Active High impact Ransomware Checked 11h ago

Russian broker sells stolen access, spies on Ukraine

CloudSEK said the Russian-speaking operator continued scanning exposed systems, stealing credentials, selling network access to multiple ransomware groups, and collecting from Ukrainian defense and aerospace targets. Organizations later named in the research included Greater Pittsburgh Orthopaedic Associates in the United States and MARTEC MARINE in Italy.

Started
Aug 3, 2026
Latest activity
Sep 9, 2026
Attributed to
Russian-speaking access broker (state-linked)Likely
Where
Worldwide, Ukraine, United States
Sectors
Government, Healthcare, Finance, Education, Telecom, Defence +2
Scale
Hundreds of thousands of internet-facing systems scanned worldwide

Current status

No credible incident-specific report or official statement dated after 2026-09-09 was found as of 2026-09-11.

Active: Confirmed and still going. Attacker activity or disruption is continuing.

Who is behind it

CloudSEK assesses the operator as a Russian-speaking access broker and says the Ukrainian collection had a likely state nexus, but names no specific Russian service.

Impact

The broker compromised exposed network appliances and, in some cases, entire Active Directory domains before selling access. CloudSEK linked several held networks to later ransomware claims by different groups. It also reported source-code theft and camera surveillance involving Ukrainian defense-related targets.

What to do

Patch and remove management interfaces from the internet. Rotate appliance, domain and service-account credentials. Check for unfamiliar admin accounts, SSH keys, web shells, forged login tickets and unusual internal connections. Change default camera passwords, update firmware and isolate cameras from the internet.

Timeline

  1. Sep 9, 2026

    CloudSEK publicly linked to its investigation and said the operator's held access later appeared in ransomware leak-site claims by several different groups. It also described the scanning setup as configured to continue.

    Activelinkedin.com
  2. Aug 25, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  3. Aug 4, 2026

    GBHackers detailed CloudSEK research showing the same operator used Sliver C2 and compromised IP cameras to spy on Ukrainian defense and aerospace organizations, alongside selling access to ransomware gangs.

    Activegbhackers.com
  4. Aug 3, 2026

    Cyber Security News reported a Russian-speaking hacker linked to a broad access-sale operation breaching organizations across education, healthcare, finance, telecom and government worldwide.

    Activecybersecuritynews.com

Sources

Related reports