Russian Hacker Sells Access After Global Company Breaches

Russian-speaking actor sells corporate access after breaching global organisations

A recent report has revealed that a Russian hacker has breached companies worldwide, selling access to their systems and spying on Ukrainian military sites. This campaign highlights the ongoing threat posed by access brokers targeting organisations with internet-facing infrastructure.

How the Russian Hacker Operation Unfolded

In early 2024, CloudSEK researchers uncovered a wide-reaching campaign led by a Russian-speaking threat actor. The hacker targeted organisations across sectors including education, healthcare, financial services, telecommunications, and government. The attack focused on entities with exposed internet-facing systems or public applications.

The operator’s approach was systematic. First, they scanned for unprotected security appliances and web applications accessible from the internet. Using known software vulnerabilities, the hacker gained initial access. Once inside a network, the attacker escalated privileges and harvested credentials, including passwords and identity data. In multiple cases, they achieved full control over company identity management systems, making it possible to impersonate users or further pivot within the network.

One of the more sophisticated aspects of this campaign was the way the hacker maintained detailed records of breached organisations and credentials. According to CloudSEK, researchers discovered an exposed server containing these records, which provided insight into the scale and methodical nature of the operation.

Attack Methods: Exploiting Internet-Facing Vulnerabilities

The campaign’s success hinged on exploiting known vulnerabilities in internet-facing systems. The hacker sought out devices and applications that lacked critical security updates, such as:

  • Unpatched VPN gateways and firewalls
  • Webmail and remote access portals
  • Publicly exposed management tools
  • Out-of-date identity services

By exploiting these weak points, the attacker was able to bypass perimeter defences and establish a beachhead within target organisations. The campaign did not rely on novel zero-day vulnerabilities, instead taking advantage of the slow patching cycles and poor configuration management common in many organisations.

Once access was established, the attacker moved laterally within the network, gathering credentials stored on compromised machines. These were then used to escalate privileges, eventually targeting identity systems like Active Directory. In several documented cases, the hacker gained administrative-level access to these systems, giving them control over user accounts and authentication processes.

Credentials Harvested and Access Sold to Ransomware Groups

After gaining access and collecting credentials, the hacker did not always launch attacks themselves. Instead, they acted as an access broker, offering entry to compromised networks for sale to ransomware affiliates and other cybercriminal groups. This business model has become increasingly common in the cybercrime ecosystem, allowing specialist actors to profit from initial access without running the risk of conducting disruptive attacks themselves.

The sale of access often included detailed documentation to buyers, such as:

  • Lists of valid usernames and passwords
  • Network maps and system inventories
  • Instructions for leveraging identity system control
  • Information on security tools and configurations in use

This level of detail makes the access more attractive to ransomware operators, who can move quickly and with precision once inside the target organisation. The research did not specify the exact number of companies affected, but the diversity of sectors and the global reach suggest the impact is significant.

Espionage and Ukrainian Military Targeting

In addition to selling access, the hacker also conducted espionage activities. Evidence collected by CloudSEK indicated that the threat actor actively targeted Ukrainian military-related sites. This points to a dual-purpose operation: profit-driven access brokering alongside intelligence gathering likely aligned with Russian state interests.

While the report did not directly attribute the campaign to a specific government agency, the combination of commercial and espionage objectives is consistent with previous Russian threat actor behaviour. The campaign has been ongoing for several months, with access sales and information gathering occurring in parallel.

Timeline and Current Exploitation Status

The activity was first detected in early 2024, when CloudSEK analysts found an exposed server used by the hacker to store detailed breach records. Since then, the operation has continued, with new organisations being targeted as vulnerabilities are discovered.

Public reporting indicates that the hacker is still actively seeking vulnerable systems, and there is evidence that access sales are ongoing in underground forums. Organisations with unpatched, internet-facing systems remain at heightened risk. There is no indication that the campaign has been disrupted or that the hacker has been identified by law enforcement.

  • Early 2024: Campaign first detected by CloudSEK
  • Ongoing: New breaches and access sales observed
  • Still active: No disruption or law enforcement action reported

Why This Incident Matters

This campaign highlights the severe risk posed by exposed internet-facing systems and the growing market for access broker services. Gaining control over identity management systems allows attackers or their buyers to move laterally, escalate privileges and deploy ransomware at scale. The dual use of criminal and espionage tactics also increases the potential impact for organisations handling sensitive data or with links to government or defence sectors.

Key Steps for Organisations

Organisations should act promptly to mitigate exposure to similar campaigns:

  • Identify and patch all internet-facing systems, prioritising known vulnerabilities
  • Enforce multi-factor authentication, especially for remote and administrative access
  • Monitor for unusual access patterns and credential abuse, particularly involving identity management systems
  • Review access logs for signs of access broker activity or lateral movement

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call