Access For Sale: Inside a Russian-Speaking Access Broker’s Dual Operation

Access For Sale: Inside a Russian-Speaking Access Broker’s Dual Operation
An exposed server tied to a Russia-nexus operator exposed months of activity showing high-volume initial access brokerage, broad exploitation of appliances, credential theft, and full Active Directory compromise across many sectors worldwide. The same operator later used Sliver C2 for targeted collection against Ukrainian defence and aerospace organisations, including theft from Git repositories and imagery from thousands of exposed IP cameras, with the activity aligning to AIVD/MIVD warnings about Russian camera surveillance. #Sliver #AIVD #MIVD #Fortinet #F5 #Citrix #SonicWall #SAP #HikVision #Neo-reGeorg

Keypoints

  • The exposed directory contained a timestamped record of activity from mid-2025 into late 2026, indicating sustained operations rather than a short campaign.
  • The operator exploited internet-facing appliances and applications in more than a dozen countries, using staged exploits for at least twelve CVEs.
  • Victims included education, healthcare, finance, telecommunications, government, managed services, enterprise, and IoT/surveillance environments.
  • The operator harvested credentials, dumped SAM and LSA secrets, extracted DPAPI backup keys, and achieved full Active Directory compromise in multiple cases.
  • Several organizations later appeared in ransomware leak claims weeks after the access was recorded, supporting the conclusion that the operator sold access upstream of extortion.
  • Late-stage activity shifted to Ukraine-focused intelligence collection using Sliver C2, including source repository theft and imagery collection from IP cameras and RDP sessions.
  • The operator also experimented with AI-assisted offensive tooling and tracked new vulnerabilities quickly through added nuclei templates and modified exploit code.

MITRE Techniques

  • [T1190 ] Exploit Public-Facing Application – The operator gained access by exploiting internet-facing appliances and applications with public and modified PoCs (‘exploited internet-facing appliances’ / ‘public proof-of-concept exploits’).
  • [T1059 ] Command and Scripting Interpreter – Multiple exploit and automation scripts were executed to manage scanning, exploitation, and campaigns (‘mass.py’, ‘1pop.py’, ‘expithink.py’, and other scripts’).
  • [T1595 ] Active Scanning – Large-scale target discovery and vulnerability checking were performed across hundreds of thousands of hosts (‘mass scanning’, ‘httpx’, ‘fscan’, ‘nuclei’).
  • [T1003 ] OS Credential Dumping – The operator dumped SAM and LSA secrets and extracted browser and credential-store secrets (‘dumped SAM and LSA secrets across the environment’).
  • [T1555 ] Credentials from Password Stores – Browser and credential-store secrets were recovered after domain compromise (‘recovered browser and credential-store secrets’).
  • [T1005 ] Data from Local System – The operator exfiltrated device configs, repositories, and files from compromised systems (‘full device configurations’, ‘source code theft’, ‘decrypted firewall configuration backups’).
  • [T1021.001 ] Remote Services: Remote Desktop Protocol – Stolen access was used to authenticate to internal Windows hosts and collect RDP session imagery (‘RDP sessions’, ‘authenticated to internal Windows hosts’).
  • [T1021.004 ] Remote Services: SSH – Internal access and tooling included SSH-based interaction and key injection into appliances (‘SSH key injection’, ‘existing SSH access’).
  • [T1090.001 ] Proxy: Internal Proxy – The operator used tunneling and SOCKS relays to reach internal assets (‘created a SOCKS tunnel’, ‘Neo-reGeorg web shell’).
  • [T1105 ] Ingress Tool Transfer – Tools, exploit kits, and malicious archives were downloaded and staged for later use (‘downloaded country specific target lists’, ‘exploit.zip staged for delivery’).
  • [T1566 ] Phishing – The article does not describe email phishing; not included.
  • [T1552.001 ] Unsecured Credentials: Credentials In Files – Plaintext credentials were found in device configurations and backups (‘plaintext credentials, certificates, and private keys’).
  • [T1078 ] Valid Accounts – Stolen NTLM hashes and harvested credentials were used for internal authentication (‘authenticated to internal Windows hosts using stolen NTLM hashes’).
  • [T1550.002 ] Use Alternate Authentication Material: Pass the Hash – NTLM hashes were used to authenticate without passwords (‘using stolen NTLM hashes via Evil-WinRM’).
  • [T1204 ] User Execution – The malicious Windows Explorer library-ms exploit was staged for delivery, implying user-triggered execution for hash leakage (‘malicious exploit.zip staged for delivery’).
  • [T1486 ] Data Encrypted for Impact – Not directly used by the operator; ransomware activity is attributed to downstream groups, not this actor.
  • [T1110 ] Brute Force – Remote-access brute forcing was part of the tooling inventory (‘VNC mass-bruteforcer’, ‘RDP/SSH scanner-bruter kit’).
  • [T1210 ] Exploitation of Remote Services – The operator exploited appliance login and service weaknesses across exposed systems (‘auth bypass’, ‘session hijack’, ‘command injection’).

Indicators of Compromise

  • [Tools / filenames ] Exploit and operator scripts staged in the directory – expithink.py, 1pop.py, mass.py, fortiv4/, exploit.zip, good.log, 1exp.php
  • [Tools / infrastructure ] Post-exploitation and tunneling tools used across the operation – Neo-ReGeorg, Sliver, WireGuard, chisel, gost, rpivot, proxychains4
  • [Vulnerabilities / CVEs ] Exploits staged for active use – CVE-2025-25257, CVE-2022-40684, CVE-2024-55591, and 9 more CVEs
  • [Targeting artifacts ] Country-partitioned target lists and scanning outputs – country-specific lists, vulnerable/not vulnerable/unreachable sets, checkpoint file
  • [Malicious web shells / payloads ] Web shells and payload delivery items – JSP web shell, Neo-reGeorg shell, malicious exploit.zip
  • [Command and control ] C2 framework and related infrastructure artifacts – Sliver server/client, 3x-ui panel, gs-netcat
  • [Recon / scanning utilities ] Discovery and vulnerability assessment tooling found in the directory – masscan, fscan, httpx, nuclei, Netlas API queries
  • [Camera / surveillance artifacts ] Collection against exposed cameras and remote desktops – RTSP screenshot utility, Ingram scanner, screenshots from IP cameras and RDP sessions


Read more: https://www.cloudsek.com/blog/access-for-sale-inside-a-russian-speaking-access-brokers-dual-operation