Russian-Speaking Access Broker Engages in Dual Operations Targeting Global Sectors
A Russian-speaking initial access broker has been identified exploiting vulnerabilities across multiple countries, targeting sectors such as healthcare, finance, and government. Their operations reveal a pattern of selling compromised access to ransomware groups, particularly coinciding with subsequent ransomware attacks on the same organizations.

The identified operator has targeted internet-facing appliances across over a dozen countries, exploiting more than twelve CVEs for initial access. Their activities have resulted in credential harvesting, full Active Directory compromises, and the extraction of sensitive data from various sectors, including healthcare and finance.
Notably, the operator deployed Sliver C2 infrastructure against Ukrainian defense and aerospace entities, stealing source code and imagery from IP cameras. This operation aligns with patterns observed in Russian intelligence, indicating a dual role as a criminal contractor and state-nexus intelligence collector.
The timing of ransomware claims following access indicates that the broker sells this access upstream rather than executing extortion directly, as evidenced by multiple ransomware groups claiming victims shortly after initial compromises. This trend poses significant risks for organizations in targeted sectors, potentially leading to increased ransomware incidents.




Comments