Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine
ID: 99c3d868-2e0a-5eb2-b868-0e3ddcc84ebe
STIX ID: report--99c3d868-2e0a-5eb2-b868-0e3ddcc84ebe
Feed Name: GBHackers
Threat Score
An exposed server revealed a Russian‑language initial access broker that automates large-scale exploitation of internet-facing appliances (Fortinet, Citrix, F5, SonicWall, etc.), pivots to full Active Directory compromise (including forged Kerberos tickets and DPAPI/krbtgt theft), sells access to ransomware affiliates, and performs state-aligned intelligence collection against Ukrainian defence and aerospace targets; the report includes tooling details, victimology, and multiple IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
