CloudSEK reported that an exposed server uncovered a Russian-speaking initial access broker running a large-scale intrusion operation against internet-facing appliances and public applications across more than a dozen countries. From mid-2025 into late 2026, the actor used public and modified proof-of-concept exploits to compromise organizations in education, healthcare, finance, telecommunications, government, managed services, and other enterprise sectors, then deployed web shells and tunnels, stole credentials, exfiltrated device configurations and cloud backups, and in some cases achieved full Active Directory compromise by obtaining material needed to forge Kerberos tickets.
The investigation found that several victims were later claimed by different ransomware groups within weeks, indicating the actor likely sold network access rather than conducting extortion directly. CloudSEK also said the same infrastructure was later used for targeted collection against Ukrainian defence and aerospace entities, including theft from exposed source-code repositories, use of Sliver C2, and collection of imagery and activity from exposed IP cameras and RDP sessions, suggesting an overlap between criminal access brokerage and activity aligned with Russian state-linked intelligence requirements.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
CloudSEK linked the camera-surveillance tradecraft in the Ukraine-focused activity to a July 2026 advisory from AIVD and MIVD about Russian state actors compromising IP cameras to identify military vehicles and cargo. This advisory served as an external reference point for the observed collection behavior.
The report states that ransomware group Tengu claimed MARTEC MARINE on its leak site the month after the operator's access. This was presented as evidence that the actor likely sold access to downstream extortion actors.
Late in the timeline, the same infrastructure was used for targeted collection against Ukrainian defence and aerospace organizations, including Sliver C2 deployment, theft of exposed Git repositories and source code, and collection of imagery from internet-facing IP cameras and exposed RDP sessions. CloudSEK assessed this phase with moderate-to-high confidence as aligned with state-linked intelligence requirements.
CloudSEK identified MARTEC MARINE as a victim where the operator forged a Kerberos golden ticket, confirming theft of krbtgt material and full domain compromise. The report explicitly anchors this event to January 2026.
CloudSEK reported that an exposed server contained timestamped, command-level records showing a Russian-speaking initial access broker conducting large-scale exploitation campaigns across multiple countries. The activity was explicitly described as spanning from mid-2025 into late 2026.
CloudSEK published findings on an exposed server that revealed a Russian-speaking initial access broker's broad intrusion activity and later Ukraine-focused espionage collection. The report assessed that the actor primarily sold access to ransomware operators while also supporting intelligence-oriented collection on the same infrastructure.
CloudSEK reported that Greater Pittsburgh Orthopaedic Associates appeared in the exposed directory as a confirmed domain compromise involving harvested administrative credentials, DPAPI backup keys, and dumped credential stores, and that RansomHouse later claimed the organization on its leak site. No explicit date was provided for either the compromise or the later claim.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.