Russian Hacker Breaches Fortinet and Other Companies, Sells Access and Spies on Ukrainian Military Sites
内容摘要
A Russian-speaking threat actor has been identified as the orchestrator of a large-scale cyber operation targeting organizations worldwide, acting as an initial access broker (IAB) for ransomware groups. The campaign, uncovered by CloudSEK researchers, exploited exposed security appliances and unpatched vulnerabilities to breach networks across education, healthcare, financial services, telecommunications, and government sectors in over a dozen countries. The hacker conducted large-scale scans to identify vulnerable internet-facing systems, leveraging 12 known exploits in products from Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, and Hikvision. Most exploits relied on public proof-of-concept code, though some were modified for the operation. Once inside a network, the attacker deployed web shells and network tunnels to move laterally, harvested NTLM password hashes, credential stores, and browser secrets, compromised Active Directory extracting Kerberos ticket-granting keys to forge long-term authentication tokens, and in some cases achieved full domain control enabling ransomware groups to later encrypt systems. While the initial focus was financial cybercrime, the operation later pivoted to targeting Ukrainian defense and aerospace organizations. The hacker deployed Sliver command-and-control tooling, accessed exposed source-code repositories, and collected hundreds of images from internet-facing IP cameras and screenshots from remote desktop sessions, likely to monitor military logistics, border crossings, and critical infrastructure.
觉得这篇分析有用?
每周收到3-5条AI基础设施关键信号 →
💬 评论 (0)