Adversary Intelligence — 2026-08-05

Exposed Server Reveals Russian Access Broker Running Dual Ransomware and Intelligence Collection Operation Against Ukrainian Defense Targets

BLUFRussian criminal access brokers now function as a sourcing layer for state intelligence requirements, collapsing the operational boundary between ransomware resale and espionage targeting of Ukrainian defense networks.

CloudSEK researchers reported recovering an exposed server belonging to a Russian-speaking initial access broker, containing months of activity spanning mid-2025 into late 2026 1. The directory showed the operator exploiting internet-facing appliances from Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin and Hikvision across more than a dozen countries, harvesting credentials and achieving full Active Directory compromise at education, healthcare, finance, telecommunications and government victims 12. At one victim the operator forged a Kerberos golden ticket using a stolen krbtgt secret, enabling indefinite domain re-entry independent of credential resets 1. CloudSEK identified two organizations, Greater Pittsburgh Orthopaedic Associates and Italy's Martec Marine, where ransomware groups RansomHouse and Tengu claimed victims within weeks of the operator's recorded access 1. Late in the recorded timeline the operator deployed Sliver C2 against Ukrainian defense and aerospace targets, stealing source-code repositories and collecting imagery from thousands of exposed IP cameras and RDP sessions, tradecraft CloudSEK said resembles a July advisory from the Dutch AIVD and MIVD on Russian state-linked camera surveillance used to locate Ukrainian military assets 12.

Analysis
CloudSEK's find, resting on a single investigation with only secondary pickup, links one financially motivated access broker to both ransomware resale and Russian state-aligned intelligence collection against Ukrainian defense and aerospace networks, indicating criminal and state cyber activity increasingly share infrastructure and personnel rather than operate in separate lanes. The shift from broad commercial scanning to targeted Sliver C2 deployment, source-code theft, and camera-derived imagery collection suggests the broker's access pipeline functions as a sourcing channel for state intelligence requirements, tradecraft mirroring what Dutch AIVD and MIVD attributed to Russian services in their July advisory. The Ukraine-focused collection could instead reflect direct state tasking rather than a contractor's opportunistic resale to a buyer. Defenders across the named sectors face continued exploitation risk regardless of which victims prove to be state targets, since the broker treats espionage and resale as parallel outputs of one operation.
3 sources
  1. Access For Sale: Inside a Russian-Speaking Access Broker's Dual Operation - CloudSEK
  2. Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites - Cyber Security News
  3. Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine - GBHackers

View in full brief →

UNCLASSIFIED // OPEN SOURCE