Russian hacker steals company access and sells it
A Russian-speaking hacker broke into companies worldwide, stole passwords and network access, then sold that access to ransomware gangs. Researchers at CloudSEK also found the same operator spying on Ukrainian defence and aerospace organizations, including hacked security cameras and remote desktop screens.
- Report priority
- High
- Involves
- Fortinet
What is known
The operator scanned the internet for security appliances and public-facing applications from vendors like Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, and Hikvision, then used mostly public proof-of-concept exploit code to break into whichever ones had known unpatched flaws.
What to do
Organizations should review whether any Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, or Hikvision systems are reachable directly from the internet and whether they are fully patched.
Take internet-facing security appliances and admin panels off direct public access where possible, apply all outstanding vendor security patches for the products named above, and watch for unexplained password resets, new web shells, or unusual Kerberos ticket activity, since CloudSEK's report is the source advisory to follow for updates.
Reported details
CloudSEK finds a server left open on the internet that the operator used to store logs of the operation. The files show the attacker scanning networks in more than a dozen countries for exposed security appliances and public applications, then firing off exploit code built from public proof-of-concept releases. After breaking in, the attacker plants a web shell to keep a foothold, tunnels through to internal Windows systems, steals password hashes, and in some cases forges Kerberos tickets to take over the whole company identity system.
CloudSEK attributes the activity to a single Russian-speaking operator functioning as a high-volume initial access broker rather than a ransomware operator running encryption itself. The operator staged exploits, mostly adapted public PoC code, for at least 12 vulnerabilities in Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, and Hikvision products, then pivoted from web shells and tunnels into Windows environments to dump NTLM hashes, SAM data, and browser-stored credentials, in confirmed cases extracting the krbtgt key for full Active Directory compromise via forged Kerberos tickets. The same infrastructure later ran Sliver C2 against Ukrainian defence and aerospace targets, pulling data from exposed source-code repositories and images from internet-facing IP cameras and RDP sessions.
References
- ppl-ai-file-upload.s3.amazonaws.com · Russian-Hacker-Breaches-Companies-Sells-Their-Access-and-Spies-on-Ukrainian-Military-Sites.pdf Cyber Security News
- cloudsek.com · access-for-sale-inside-a-russian-speaking-access-brokers-dual-operation Cyber Security News
- any.run · enterprise Cyber Security News
- bleepingcomputer.com · hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts BleepingComputer
- infosecurity-magazine.com · aitm-phishing-top-entry-point-law Infosecurity Magazine
- neuracybintel.com · sonicwall-sma1000-zero-days-fuel-inc-ransomware-attacks-against-enterprise-vpn-infrastructure NeuraCybIntel
- securityweek.com · sonicwall-issues-urgent-sma-patch-warning-for-two-zero-day-exploits NeuraCybIntel
- securityweek.com · sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch NeuraCybIntel
- sonicwall.com · kA1VN000001nv6D0AQ NeuraCybIntel
- neuracybintel.com · critical-fastjson-rce-zero-day-under-active-exploitation-unauthenticated-attacks-hit-us-organizations NeuraCybIntel
- securityweek.com · river-bank-says-hackers-deleted-data-stolen-in-ransomware-attack SecurityWeek
- securityweek.com · brinks-home-discloses-data-breach-as-hackers-leak-files SecurityWeek
- securityweek.com · recent-sonicwall-vulnerabilities-exploited-in-ransomware-attacks SecurityWeek
- openwall.com · 2 Openwall oss-security
- openwall.com · 6 Openwall oss-security
- safedep.io · keyv-npm-supply-chain-compromise SafeDep