In effect, the server was the operator's playbook and keystroke log, left visible to anyone who knew where to look.
The broker staged exploits for at least 12 distinct CVEs targeting widely deployed internet-facing edge appliances and web applications . Affected vendors include Fortinet, SonicWall, F5, Citrix, Sophos, SAP, Roundcube, vBulletin, and Hikvision
. While most exploit code was public proof-of-concept, key Fortinet and Citrix exploits were modified into modular frameworks with Russian-language wrappers that automated SSH key injection, VPN user creation, admin backdoor provisioning, and mass scanning
. The operator also maintained a local copy of the nuclei templates repository plus over 100 custom templates for detecting fresh vulnerabilities and C2/stealer panels
.
Targeted sectors include education, healthcare, finance, telecommunications, and government—across more than a dozen countries in North America, Europe, and beyond .
CloudSEK notes this tradecraft closely matches the AIVD/MIVD (Dutch intelligence) advisory on Russian state-linked camera surveillance used to locate Ukrainian military positions .
CloudSEK assesses with high confidence that the operator is a Russian-speaking initial access broker whose Ukraine-focused activity is best explained as a criminal contractor selling access—including camera-derived intelligence—to state buyers .
This aligns with a well-documented Russian intelligence pattern: state-sponsored actors (e.g., SVR, GRU, FSB) routinely source initial network access from the criminal ecosystem rather than conducting initial compromise themselves . The criminal broker handles the high-volume, noisy work of scanning and exploiting edge appliances; state clients pay for pre-positioned access to high-value targets (especially defense, aerospace, and government entities) without exposing state-controlled infrastructure during the initial breach.
The same access that the broker sold to ransomware groups for profit against commercial targets was also sold as a surveillance pipeline against Ukrainian military targets—a dual-use model where the same technical capability generates both criminal revenue and strategic intelligence value for the Russian state .