Voltar
Inteligência do adversário
Tabela de conteúdo

Executive Summary

An exposed server owned by a Russia-nexus threat actor revealed months of activity from a high-volume initial access broker. The operator exploited internet-facing appliances across a dozen-plus countries, harvesting credentials and achieving full Active Directory compromise across education, healthcare, finance, telecommunications, and government victims. In multiple confirmed cases, ransomware groups claimed the same organizations within weeks of the operator's access, indicating the operator supplies access upstream of extortion rather than conducting it directly.

Late in the timeline, the operator deployed Sliver C2 against Ukrainian defence and aerospace targets, stealing source repositories and harvesting imagery from thousands of exposed IP cameras and RDP sessions. This tradecraft closely matches the AIVD/MIVD advisory on Russian state-linked camera surveillance used to locate Ukrainian military assets.  The US, Europe, and Korea were seen within the artefacts as secondary targets.

We assess with high confidence the operator is a Russian-speaking initial access broker. The Ukraine-focused activity is best explained as a criminal contractor selling access, including camera-derived intelligence to state buyers, consistent with the documented pattern of Russian intelligence services sourcing access from criminal operators rather than running it directly.

Key Findings

  • The exposed directory provided a timestamped, command level record of the operator's activity spanning mid-2025 into late 2026.
  • The operator conducted initial access brokerage against internet facing appliances and applications across more than a dozen countries spanning North America, Europe, and beyond, staging exploits for at least twelve CVEs, most public proof-of-concept and some modified.
  • Multiple organisations across government, managed services, and enterprise sectors had full device configurations, plaintext credentials, and cloud backup repositories exfiltrated or enumerated.
  • Late in the timeline the operator deployed Sliver C2 and conducted dedicated collection against Ukrainian defence and aerospace targets, including source code theft activity inconsistent with the commercial profile of the rest of the operation.
  • The operator experimented with AI-assisted offensive tooling in the final weeks of the recorded activity

The Open Directory

The directory's structure reflects the operator's working method. Exploit code is organised by CVE; target lists are partitioned by country; scan results are separated into vulnerable, not vulnerable, and unreachable sets, with the not vulnerable list retained for later revisiting. A checkpoint file recorded that scanning had processed a large volume of targets and was configured to continue, consistent with sustained, ongoing operation rather than a discrete campaign.

Following the Attacker's Keystrokes

Infrastructure Preparation

The operator verified external connectivity, prepared the environment, installed required tooling (Go, httpx), and downloaded country specific target lists before launching multiple campaigns simultaneously using GNU screen.

Mass Exploitation Campaigns

Multiple exploitation frameworks targeting Fortinet, SonicWall, Sophos, Citrix, SAP, Roundcube, and vBulletin were executed in parallel. The operator largely relied on public proof-of-concept exploits, modifying only a small subset for operational use.

Credential Harvesting

The operator ran a custom mass scanner against an F5 BIG ip target list and successfully managed to exploit and create admin credentials on many load balancers with identifiable hostnames concentrated in higher education and further victims across healthcare, financial services, and telecommunications. The final list was written in a good.log for the operator to review.

Initial Foothold and Internal Access

After identifying a successful compromise, the operator established access through a Neo-reGeorg web shell, created a SOCKS tunnel, and later authenticated to internal Windows hosts using stolen NTLM hashes via Evil-WinRM.

Active Directory Compromise

The operator extracted the domain DPAPI backup key, recovered browser and credential-store secrets, and dumped SAM and LSA secrets across the environment, ultimately obtaining full control of the Active Directory domain. A domain controller does not issue a decade long TGT; this is a forged ticket, confirming the operator obtained the domain's krbtgt secret and thereby full domain compromise, with indefinite re entry independent of credential resets

Data and Configuration Theft

Beyond credential collection, the operator accessed cloud backup repositories using stolen credentials and decrypted firewall configuration backups containing plaintext credentials, certificates, and private keys.

Ukrainian defence and aerospace collection

Late in the timeline, activity diverged from commercial access brokerage. The operator deployed Sliver C2 infrastructure and conducted targeted collection against Ukrainian defence and aerospace organisations, including theft of exposed Git repositories.

Exploitation Arsenal

Exploit code for at least a dozen distinct vulnerabilities was staged across the tree. Most are unmodified public proof-of-concept clones, several still carrying their original authors' metadata and credit lines. A small number were modified beyond upstream, and one FortiOS toolkit was rebuilt as an independent framework.

CVE Product Type State in Directory
CVE-2025-25257 Fortinet FortiWeb Unauth SQLi → RCE Modified expithink.py adds a hardcoded OOB DNS callback absent from the public PoC
CVE-2022-40684 Fortinet FortiOS / FortiProxy Auth bypass Rebuilt Modular framework (fortiv4/): SSH key injection, VPN user creation, admin backdoor.
CVE-2024-55591 Fortinet FortiOS WebSocket auth bypass watchTowr PoC (1pop.py) + custom admin creation payload
CVE-2023-46747 F5 BIG-IP TMUI Auth bypass → RCE Public PoC Russian-language mass-scanner (mass.py)
CVE-2025-5777 Citrix ADC / NetScaler OOB memory read Custom implementation
CVE-2023-44221 / CVE-2024-38475 SonicWall SMA Path traversal/ Session hijack Public exploit chain, multiple wrappers, Russian batch checker
CVE-2017-7921 HikVision cameras Hardcoded credential bypass Stock clone uses large-scale target list
CVE-2025-48703 CentOS Web Panel Unauth command injection Stock clone
CVE-2025-24071 Windows Explorer (.library-ms) NTLM hash leak on extraction Stock clone with a pre-built malicious exploit.zip staged for delivery
CVE-2025-31324 SAP NetWeaver Unauth file upload RCE Stock clone shipping a live command execution JSP web shell
vBulletin replaceAdTemplate vBulletin 5.x–6.x Template injection RCE Modified Russian-language mass scan wrapper (1exp.php)

Alongside these sat a stock copy of the public nuclei templates repository, more than 100 templates added to this specific instance including detectors for recently disclosed vulnerabilities and for stealer and C2 panels. This indicates the operator actively tracks new disclosures and incorporates them quickly.

The history also shows the operator deploying AI assisted tooling to automate reconnaissance and pentesting  including an autonomous pentest-agent framework and a browser automation server. The most recent addition being Kimi. It was heavily hyped shortly before this activity, and its use here shows an operator who follows current tooling closely and adopts it quickly.

Targeting and Victimology

The operator's filing system was organised by at least thirteen distinct two letter sets. The distribution is that of an access broker working through whatever is exposed, region by region, rather than a targeted campaign against one sector.

The target lists ran into the hundreds of thousands of hosts across the country partitioned sets. Against that volume, confirmed compromise represents a significant fraction, concentrated throughout many different sectors

Sector Compromised Assets
Higher education Multiple load-balancer appliances across several institutions
Government Full firewall device configuration exfiltrated and decrypted
Government (Tech Projects) Source repositories exfiltrated via exposed version control
Enterprise (multiple) Full Active Directory domain compromise
Managed services Offsite backup repository enumerated via stolen cloud credentials
Healthcare / Financial services / Telecommunications Individual load-balancer appliances compromised
IoT / Surveillance Multiple exposed IP cameras confirmed

Tooling

Function Tools
Mass scanning masscan, fscan, httpx, nuclei (+ local template additions)
Target acquisition Netlas API queries, assetfinder, IPGeoLocation, backupfinder
Vulnerability scanning nuclei-templates, plus a pirated commercial scanner
Exploitation Public PoCs for a dozen CVEs and many modified exploits
Web shells and tunnelling Neo-reGeorg, reGeorg, suo5, rpivot, gost, chisel, proxychains4
Operator infrastructure WireGuard, 3x-ui panel, gs-netcat, custom iptables DNAT scripts
Active Directory attack Impacket, NetExec, CrackMapExec, evil-winrm, powerview.py, pywsus
Credential access Responder (LLMNR/NBT-NS poisoning), dploot, donpapi, GhostKatz
Command and control Sliver (server and client)
Camera and RTSP access Ingram scanner, an RTSP screenshot utility
Remote-access brute force VNC mass-bruteforcer, an RDP/SSH scanner-bruter kit
Repository theft git-dumper, GitTools extractor
Data theft restic, elasticdump
Automation Autonomous pentest-agent framework, browser-automation server

Attribution

A Russian speaking operator

Every artifact the operator wrote themselves is in Russian tool documentation, scanner interfaces, batch-checker output, and campaign logs across multiple exploitation frameworks. Cyrillic fragments appear in the shell history where the keyboard layout also slipped mid command.

Activity timestamps cluster in the evening in Moscow time, and the operator's own WireGuard tunnel terminates on infrastructure consistent with that.

We assess a Russian speaking operator with high confidence.

An initial access broker

The recovered activity covers scanning, exploitation, credential capture, tunnelling and lateral movement, and stops there. No encryption, no extortion, no data-leak infrastructure. Access is taken to the point where it becomes sellable, and then left.

What happens to that access afterwards is visible in public ransomware reporting. Multiple organisations whose networks this operator held access to were later claimed as victims by ransomware groups and not by the same group each time. The following are some recent examples, but the artefacts contain several victim organizations that have not been named publicly yet.

Greater Pittsburgh Orthopaedic Associates (GPOA), a US healthcare provider, appears in the directory as one of the operator's confirmed domain compromises: administrative credentials harvested, DPAPI backup key extracted from the domain controller, credential stores dumped across the internal network. RansomHouse subsequently claimed the organisation on its leak site, alleging encryption of company data.

GPOA Ransomware incident Notification - CloudSEK GTI

MARTEC MARINE, an Italian firm supplying defence and integrated safety systems for navy ships, cruise liners and mega yachts damage control, fire detection and personnel tracking is the second. This is the domain where the operator forged a Kerberos golden ticket in January 2026, giving themselves authentication material valid for a decade. Tengu claimed the company on its leak site the following month.

Martec Marine Ransomware incident Notification - CloudSEK GTI

Two features of this pattern matter more than either individual case.

  • The first is timing. In each instance the ransomware claim follows the operator's access by a matter of weeks, not days or years. That interval is consistent with the documented lag between initial compromise and extortion in ransomware operations, and it places this operator upstream of the extortion rather than participating in it. The access is established, held, and then appears to change hands.
  • The second is that the claiming groups differ. An affiliate working with multiple ransomware groups and their victims surface under that group’s name.

“Several further instances of the same pattern were identified across the victim set, following the same sequence: access established and recorded in the directory, then a ransomware claim against the same organisation weeks later, attributed to a different group each time.”

Connections to state espionage

Alongside the brokerage, the operator ran a sustained collection effort against Ukraine that follows a well documented Russian pattern: identify defence and critical infrastructure organisations, take whatever is reachable from the internet, and hold the access.

The targeting is specific and it is significant. The operator enumerated many national defence sector attack surfaces, cataloguing thousands of government, education, media and commercial domains. Organisations across the country's defence industrial base, energy generation, telecommunications and broadcast sectors appear in the recovered target and results data.

Russian services have been targeting exactly this set of organisations since the start of the war, using exactly these methods: internet-facing exposure, credential reuse, source code theft from suppliers, and long term quiet access rather than immediate disruption. The activity here sits squarely inside that pattern.

It also extends into physical space. Among the recovered artefacts are images: hundreds of frames captured from internet facing IP cameras across Ukraine, taken from facilities in the sectors above, together with hundreds of screenshots lifted from exposed remote desktop services. The operator was not only inside networks but watching sites and operator consoles directly.

In July 2026 the Dutch intelligence services, AIVD and MIVD, published a joint advisory on precisely this activity. Russian state actors, they assess, are systematically compromising internet-facing IP cameras across EU and NATO member states and Ukraine, exploiting default credentials and outdated firmware, and running image recognition over the results to identify military vehicles and the cargo they carry. In Ukraine, the advisory states, the imagery is used to help locate Ukrainian military personnel and materiel and to target them.

We assess with moderate-to-high confidence that this is state-nexus intelligence collection, conducted on the same infrastructure and by the same hands as the brokerage. The tradecraft aligns with an operation Western intelligence services attribute to Russian state actors. 

Which service benefits is a separate question, and one we leave open. The Dutch services, working from considerably better visibility than a single exposed directory affords, attribute the camera campaign to "at least one Russian intelligence and security service" without naming it. We apply the same standard.

Assessment

The two strands run on shared infrastructure, the same VPS, command-and-control server, tunnels and toolkit against two distinct target sets. Commercially, the operator exploits exposed appliances at volume and sells the resulting network access to ransomware operations. Separately, they collect against Ukrainian defence and critical infrastructure.

Whether that second strand reflects direct tasking, contracted work, or collection sold on to a state customer cannot be determined from this directory, and the documented overlap between Russian criminal and state cyber activity makes each plausible. What the evidence supports is a criminal access broker whose secondary activity also serves state intelligence requirements.

Mitigations:

  1. Remove management interfaces for Fortinet, F5, Citrix, SonicWall and SAP appliances from direct internet exposure, patch the vulnerabilities listed above, and audit development, staging and disaster-recovery devices to the same standard as production.
  2. Rotate all appliance administrative credentials along with any LDAP, RADIUS or service-account credentials stored in device configurations, and treat an exfiltrated configuration as full disclosure of the network behind the device.
  3. Where domain compromise is suspected, rotate the krbtgt account password twice with a full replication interval between resets, disable RC4-HMAC in favour of AES, and alert on any Kerberos ticket whose lifetime exceeds domain policy.
  4. Disable LLMNR and NBT-NS, enable SMB signing and Extended Protection for Authentication, restrict WinRM to designated administrative hosts, and deploy a vulnerable driver blocklist.
  5. Change default credentials on every IP camera, keep firmware current, place cameras on an isolated VLAN with no direct internet exposure, and restrict their fields of view so that personnel movement, logistics areas and sensitive infrastructure stay out of frame.
  6. Treat devices with unfamiliar successful administrative logins as compromised audit for backdoor accounts, injected SSH keys and altered configuration, and alert on appliance-originated connections to internal hosts.

References

Nenhum item encontrado.

Blogs relacionados