cognitive cybersecurity intelligence

News and Analysis

Search

Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites

Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites

A Russian-speaking hacker has been linked to a broad operation that breached organizations worldwide, collected credentials, and prepared access for sale to ransomware groups.

The activity affected education, healthcare, financial services, telecommunications, government bodies, and other organizations with internet-facing systems.

The operator reportedly searched for exposed security appliances and public applications, then used known software flaws to enter networks.

Once inside, the attacker gathered passwords, moved through internal systems, and in some cases gained full control of company identity systems.

CloudSEK researchers identified the activity after finding an exposed server that contained a detailed record of the operator’s work. 

CloudSEK said in a report shared with Cyber Security News (CSN) that the evidence points to a high-volume initial access broker rather than a ransomware group carrying out encryption directly.

Open Directory (Source – CloudSEK)

The case shows how a single compromise can become the opening step in a larger criminal chain. Stolen access can be held, resold, or reused, allowing ransomware actors to enter a victim network without having to find the original weakness themselves.

A previous report on initial access broker activity also highlighted the danger of exposed remote services and poorly protected credentials.

Russian Hacker Breaches Companies

The recovered files indicate the operator ran large-scale scans across more than a dozen countries.

They staged exploits for at least 12 vulnerabilities affecting products from Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, Hikvision, and other widely deployed technologies.

Most of the exploit code was public proof-of-concept material, although some tools were changed for the operation.

This approach gave the attacker a fast way to test many targets, especially organizations that had left vulnerable systems directly reachable from the internet.

Multiple exploitation frameworks (Source – CloudSEK)

After finding a way in, the operator used web shells and network tunnels to reach Windows systems inside victim environments.

Stolen NTLM password hashes were then used to authenticate remotely, while credential stores, security-account data, and browser secrets were collected to expand access.

In confirmed cases, the attacker extracted the key needed to forge long-lasting Kerberos authentication tickets, indicating complete Active Directory compromise.

Organizations linked to these breaches were later named by different ransomware groups, a pattern that supports the assessment that access was being supplied to outside extortion crews.

The findings reinforce why defenders should prioritize exposed edge devices. As recent reporting on rapid vulnerability exploitation trends noted, internet-facing appliances remain attractive because a successful breach can provide a direct path into a corporate network.

Ukrainian Surveillance Operation

The operation later shifted from broad commercial targeting to focused collection against Ukrainian defence and aerospace organizations.

The attacker deployed Sliver command-and-control tooling, accessed exposed source-code repositories, and collected material that did not fit the routine pattern of selling corporate access.

Investigators also found hundreds of images taken from internet-facing IP cameras and screenshots captured from exposed remote desktop sessions.

Active Directory Compromise (Source – CloudSEK)

The activity could give an operator visibility into facilities, staff movements, logistics areas, and systems connected to Ukrainian critical sectors.

This overlaps with warnings about Russian-linked actors targeting cameras near border crossings, military locations, and transport infrastructure to monitor aid movements into Ukraine.

A related report on Russian attacks against logistics described similar interest in camera feeds and transportation data.

CloudSEK assessed with moderate-to-high confidence that the Ukraine-focused work served state-linked intelligence needs, although the available evidence did not establish whether the actor received direct tasking or sold the collected access and imagery to a state customer.

The criminal and espionage activities used shared infrastructure, tunnels, and tooling.

Organizations should remove administrative interfaces from direct internet exposure, promptly patch affected appliances, and treat stolen configuration backups as a full network exposure.

Connections to state espionage (Source – CloudSEK)

They should rotate appliance and service credentials, review unfamiliar administrator logins, and check for unauthorized accounts, injected SSH keys, or changed device settings.

Where domain compromise is suspected, defenders should reset the krbtgt account twice with a full replication interval, move away from RC4-HMAC, and investigate unusually long Kerberos tickets.

Camera operators should replace default passwords, update firmware, isolate cameras from the public internet, and avoid positioning devices where they reveal sensitive operations.

Indicators of Compromise (IoCs):-

TypeIndicatorDescriptionIPv446.8.236Operator VPS, value rendered in the supplied sourceIPv4:Port129.146.8Operator jumpbox, value rendered in the supplied sourceIPv4:Port107.189.1Chisel reverse SOCKS endpoint, value rendered in the supplied sourceIPv4185.217.9File transfer service, value rendered in the supplied sourceSHA-256b2d46bfc2612593ac4Sliver Linux implant hash, value rendered in the supplied sourceSHA-25616f83f056db777a3ffVulnerable signed driver bundled with credential dumper, value rendered in the supplied source

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Building Resilience Against Phishing & Malware and Analyze it in a safe environment – Power your SOC with ANY.RUN
The post Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts