🚀 Introducing the CloudSEK MCP Server!
Read more
%20(1).png)
An exposed server owned by a Russia-nexus threat actor revealed months of activity from a high-volume initial access broker. The operator exploited internet-facing appliances across a dozen-plus countries, harvesting credentials and achieving full Active Directory compromise across education, healthcare, finance, telecommunications, and government victims. In multiple confirmed cases, ransomware groups claimed the same organizations within weeks of the operator's access, indicating the operator supplies access upstream of extortion rather than conducting it directly.
Late in the timeline, the operator deployed Sliver C2 against Ukrainian defence and aerospace targets, stealing source repositories and harvesting imagery from thousands of exposed IP cameras and RDP sessions. This tradecraft closely matches the AIVD/MIVD advisory on Russian state-linked camera surveillance used to locate Ukrainian military assets. The US, Europe, and Korea were seen within the artefacts as secondary targets.
We assess with high confidence the operator is a Russian-speaking initial access broker. The Ukraine-focused activity is best explained as a criminal contractor selling access, including camera-derived intelligence to state buyers, consistent with the documented pattern of Russian intelligence services sourcing access from criminal operators rather than running it directly.
The directory's structure reflects the operator's working method. Exploit code is organised by CVE; target lists are partitioned by country; scan results are separated into vulnerable, not vulnerable, and unreachable sets, with the not vulnerable list retained for later revisiting. A checkpoint file recorded that scanning had processed a large volume of targets and was configured to continue, consistent with sustained, ongoing operation rather than a discrete campaign.


The operator verified external connectivity, prepared the environment, installed required tooling (Go, httpx), and downloaded country specific target lists before launching multiple campaigns simultaneously using GNU screen.

Multiple exploitation frameworks targeting Fortinet, SonicWall, Sophos, Citrix, SAP, Roundcube, and vBulletin were executed in parallel. The operator largely relied on public proof-of-concept exploits, modifying only a small subset for operational use.

The operator ran a custom mass scanner against an F5 BIG ip target list and successfully managed to exploit and create admin credentials on many load balancers with identifiable hostnames concentrated in higher education and further victims across healthcare, financial services, and telecommunications. The final list was written in a good.log for the operator to review.

After identifying a successful compromise, the operator established access through a Neo-reGeorg web shell, created a SOCKS tunnel, and later authenticated to internal Windows hosts using stolen NTLM hashes via Evil-WinRM.

The operator extracted the domain DPAPI backup key, recovered browser and credential-store secrets, and dumped SAM and LSA secrets across the environment, ultimately obtaining full control of the Active Directory domain. A domain controller does not issue a decade long TGT; this is a forged ticket, confirming the operator obtained the domain's krbtgt secret and thereby full domain compromise, with indefinite re entry independent of credential resets

Beyond credential collection, the operator accessed cloud backup repositories using stolen credentials and decrypted firewall configuration backups containing plaintext credentials, certificates, and private keys.

Late in the timeline, activity diverged from commercial access brokerage. The operator deployed Sliver C2 infrastructure and conducted targeted collection against Ukrainian defence and aerospace organisations, including theft of exposed Git repositories.
Exploit code for at least a dozen distinct vulnerabilities was staged across the tree. Most are unmodified public proof-of-concept clones, several still carrying their original authors' metadata and credit lines. A small number were modified beyond upstream, and one FortiOS toolkit was rebuilt as an independent framework.
Alongside these sat a stock copy of the public nuclei templates repository, more than 100 templates added to this specific instance including detectors for recently disclosed vulnerabilities and for stealer and C2 panels. This indicates the operator actively tracks new disclosures and incorporates them quickly.
The history also shows the operator deploying AI assisted tooling to automate reconnaissance and pentesting including an autonomous pentest-agent framework and a browser automation server. The most recent addition being Kimi. It was heavily hyped shortly before this activity, and its use here shows an operator who follows current tooling closely and adopts it quickly.
The operator's filing system was organised by at least thirteen distinct two letter sets. The distribution is that of an access broker working through whatever is exposed, region by region, rather than a targeted campaign against one sector.
The target lists ran into the hundreds of thousands of hosts across the country partitioned sets. Against that volume, confirmed compromise represents a significant fraction, concentrated throughout many different sectors


Every artifact the operator wrote themselves is in Russian tool documentation, scanner interfaces, batch-checker output, and campaign logs across multiple exploitation frameworks. Cyrillic fragments appear in the shell history where the keyboard layout also slipped mid command.
Activity timestamps cluster in the evening in Moscow time, and the operator's own WireGuard tunnel terminates on infrastructure consistent with that.
We assess a Russian speaking operator with high confidence.
The recovered activity covers scanning, exploitation, credential capture, tunnelling and lateral movement, and stops there. No encryption, no extortion, no data-leak infrastructure. Access is taken to the point where it becomes sellable, and then left.
What happens to that access afterwards is visible in public ransomware reporting. Multiple organisations whose networks this operator held access to were later claimed as victims by ransomware groups and not by the same group each time. The following are some recent examples, but the artefacts contain several victim organizations that have not been named publicly yet.
Greater Pittsburgh Orthopaedic Associates (GPOA), a US healthcare provider, appears in the directory as one of the operator's confirmed domain compromises: administrative credentials harvested, DPAPI backup key extracted from the domain controller, credential stores dumped across the internal network. RansomHouse subsequently claimed the organisation on its leak site, alleging encryption of company data.

MARTEC MARINE, an Italian firm supplying defence and integrated safety systems for navy ships, cruise liners and mega yachts damage control, fire detection and personnel tracking is the second. This is the domain where the operator forged a Kerberos golden ticket in January 2026, giving themselves authentication material valid for a decade. Tengu claimed the company on its leak site the following month.

Two features of this pattern matter more than either individual case.
“Several further instances of the same pattern were identified across the victim set, following the same sequence: access established and recorded in the directory, then a ransomware claim against the same organisation weeks later, attributed to a different group each time.”
Alongside the brokerage, the operator ran a sustained collection effort against Ukraine that follows a well documented Russian pattern: identify defence and critical infrastructure organisations, take whatever is reachable from the internet, and hold the access.
The targeting is specific and it is significant. The operator enumerated many national defence sector attack surfaces, cataloguing thousands of government, education, media and commercial domains. Organisations across the country's defence industrial base, energy generation, telecommunications and broadcast sectors appear in the recovered target and results data.
Russian services have been targeting exactly this set of organisations since the start of the war, using exactly these methods: internet-facing exposure, credential reuse, source code theft from suppliers, and long term quiet access rather than immediate disruption. The activity here sits squarely inside that pattern.
It also extends into physical space. Among the recovered artefacts are images: hundreds of frames captured from internet facing IP cameras across Ukraine, taken from facilities in the sectors above, together with hundreds of screenshots lifted from exposed remote desktop services. The operator was not only inside networks but watching sites and operator consoles directly.

In July 2026 the Dutch intelligence services, AIVD and MIVD, published a joint advisory on precisely this activity. Russian state actors, they assess, are systematically compromising internet-facing IP cameras across EU and NATO member states and Ukraine, exploiting default credentials and outdated firmware, and running image recognition over the results to identify military vehicles and the cargo they carry. In Ukraine, the advisory states, the imagery is used to help locate Ukrainian military personnel and materiel and to target them.

We assess with moderate-to-high confidence that this is state-nexus intelligence collection, conducted on the same infrastructure and by the same hands as the brokerage. The tradecraft aligns with an operation Western intelligence services attribute to Russian state actors.
Which service benefits is a separate question, and one we leave open. The Dutch services, working from considerably better visibility than a single exposed directory affords, attribute the camera campaign to "at least one Russian intelligence and security service" without naming it. We apply the same standard.
The two strands run on shared infrastructure, the same VPS, command-and-control server, tunnels and toolkit against two distinct target sets. Commercially, the operator exploits exposed appliances at volume and sells the resulting network access to ransomware operations. Separately, they collect against Ukrainian defence and critical infrastructure.
Whether that second strand reflects direct tasking, contracted work, or collection sold on to a state customer cannot be determined from this directory, and the documented overlap between Russian criminal and state cyber activity makes each plausible. What the evidence supports is a criminal access broker whose secondary activity also serves state intelligence requirements.