-speaking hacker has been implicated in a two-pronged cyber operation, according to new research. This individual not only breached numerous global organizations to sell network access to ransomware syndicates but also engaged in targeted surveillance of Ukrainian military and aerospace entities. The breadth of this activity, uncovered through an exposed server, highlights a concerning convergence of cybercrime and state-aligned espionage.
Table Of Content
The campaign impacted a diverse array of sectors internationally, including education, healthcare, financial services, telecommunications, and government bodies. The attacker specifically targeted internet-facing systems, exploiting known vulnerabilities to gain initial entry. Once inside, the hacker meticulously harvested credentials, navigated internal networks, and, in some instances, achieved complete control over corporate identity management systems.
Researchers at CloudSEK said in a report that their investigation began after discovering an inadequately secured server containing extensive records of the operator’s activities. The evidence strongly suggests the perpetrator functions as a high-volume initial access broker (IAB), specializing in providing network footholds rather than directly deploying ransomware.
This case underscores the critical role IABs play in the broader cybercriminal ecosystem. Compromised access, once acquired, can be resold or leveraged, offering ransomware groups a streamlined entry point into victim networks without the need to identify initial vulnerabilities themselves. Previous analyses of IAB operations have consistently emphasized the risks associated with exposed remote services and insufficiently protected credentials.
Russian Hacker Breaches Companies
The recovered data reveals that the operator conducted extensive scans across more than a dozen countries. The hacker prepared and executed exploits for at least 12 distinct vulnerabilities affecting products from major vendors such as Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, and Hikvision. These exploits targeted widely deployed technologies, leveraging publicly available proof-of-concept code, though some tools were customized for the specific operations.
This strategy enabled the attacker to rapidly test a multitude of targets, particularly organizations that had left vulnerable systems directly accessible from the public internet. After establishing initial access, the operator deployed web shells and established network tunnels to penetrate Windows systems within victim environments.
Lateral movement involved the theft of NTLM password hashes for remote authentication. The hacker also collected credential stores, security account data, and browser secrets to expand their reach. In several confirmed instances, the attacker successfully extracted the Kerberos authentication key, enabling the creation of long-lasting “Golden Tickets” and indicating a complete compromise of Active Directory. Organizations affected by these breaches later appeared on ransomware groups’ data leak sites, supporting the assessment that network access was being supplied to external extortion crews.
These findings serve as a stark reminder for defenders to prioritize the security of exposed edge devices. As recent reports on rapid vulnerability exploitation trends have highlighted, internet-facing appliances remain highly attractive targets, as a successful breach often provides a direct gateway into internal corporate networks.
Ukrainian Surveillance Operation
Intriguingly, the hacker’s activities transitioned from broad commercial targeting to a focused intelligence-gathering operation against Ukrainian defense and aerospace organizations. During this phase, the attacker deployed Sliver command-and-control (C2) frameworks, accessed exposed source-code repositories, and collected information that deviates significantly from typical corporate access brokering.
Investigators also discovered hundreds of images retrieved from internet-connected IP cameras and screenshots captured from exposed remote desktop sessions. This type of intelligence could provide the operator with critical insights into facilities, personnel movements, logistics hubs, and systems linked to vital Ukrainian sectors. This activity aligns with previous warnings regarding Russian-linked actors targeting surveillance cameras near border crossings, military installations, and transportation infrastructure to monitor aid flows into Ukraine. A related report on Russian cyberattacks against logistics networks also noted a similar interest in camera feeds and transportation data.
CloudSEK concluded, with moderate-to-high confidence, that the Ukraine-focused operations served state-linked intelligence objectives. However, the available evidence did not definitively establish whether the actor received direct orders from a state entity or sold the collected access and imagery to a state customer. Notably, both the criminal and espionage activities utilized shared infrastructure, tunnels, and tooling, suggesting a common operator or close coordination.
What You Should Do
- Secure Edge Devices: Immediately remove administrative interfaces from direct internet exposure.
- Patch Promptly: Apply all available security patches to network appliances and public-facing applications without delay.
- Treat Backups as Compromised: Assume stolen configuration backups represent a full network compromise and act accordingly.
- Rotate Credentials: Regularly rotate credentials for all appliances and services, especially after any suspected breach.
- Audit Accounts: Review all administrator logins for unfamiliar activity and check for unauthorized accounts, injected SSH keys, or altered device settings.
- Address Active Directory Compromise: If domain compromise is suspected, reset the
krbtgtaccount twice with a full replication interval. Migrate away from RC4-HMAC and investigate any unusually long Kerberos tickets. - Harden IP Cameras: Replace default passwords on all IP cameras, update firmware, isolate cameras from the public internet where possible, and avoid positioning devices where they could reveal sensitive operations or infrastructure.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.