SonicWall, Citrix, Sophos, Fortinet, vBulletin, Hikvision and SAP: Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites

SonicWall, Citrix, Sophos, Fortinet, vBulletin, Hikvision and SAP: Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites

Russian-Speaking Hacker Linked to Global Cybercrime and Espionage Operation

A Russian-speaking threat actor has been identified as the orchestrator of a large-scale cyber operation targeting organizations worldwide, acting as an initial access broker (IAB) for ransomware groups. The campaign, uncovered by CloudSEK researchers, exploited exposed security appliances and unpatched vulnerabilities to breach networks across education, healthcare, financial services, telecommunications, and government sectors in over a dozen countries.

Attack Methodology

The hacker conducted large-scale scans to identify vulnerable internet-facing systems, leveraging 12 known exploits in products from Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, and Hikvision. Most exploits relied on public proof-of-concept (PoC) code, though some were modified for the operation.

Once inside a network, the attacker:

  • Deployed web shells and network tunnels to move laterally.
  • Harvested NTLM password hashes, credential stores, and browser secrets.
  • Compromised Active Directory (AD), extracting Kerberos ticket-granting keys to forge long-term authentication tokens.
  • In some cases, achieved full domain control, enabling ransomware groups to later encrypt systems.

Shift to Espionage: Ukraine in the Crosshairs

While the initial focus was financial cybercrime, the operation later pivoted to targeting Ukrainian defense and aerospace organizations. The hacker:

  • Deployed Sliver command-and-control (C2) tooling.
  • Accessed exposed source-code repositories.
  • Collected hundreds of images from internet-facing IP cameras and screenshots from remote desktop sessions, likely to monitor military logistics, border crossings, and critical infrastructure.

CloudSEK assessed with moderate-to-high confidence that this phase served Russian state-linked intelligence needs, though it remains unclear whether the actor was directly tasked or sold the data to a state customer.

Shared Infrastructure and Defensive Recommendations

The same VPS servers, tunnels, and tooling were used for both criminal and espionage activities, highlighting the blurred lines between cybercrime and state-sponsored operations. Organizations are advised to:

  • Remove administrative interfaces from direct internet exposure.
  • Patch vulnerable appliances immediately.
  • Rotate credentials and review unauthorized logins, SSH keys, and device settings.
  • Isolate IP cameras from public networks and replace default passwords.

Indicators of Compromise (IoCs)

CloudSEK provided key IoCs, including:

  • IPv4 addresses linked to operator VPS, jumpboxes, and C2 infrastructure.
  • SHA-256 hashes for Sliver Linux implants and malicious drivers used in credential theft.

The case underscores the dual threat posed by initial access brokers facilitating both ransomware attacks and state-aligned espionage while reinforcing the risks of unpatched edge devices and exposed credentials.

Source: https://cybersecuritynews.com/russian-hacker-breaches-companies/

SonicWall TPRM report: https://www.rankiteo.com/company/sonicwall

Citrix TPRM report: https://www.rankiteo.com/company/citrix

Sophos TPRM report: https://www.rankiteo.com/company/sophos

Fortinet TPRM report: https://www.rankiteo.com/company/fortinet

vBulletin TPRM report: https://www.rankiteo.com/company/vbulletin-solutions-inc.

Hikvision TPRM report: https://www.rankiteo.com/company/hikvision

SAP TPRM report: https://www.rankiteo.com/company/sap

"id": "sapforvbucitsonsophik1785846368",
"linkid": "sap, fortinet, vbulletin-solutions-inc., citrix, sonicwall, sophos, hikvision",
"type": "Vulnerability",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['Education',
                                     'Healthcare',
                                     'Financial Services',
                                     'Telecommunications',
                                     'Government',
                                     'Defense',
                                     'Aerospace'],
                        'location': 'Over a dozen countries (including '
                                    'Ukraine)',
                        'type': ['Education',
                                 'Healthcare',
                                 'Financial Services',
                                 'Telecommunications',
                                 'Government',
                                 'Defense',
                                 'Aerospace']}],
 'attack_vector': 'Exploitation of unpatched vulnerabilities and exposed '
                  'security appliances',
 'data_breach': {'data_exfiltration': 'Yes (data sold on dark web in some '
                                      'cases)',
                 'file_types_exposed': ['Images', 'Source code', 'Screenshots'],
                 'personally_identifiable_information': 'Yes (credentials, '
                                                        'authentication '
                                                        'tokens)',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, authentication tokens, '
                                        'military logistics data)',
                 'type_of_data_compromised': ['NTLM password hashes',
                                              'Credential stores',
                                              'Browser secrets',
                                              'Kerberos ticket-granting keys',
                                              'Source-code repositories',
                                              'Images from IP cameras',
                                              'Remote desktop screenshots']},
 'description': 'A Russian-speaking threat actor has been identified as the '
                'orchestrator of a large-scale cyber operation targeting '
                'organizations worldwide, acting as an initial access broker '
                '(IAB) for ransomware groups. The campaign exploited exposed '
                'security appliances and unpatched vulnerabilities to breach '
                'networks across education, healthcare, financial services, '
                'telecommunications, and government sectors in over a dozen '
                'countries. The operation later pivoted to targeting Ukrainian '
                'defense and aerospace organizations for espionage purposes.',
 'impact': {'data_compromised': 'NTLM password hashes, credential stores, '
                                'browser secrets, Kerberos ticket-granting '
                                'keys, source-code repositories, images from '
                                'IP cameras, remote desktop screenshots',
            'identity_theft_risk': 'High (due to credential harvesting)',
            'operational_impact': 'Full domain control achieved in some cases, '
                                  'enabling ransomware deployment',
            'systems_affected': 'Networks across education, healthcare, '
                                'financial services, telecommunications, '
                                'government, defense, and aerospace sectors'},
 'initial_access_broker': {'backdoors_established': 'Web shells and network '
                                                    'tunnels',
                           'data_sold_on_dark_web': 'Likely (for financial '
                                                    'gain)',
                           'entry_point': 'Exploitation of unpatched '
                                          'vulnerabilities in security '
                                          'appliances',
                           'high_value_targets': 'Active Directory, Kerberos '
                                                 'ticket-granting keys, '
                                                 'source-code repositories, IP '
                                                 'cameras, remote desktop '
                                                 'sessions'},
 'lessons_learned': 'The case underscores the dual threat posed by initial '
                    'access brokers facilitating both ransomware attacks and '
                    'state-aligned espionage, as well as the risks of '
                    'unpatched edge devices and exposed credentials.',
 'motivation': ['Financial gain', 'State-aligned intelligence collection'],
 'post_incident_analysis': {'corrective_actions': ['Patch management',
                                                   'Credential rotation',
                                                   'Network segmentation',
                                                   'Enhanced monitoring',
                                                   'Isolation of critical '
                                                   'systems'],
                            'root_causes': ['Unpatched vulnerabilities in '
                                            'security appliances',
                                            'Exposed administrative interfaces',
                                            'Weak or default credentials',
                                            'Lack of network segmentation']},
 'ransomware': {'data_encryption': 'Yes (in some cases, enabling ransomware '
                                   'deployment)',
                'data_exfiltration': 'Yes'},
 'recommendations': ['Remove administrative interfaces from direct internet '
                     'exposure',
                     'Patch vulnerable appliances immediately',
                     'Rotate credentials and review unauthorized logins, SSH '
                     'keys, and device settings',
                     'Isolate IP cameras from public networks and replace '
                     'default passwords'],
 'references': [{'source': 'CloudSEK'}],
 'response': {'remediation_measures': ['Remove administrative interfaces from '
                                       'direct internet exposure',
                                       'Patch vulnerable appliances '
                                       'immediately',
                                       'Rotate credentials',
                                       'Review unauthorized logins, SSH keys, '
                                       'and device settings',
                                       'Isolate IP cameras from public '
                                       'networks',
                                       'Replace default passwords'],
              'third_party_assistance': 'CloudSEK researchers'},
 'threat_actor': 'Russian-speaking hacker (Initial Access Broker)',
 'title': 'Russian-Speaking Hacker Linked to Global Cybercrime and Espionage '
          'Operation',
 'type': ['Cybercrime', 'Espionage'],
 'vulnerability_exploited': ['Fortinet vulnerabilities',
                             'F5 vulnerabilities',
                             'SonicWall vulnerabilities',
                             'Sophos vulnerabilities',
                             'Citrix vulnerabilities',
                             'SAP vulnerabilities',
                             'Roundcube vulnerabilities',
                             'vBulletin vulnerabilities',
                             'Hikvision vulnerabilities']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.