Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical CUPS Vulnerability (CVE-2023-4586) Lets Attackers Gain Root Privileges
August 4, 2026
New Roblox Malware Steals Desktop Streams and Webcam Footage
August 4, 2026
Keyv npm package compromised in supply chain attack
August 4, 2026
Home/Threats/Russian Hacker Sells Company Access, Spies on Ukrainian Military
Threats

Russian Hacker Sells Company Access, Spies on Ukrainian Military

Key Takeaways A Russian-speaking hacker engaged in a dual operation: selling corporate access to ransomware groups and conducting espionage against Ukrainian military and defense organizations. The...

David kimber
David kimber
August 4, 2026 4 Min Read
1 0

Key Takeaways

  • A Russian-speaking hacker engaged in a dual operation: selling corporate access to ransomware groups and conducting espionage against Ukrainian military and defense organizations.
  • The hacker exploited at least 12 known vulnerabilities in widely used network appliances and applications, including products from Fortinet, F5, and Citrix.
  • Affected sectors include education, healthcare, financial services, telecommunications, and government, across multiple countries.
  • The attacker achieved full Active Directory compromise in some corporate breaches, extracting Kerberos authentication keys.
  • The Ukraine-focused activities involved deploying Sliver C2, accessing source code repositories, and collecting visual intelligence from IP cameras and remote desktop sessions.

A sophisticated Russian-speaking hacker has been implicated in a two-pronged cyber operation, according to new research. This individual not only breached numerous global organizations to sell network access to ransomware syndicates but also engaged in targeted surveillance of Ukrainian military and aerospace entities. The breadth of this activity, uncovered through an exposed server, highlights a concerning convergence of cybercrime and state-aligned espionage.

Table Of Content

  • Key Takeaways
  • Russian Hacker Breaches Companies
  • Ukrainian Surveillance Operation
  • What You Should Do

The campaign impacted a diverse array of sectors internationally, including education, healthcare, financial services, telecommunications, and government bodies. The attacker specifically targeted internet-facing systems, exploiting known vulnerabilities to gain initial entry. Once inside, the hacker meticulously harvested credentials, navigated internal networks, and, in some instances, achieved complete control over corporate identity management systems.

Researchers at CloudSEK said in a report that their investigation began after discovering an inadequately secured server containing extensive records of the operator’s activities. The evidence strongly suggests the perpetrator functions as a high-volume initial access broker (IAB), specializing in providing network footholds rather than directly deploying ransomware.

This case underscores the critical role IABs play in the broader cybercriminal ecosystem. Compromised access, once acquired, can be resold or leveraged, offering ransomware groups a streamlined entry point into victim networks without the need to identify initial vulnerabilities themselves. Previous analyses of IAB operations have consistently emphasized the risks associated with exposed remote services and insufficiently protected credentials.

Russian Hacker Breaches Companies

The recovered data reveals that the operator conducted extensive scans across more than a dozen countries. The hacker prepared and executed exploits for at least 12 distinct vulnerabilities affecting products from major vendors such as Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, and Hikvision. These exploits targeted widely deployed technologies, leveraging publicly available proof-of-concept code, though some tools were customized for the specific operations.

This strategy enabled the attacker to rapidly test a multitude of targets, particularly organizations that had left vulnerable systems directly accessible from the public internet. After establishing initial access, the operator deployed web shells and established network tunnels to penetrate Windows systems within victim environments.

Lateral movement involved the theft of NTLM password hashes for remote authentication. The hacker also collected credential stores, security account data, and browser secrets to expand their reach. In several confirmed instances, the attacker successfully extracted the Kerberos authentication key, enabling the creation of long-lasting “Golden Tickets” and indicating a complete compromise of Active Directory. Organizations affected by these breaches later appeared on ransomware groups’ data leak sites, supporting the assessment that network access was being supplied to external extortion crews.

These findings serve as a stark reminder for defenders to prioritize the security of exposed edge devices. As recent reports on rapid vulnerability exploitation trends have highlighted, internet-facing appliances remain highly attractive targets, as a successful breach often provides a direct gateway into internal corporate networks.

Ukrainian Surveillance Operation

Intriguingly, the hacker’s activities transitioned from broad commercial targeting to a focused intelligence-gathering operation against Ukrainian defense and aerospace organizations. During this phase, the attacker deployed Sliver command-and-control (C2) frameworks, accessed exposed source-code repositories, and collected information that deviates significantly from typical corporate access brokering.

Investigators also discovered hundreds of images retrieved from internet-connected IP cameras and screenshots captured from exposed remote desktop sessions. This type of intelligence could provide the operator with critical insights into facilities, personnel movements, logistics hubs, and systems linked to vital Ukrainian sectors. This activity aligns with previous warnings regarding Russian-linked actors targeting surveillance cameras near border crossings, military installations, and transportation infrastructure to monitor aid flows into Ukraine. A related report on Russian cyberattacks against logistics networks also noted a similar interest in camera feeds and transportation data.

CloudSEK concluded, with moderate-to-high confidence, that the Ukraine-focused operations served state-linked intelligence objectives. However, the available evidence did not definitively establish whether the actor received direct orders from a state entity or sold the collected access and imagery to a state customer. Notably, both the criminal and espionage activities utilized shared infrastructure, tunnels, and tooling, suggesting a common operator or close coordination.

What You Should Do

  • Secure Edge Devices: Immediately remove administrative interfaces from direct internet exposure.
  • Patch Promptly: Apply all available security patches to network appliances and public-facing applications without delay.
  • Treat Backups as Compromised: Assume stolen configuration backups represent a full network compromise and act accordingly.
  • Rotate Credentials: Regularly rotate credentials for all appliances and services, especially after any suspected breach.
  • Audit Accounts: Review all administrator logins for unfamiliar activity and check for unauthorized accounts, injected SSH keys, or altered device settings.
  • Address Active Directory Compromise: If domain compromise is suspected, reset the krbtgt account twice with a full replication interval. Migrate away from RC4-HMAC and investigate any unusually long Kerberos tickets.
  • Harden IP Cameras: Replace default passwords on all IP cameras, update firmware, isolate cameras from the public internet where possible, and avoid positioning devices where they could reveal sensitive operations or infrastructure.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitHackerPatchransomwareSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical Gitea RCE Vulnerability CVE-2024-XXXX Exposes Servers

Next Post

Cybercriminals Exploit ChatGPT for Scam Operations, OpenAI Reports

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Gitea RCE Vulnerability CVE-2024-XXXX Exposes Servers
August 4, 2026
Critical Adobe Campaign Classic Flaws Let Attackers Run Code
August 4, 2026
Critical Flaws in Google Cloud AI Let Attackers Hijack CI/CD Pipelines
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us