Russian access broker's server exposes Ukraine spying

A Russian-speaking hacker who sells corporate network access left his own server open to the internet, and researchers have spent months of his command history reading it. What they found is a working record of how organisations end up on a ransomware leak site, and a second operation, run from the same machine, aimed at Ukraine's defence industry.

CloudSEK's researchers published the investigation on August 3, 2026. The exposed directory held a timestamped, command-level record of activity running from mid-2025 into late 2026, complete with exploit code, target lists partitioned by country, and scan results sorted into vulnerable, not vulnerable and unreachable.

An industrial-scale door opener

The operator is what the industry calls an initial access broker: someone who breaks in, takes the access as far as it is worth taking, and then sells it to whoever wants to do the extortion. CloudSEK found no encryption, no ransom notes and no leak site of his own. Everything stops at the point where access becomes sellable.

Getting there was a volume business. Target lists ran into the hundreds of thousands of hosts across at least thirteen country sets, and exploit code for at least a dozen vulnerabilities sat staged on the server, most of it public proof-of-concept code cloned unmodified and still carrying its original authors' credit lines. The staged flaws hit Fortinet FortiOS, FortiProxy and FortiWeb, F5 BIG-IP, Citrix NetScaler, SonicWall SMA, SAP NetWeaver, HikVision cameras, CentOS Web Panel, Windows Explorer and vBulletin. A few had been reworked for operational use, including a FortiOS toolkit rebuilt into a framework that injects SSH keys, creates VPN users and plants an admin backdoor.

A custom mass scanner aimed at F5 BIG-IP load balancers created administrator accounts on many of them, with hostnames concentrated in higher education and further hits across healthcare, financial services and telecommunications. From a successful hit the operator deployed a Neo-reGeorg web shell, tunnelled in over SOCKS, and authenticated to internal Windows machines with stolen NTLM hashes, the password equivalents Windows passes around during authentication. Inside, the pattern was consistent: extract the domain's DPAPI backup key, dump credential stores, take the domain.

The handoff to ransomware

CloudSEK's strongest evidence for what happens to that access is the timing. Organisations recorded in the directory were claimed on ransomware leak sites weeks afterwards, and not by the same crew each time.

Greater Pittsburgh Orthopaedic Associates, a US healthcare provider, appears in the directory as a confirmed domain compromise before RansomHouse claimed it. Martec Marine, an Italian supplier of damage control, fire detection and personnel tracking systems for navy ships and cruise liners, is the domain where the operator forged a Kerberos golden ticket in January 2026, giving himself authentication material valid for a decade; the Tengu crew claimed the company the following month. Leak-site postings are unverified claims made by the attackers, but the sequence in the directory is the operator's own log. IntelFusions has reported the same broker-to-ransomware handoff before.

The part that is not about money

Late in the timeline the activity changes character. The operator stood up Sliver command-and-control infrastructure and collected against Ukrainian defence and aerospace organisations, stealing exposed Git repositories and cataloguing thousands of domains across Ukraine's defence industrial base, energy generation, telecommunications and broadcast sectors.

It went beyond networks. The recovered files include hundreds of frames grabbed from internet-facing IP cameras across Ukraine and hundreds of screenshots taken from exposed remote desktop sessions. In July 2026 the Dutch intelligence services AIVD and MIVD published a joint advisory describing exactly this: Russian state actors compromising internet-facing cameras across EU and NATO states and Ukraine, and running image recognition over the results to identify military vehicles and their cargo.

CloudSEK assesses with high confidence that the operator is a Russian speaker, based on Russian-language tooling and logs, Cyrillic fragments where the keyboard layout slipped mid-command, and activity clustering in the Moscow evening. It assesses with moderate-to-high confidence that the Ukraine strand is state-nexus intelligence collection run on the same infrastructure and by the same hands as the brokerage. Which service benefits, the researchers leave open, as the Dutch advisory did.

What you should do

Take management interfaces for Fortinet, F5, Citrix, SonicWall and SAP appliances off the public internet and patch them, and hold development, staging and disaster-recovery devices to the production standard. Treat an exfiltrated device configuration as full disclosure of the network behind it and rotate every credential it held, including LDAP, RADIUS and service accounts. Where domain compromise is suspected, rotate the krbtgt password twice with a full replication interval between resets and alert on any Kerberos ticket whose lifetime exceeds domain policy. Change default credentials on IP cameras, keep their firmware current, put them on an isolated VLAN, and check what is in frame.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions