An exposed server tied to a Russia-nexus operator exposed months of activity showing high-volume initial access brokerage, broad exploitation of appliances, credential theft, and full Active Directory compromise across many sectors worldwide. The same operator later used Sliver C2 for targeted collection against Ukrainian defence and aerospace organisations, including theft from Git repositories and imagery from thousands of exposed IP cameras, with the activity aligning to AIVD/MIVD warnings about Russian camera surveillance. #Sliver #AIVD #MIVD #Fortinet #F5 #Citrix #SonicWall #SAP #HikVision #Neo-reGeorg
Keypoints
- The exposed directory contained a timestamped record of activity from mid-2025 into late 2026, indicating sustained operations rather than a short campaign.
- The operator exploited internet-facing appliances and applications in more than a dozen countries, using staged exploits for at least twelve CVEs.
- Victims included education, healthcare, finance, telecommunications, government, managed services, enterprise, and IoT/surveillance environments.
- The operator harvested credentials, dumped SAM and LSA secrets, extracted DPAPI backup keys, and achieved full Active Directory compromise in multiple cases.
- Several organizations later appeared in ransomware leak claims weeks after the access was recorded, supporting the conclusion that the operator sold access upstream of extortion.
- Late-stage activity shifted to Ukraine-focused intelligence collection using Sliver C2, including source repository theft and imagery collection from IP cameras and RDP sessions.
- The operator also experimented with AI-assisted offensive tooling and tracked new vulnerabilities quickly through added nuclei templates and modified exploit code.
MITRE Techniques
- [T1190 ] Exploit Public-Facing Application â The operator gained access by exploiting internet-facing appliances and applications with public and modified PoCs (âexploited internet-facing appliancesâ / âpublic proof-of-concept exploitsâ).
- [T1059 ] Command and Scripting Interpreter â Multiple exploit and automation scripts were executed to manage scanning, exploitation, and campaigns (âmass.pyâ, â1pop.pyâ, âexpithink.pyâ, and other scriptsâ).
- [T1595 ] Active Scanning â Large-scale target discovery and vulnerability checking were performed across hundreds of thousands of hosts (âmass scanningâ, âhttpxâ, âfscanâ, ânucleiâ).
- [T1003 ] OS Credential Dumping â The operator dumped SAM and LSA secrets and extracted browser and credential-store secrets (âdumped SAM and LSA secrets across the environmentâ).
- [T1555 ] Credentials from Password Stores â Browser and credential-store secrets were recovered after domain compromise (ârecovered browser and credential-store secretsâ).
- [T1005 ] Data from Local System â The operator exfiltrated device configs, repositories, and files from compromised systems (âfull device configurationsâ, âsource code theftâ, âdecrypted firewall configuration backupsâ).
- [T1021.001 ] Remote Services: Remote Desktop Protocol â Stolen access was used to authenticate to internal Windows hosts and collect RDP session imagery (âRDP sessionsâ, âauthenticated to internal Windows hostsâ).
- [T1021.004 ] Remote Services: SSH â Internal access and tooling included SSH-based interaction and key injection into appliances (âSSH key injectionâ, âexisting SSH accessâ).
- [T1090.001 ] Proxy: Internal Proxy â The operator used tunneling and SOCKS relays to reach internal assets (âcreated a SOCKS tunnelâ, âNeo-reGeorg web shellâ).
- [T1105 ] Ingress Tool Transfer â Tools, exploit kits, and malicious archives were downloaded and staged for later use (âdownloaded country specific target listsâ, âexploit.zip staged for deliveryâ).
- [T1566 ] Phishing â The article does not describe email phishing; not included.
- [T1552.001 ] Unsecured Credentials: Credentials In Files â Plaintext credentials were found in device configurations and backups (âplaintext credentials, certificates, and private keysâ).
- [T1078 ] Valid Accounts â Stolen NTLM hashes and harvested credentials were used for internal authentication (âauthenticated to internal Windows hosts using stolen NTLM hashesâ).
- [T1550.002 ] Use Alternate Authentication Material: Pass the Hash â NTLM hashes were used to authenticate without passwords (âusing stolen NTLM hashes via Evil-WinRMâ).
- [T1204 ] User Execution â The malicious Windows Explorer library-ms exploit was staged for delivery, implying user-triggered execution for hash leakage (âmalicious exploit.zip staged for deliveryâ).
- [T1486 ] Data Encrypted for Impact â Not directly used by the operator; ransomware activity is attributed to downstream groups, not this actor.
- [T1110 ] Brute Force â Remote-access brute forcing was part of the tooling inventory (âVNC mass-bruteforcerâ, âRDP/SSH scanner-bruter kitâ).
- [T1210 ] Exploitation of Remote Services â The operator exploited appliance login and service weaknesses across exposed systems (âauth bypassâ, âsession hijackâ, âcommand injectionâ).
Indicators of Compromise
- [Tools / filenames ] Exploit and operator scripts staged in the directory â expithink.py, 1pop.py, mass.py, fortiv4/, exploit.zip, good.log, 1exp.php
- [Tools / infrastructure ] Post-exploitation and tunneling tools used across the operation â Neo-ReGeorg, Sliver, WireGuard, chisel, gost, rpivot, proxychains4
- [Vulnerabilities / CVEs ] Exploits staged for active use â CVE-2025-25257, CVE-2022-40684, CVE-2024-55591, and 9 more CVEs
- [Targeting artifacts ] Country-partitioned target lists and scanning outputs â country-specific lists, vulnerable/not vulnerable/unreachable sets, checkpoint file
- [Malicious web shells / payloads ] Web shells and payload delivery items â JSP web shell, Neo-reGeorg shell, malicious exploit.zip
- [Command and control ] C2 framework and related infrastructure artifacts â Sliver server/client, 3x-ui panel, gs-netcat
- [Recon / scanning utilities ] Discovery and vulnerability assessment tooling found in the directory â masscan, fscan, httpx, nuclei, Netlas API queries
- [Camera / surveillance artifacts ] Collection against exposed cameras and remote desktops â RTSP screenshot utility, Ingram scanner, screenshots from IP cameras and RDP sessions