Initial access brokers advertised and sold access to dozens of organizations through Zoho ManageEngine Desktop Central, turning a legitimate remote monitoring and management platform into a high-value entry point for ransomware operations. KELA tracked 53 access listings between July and September 2020 with a combined asking price of $153,850, and said at least 10 had already been sold. Victims spanned multiple countries and sectors, including government organizations, while some of the highest-priced listings were tied to companies in Turkey and Canada. Researchers assessed that the compromises were more likely caused by direct attacks against exposed Desktop Central instances and the use of valid credentials than by a single managed service provider breach.
The sales fit a broader underground market in which brokers monetized enterprise footholds for follow-on attacks, including ransomware deployment. KELA later counted 242 network access listings worth about $1.21 million in Q4 2020, with common offerings including RDP, VPN, Citrix, RCE, and increasingly RMM-based access. The appeal of Desktop Central was its ability to provide remote control and script execution across many endpoints, enabling rapid domain-wide compromise; a separate DFIR case involving NetWalker showed how quickly ransomware operators could move from initial access to full encryption. Zoho said weak credentials were the likely cause in the investigated Desktop Central cases and moved to block future logins using weak passwords.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On December 4, 2020, the LockBit ransomware blog claimed to have compromised Mexico's National Insurance and Surety Commission and demanded a $1 million ransom. KELA assessed the previously advertised access may have been sold to LockBit or handled by a LockBit affiliate.
In late November 2020, a threat actor advertised access to Mexico's National Insurance and Surety Commission with a starting auction price of $70,000 and a buy-now price of $100,000. KELA assessed the access could have been intended for ransomware use.
In September 2020, KELA observed the broker advertising 36 additional accesses via Zoho ManageEngine Desktop Central on a Russian-speaking underground forum. KELA assessed the actor offered 53 accesses across July and September 2020 with a combined asking value of $153,850, and at least 10 had already been sold.
KELA said the same initial access broker offered about a dozen unauthorized accesses tied to Zoho ManageEngine Desktop Central in July 2020. These listings were part of a broader campaign selling access to organizations across multiple countries and sectors.
The content notes that CVE-2020-10189 in ManageEngine Desktop Central was reported as exploited in March 2020 to install malware. This is cited as prior abuse of the product, though KELA assessed the later access-sales activity was likely unrelated.
After KELA shared victim information with Zoho, Zoho's information security team investigated and concluded that weak credentials used on ManageEngine products were the likely cause of the compromises under review. KELA's later Q4 report cited this conclusion in connection with the actor 'pshmm.'
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.