A recent report has revealed that a Russian hacker has breached companies worldwide, selling access to their systems and spying on Ukrainian military sites. This campaign highlights the ongoing threat posed by access brokers targeting organisations with internet-facing infrastructure.
How the Russian Hacker Operation Unfolded
In early 2024, CloudSEK researchers uncovered a wide-reaching campaign led by a Russian-speaking threat actor. The hacker targeted organisations across sectors including education, healthcare, financial services, telecommunications, and government. The attack focused on entities with exposed internet-facing systems or public applications.
The operator’s approach was systematic. First, they scanned for unprotected security appliances and web applications accessible from the internet. Using known software vulnerabilities, the hacker gained initial access. Once inside a network, the attacker escalated privileges and harvested credentials, including passwords and identity data. In multiple cases, they achieved full control over company identity management systems, making it possible to impersonate users or further pivot within the network.
One of the more sophisticated aspects of this campaign was the way the hacker maintained detailed records of breached organisations and credentials. According to CloudSEK, researchers discovered an exposed server containing these records, which provided insight into the scale and methodical nature of the operation.
Attack Methods: Exploiting Internet-Facing Vulnerabilities
The campaign’s success hinged on exploiting known vulnerabilities in internet-facing systems. The hacker sought out devices and applications that lacked critical security updates, such as:
- Unpatched VPN gateways and firewalls
- Webmail and remote access portals
- Publicly exposed management tools
- Out-of-date identity services
By exploiting these weak points, the attacker was able to bypass perimeter defences and establish a beachhead within target organisations. The campaign did not rely on novel zero-day vulnerabilities, instead taking advantage of the slow patching cycles and poor configuration management common in many organisations.
Once access was established, the attacker moved laterally within the network, gathering credentials stored on compromised machines. These were then used to escalate privileges, eventually targeting identity systems like Active Directory. In several documented cases, the hacker gained administrative-level access to these systems, giving them control over user accounts and authentication processes.
Credentials Harvested and Access Sold to Ransomware Groups
After gaining access and collecting credentials, the hacker did not always launch attacks themselves. Instead, they acted as an access broker, offering entry to compromised networks for sale to ransomware affiliates and other cybercriminal groups. This business model has become increasingly common in the cybercrime ecosystem, allowing specialist actors to profit from initial access without running the risk of conducting disruptive attacks themselves.
The sale of access often included detailed documentation to buyers, such as:
- Lists of valid usernames and passwords
- Network maps and system inventories
- Instructions for leveraging identity system control
- Information on security tools and configurations in use
This level of detail makes the access more attractive to ransomware operators, who can move quickly and with precision once inside the target organisation. The research did not specify the exact number of companies affected, but the diversity of sectors and the global reach suggest the impact is significant.
Espionage and Ukrainian Military Targeting
In addition to selling access, the hacker also conducted espionage activities. Evidence collected by CloudSEK indicated that the threat actor actively targeted Ukrainian military-related sites. This points to a dual-purpose operation: profit-driven access brokering alongside intelligence gathering likely aligned with Russian state interests.
While the report did not directly attribute the campaign to a specific government agency, the combination of commercial and espionage objectives is consistent with previous Russian threat actor behaviour. The campaign has been ongoing for several months, with access sales and information gathering occurring in parallel.
Timeline and Current Exploitation Status
The activity was first detected in early 2024, when CloudSEK analysts found an exposed server used by the hacker to store detailed breach records. Since then, the operation has continued, with new organisations being targeted as vulnerabilities are discovered.
Public reporting indicates that the hacker is still actively seeking vulnerable systems, and there is evidence that access sales are ongoing in underground forums. Organisations with unpatched, internet-facing systems remain at heightened risk. There is no indication that the campaign has been disrupted or that the hacker has been identified by law enforcement.
- Early 2024: Campaign first detected by CloudSEK
- Ongoing: New breaches and access sales observed
- Still active: No disruption or law enforcement action reported
Why This Incident Matters
This campaign highlights the severe risk posed by exposed internet-facing systems and the growing market for access broker services. Gaining control over identity management systems allows attackers or their buyers to move laterally, escalate privileges and deploy ransomware at scale. The dual use of criminal and espionage tactics also increases the potential impact for organisations handling sensitive data or with links to government or defence sectors.
Key Steps for Organisations
Organisations should act promptly to mitigate exposure to similar campaigns:
- Identify and patch all internet-facing systems, prioritising known vulnerabilities
- Enforce multi-factor authentication, especially for remote and administrative access
- Monitor for unusual access patterns and credential abuse, particularly involving identity management systems
- Review access logs for signs of access broker activity or lateral movement
Originally reported by cybersecuritynews.com.






