
OPERATION TALKED: Russian-Linked Campaign Against Ukraine's Defense Industry
Indicators of Compromise
No domains found for this campaign
APT Groups1
Russian-speaking cyber espionage threat actor conducting systematic reconnaissance, exploitation, and data theft operations since June 2025 (14 months active). The actor operates a multi-layered C2 infrastructure hosted on Yandex Cloud (Moscow), utilizing the Sliver C2 framework, WireGuard VPN, 3x-ui/Xray panel, and a broad arsenal of 22 CVE exploits. Primary targeting focuses on Ukraine's defense industry and critical infrastructure, with secondary opportunistic exploitation of FortiGate, SonicWall, Sophos, F5, WordPress, and other exposed systems globally. The actor's identity is partially exposed through critical OPSEC failures — an open directory on their primary C2 server exposed 8,400+ operational files including their entire toolkit, credential dumps, target lists, shell history, and Sliver C2 logs. This failure enabled complete reconstruction of their operational timeline, TTPs, and attribution. 3.2 Key Characteristics - **Technical Level:** Intermediate-Advanced — professional C2 frameworks, custom tool development (vnc_25, scanpxy), broad CVE coverage - **OPSEC Level:** WEAK — open directory, uncleaned shell history, hardcoded credentials, Cyrillic keyboard traces, cross-platform identity reuse - **Operational Style:** Patient, methodical reconnaissance followed by targeted exploitation. Uses dual-implant redundancy (2 beacons per victim). Multi-layered tunneling for C2 resilience. - **Language:** Native Russian speaker. Uses Chinese Kimi AI (kimi-code/kimi-for-coding) as coding assistant. - **Platform:** Dual — Windows workstation (WezTerm, PowerShell Core, Chocolatey) + Linux servers (Ubuntu 22.04/24.04) - **Work Hours:** UTC+3 timezone (Moscow) — most activity during European business hours
Campaign Guidance
Remediation, mitigation, notes, history and related intelligence
Patch every internet-facing appliance matching the 19+ CVEs in this campaign's arsenal, prioritizing Sophos XG (CVE-2022-1040), WordPress (CVE-2026-63030), FortiOS (CVE-2024-55591), F5 BIG-IP (CVE-2023-46747), SAP NetWeaver (CVE-2025-31324), and Roundcube (CVE-2025-49113 / CVE-2025-25257).
Block all listed C2, webshell/tunnel, and exfiltration IOC IPs (see IOC section) at firewall/IPS, prioritizing 46.8.236.121 and its associated ports.
Force-rotate all FortiGate SSL-VPN, domain admin, and service-account credentials across any environment with FortiGate exposure (credential-reuse risk).
If Pass-the-Hash/Pass-the-Ticket or domain-admin compromise is suspected, rotate the KRBTGT account twice per Microsoft guidance.
Hunt for and remove Godzilla/r57/suo5/Neo-reGeorg webshells on IIS/ASP.NET and PHP-hosted applications.
Audit Git repository access and clone logs for git-dumper-style bulk-download activity; rotate any credentials or keys committed to exposed repositories.
Hunt for Sliver implant indicators — process masquerading, beacon traffic to 46.8.236.121:11008/11009, 60-second-interval mTLS check-ins.
Restrict/disable WinRM and SMB administrative shares where not operationally required; segment networks to break Pass-the-Hash/WinRM lateral-movement paths.
Review DPAPI-protected credential stores on any host where compromise is suspected (DonPAPI target).
For any organization identified via the Elasticsearch (45.139.104.5:9200) exposure, initiate coordinated third-party disclosure.