Campaigns
OPERATION TALKED: Russian-Linked Campaign Against Ukraine's Defense Industry

OPERATION TALKED: Russian-Linked Campaign Against Ukraine's Defense Industry

Cyber EspionageSliver C2Russia-LinkedOPERATION TALKED
SOCRadar identified an active Russian-linked cyber espionage operation - codenamed OPERATION TALKED - after discovering the actor's own C2 server at 46.8.236.121 left as a fully open unauthenticated directory exposing 8400+ operational files. A 14-month campaign (June 2025 - July 2026) combines mass opportunistic exploitation of internet-facing appliances with targeted espionage against Ukraine's defense and aerospace industry - resulting in confirmed Git repository theft from nine defense contractors and an active interactive-shell breach of a Ukrainian railway logistics operator still open at time of publication.

Indicators of Compromise

No domains found for this campaign

APT Groups1

Operation TalkedRU

Russian-speaking cyber espionage threat actor conducting systematic reconnaissance, exploitation, and data theft operations since June 2025 (14 months active). The actor operates a multi-layered C2 infrastructure hosted on Yandex Cloud (Moscow), utilizing the Sliver C2 framework, WireGuard VPN, 3x-ui/Xray panel, and a broad arsenal of 22 CVE exploits. Primary targeting focuses on Ukraine's defense industry and critical infrastructure, with secondary opportunistic exploitation of FortiGate, SonicWall, Sophos, F5, WordPress, and other exposed systems globally. The actor's identity is partially exposed through critical OPSEC failures — an open directory on their primary C2 server exposed 8,400+ operational files including their entire toolkit, credential dumps, target lists, shell history, and Sliver C2 logs. This failure enabled complete reconstruction of their operational timeline, TTPs, and attribution. 3.2 Key Characteristics - **Technical Level:** Intermediate-Advanced — professional C2 frameworks, custom tool development (vnc_25, scanpxy), broad CVE coverage - **OPSEC Level:** WEAK — open directory, uncleaned shell history, hardcoded credentials, Cyrillic keyboard traces, cross-platform identity reuse - **Operational Style:** Patient, methodical reconnaissance followed by targeted exploitation. Uses dual-implant redundancy (2 beacons per victim). Multi-layered tunneling for C2 resilience. - **Language:** Native Russian speaker. Uses Chinese Kimi AI (kimi-code/kimi-for-coding) as coding assistant. - **Platform:** Dual — Windows workstation (WezTerm, PowerShell Core, Chocolatey) + Linux servers (Ubuntu 22.04/24.04) - **Work Hours:** UTC+3 timezone (Moscow) — most activity during European business hours

Titan_monitor_botOperation TalkedEdwin Moses

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

Remediation
  1. Patch every internet-facing appliance matching the 19+ CVEs in this campaign's arsenal, prioritizing Sophos XG (CVE-2022-1040), WordPress (CVE-2026-63030), FortiOS (CVE-2024-55591), F5 BIG-IP (CVE-2023-46747), SAP NetWeaver (CVE-2025-31324), and Roundcube (CVE-2025-49113 / CVE-2025-25257).

  2. Block all listed C2, webshell/tunnel, and exfiltration IOC IPs (see IOC section) at firewall/IPS, prioritizing 46.8.236.121 and its associated ports.

  3. Force-rotate all FortiGate SSL-VPN, domain admin, and service-account credentials across any environment with FortiGate exposure (credential-reuse risk).

  4. If Pass-the-Hash/Pass-the-Ticket or domain-admin compromise is suspected, rotate the KRBTGT account twice per Microsoft guidance.

  5. Hunt for and remove Godzilla/r57/suo5/Neo-reGeorg webshells on IIS/ASP.NET and PHP-hosted applications.

  6. Audit Git repository access and clone logs for git-dumper-style bulk-download activity; rotate any credentials or keys committed to exposed repositories.

  7. Hunt for Sliver implant indicators — process masquerading, beacon traffic to 46.8.236.121:11008/11009, 60-second-interval mTLS check-ins.

  8. Restrict/disable WinRM and SMB administrative shares where not operationally required; segment networks to break Pass-the-Hash/WinRM lateral-movement paths.

  9. Review DPAPI-protected credential stores on any host where compromise is suspected (DonPAPI target).

  10. For any organization identified via the Elasticsearch (45.139.104.5:9200) exposure, initiate coordinated third-party disclosure.

Observed Countries250

AD (372)
AE (778)
AF (595)
AG (867)
AI (105)
AL (764)
AM (995)
AO (255)
AQ (342)
AR (959)
AS (517)
AT (945)
AU (360)
AW (445)
AX (765)
AZ (949)
BA (641)
BB (492)
BD (698)
BE (370)
BF (262)
BG (472)
BH (358)
BI (963)
BJ (261)
BL (631)
BM (869)
BN (913)
BO (117)
BQ (269)
BR (359)
BS (485)
BT (779)
BV (585)
BW (224)
BY (681)
BZ (254)
CA (357)
CC (573)
CD (244)
CF (390)
CG (828)
CH (972)
CI (885)
CK (421)
CL (171)
CM (341)
CN (803)
CO (586)
CR (25)
CU (483)
CV (990)
CW (82)
CX (87)
CY (199)
CZ (453)
DE (248)
DJ (210)
DK (894)
DM (599)
DO (396)
DZ (815)
EC (135)
EE (546)
EG (469)
EH (995)
ER (517)
ES (990)
ET (757)
FI (18)
FJ (453)
FK (175)
FM (479)
FO (432)
FR (207)
GA (955)
GB (435)
GD (95)
GE (917)
GF (208)
GG (652)
GH (958)
GI (103)
GL (102)
GM (10)
GN (982)
GP (183)
GQ (291)
GR (771)
GS (545)
GT (902)
GU (949)
GW (878)
GY (300)
HK (943)
HM (479)
HN (122)
HR (826)
HT (92)
HU (910)
ID (80)
IE (675)
IL (309)
IM (662)
IN (577)
IO (641)
IQ (678)
IR (320)
IS (231)
IT (32)
JE (608)
JM (214)
JO (983)
JP (673)
KE (984)
KG (481)
KH (245)
KI (57)
KM (851)
KN (973)
KP (157)
KR (699)
KW (879)
KY (300)
KZ (620)
LA (964)
LB (268)
LC (467)
LI (434)
LK (108)
LR (128)
LS (714)
LT (84)
LU (412)
LV (51)
LY (755)
MA (150)
MC (313)
MD (61)
ME (718)
MF (151)
MG (74)
MH (885)
MK (537)
ML (853)
MM (9)
MN (7)
MO (772)
MP (566)
MQ (430)
MR (170)
MS (774)
MT (313)
MU (985)
MV (842)
MW (369)
MX (948)
MY (459)
MZ (247)
NA (81)
NC (94)
NE (385)
NF (547)
NG (176)
NI (126)
NL (249)
NO (635)
NP (583)
NR (946)
NU (163)
NZ (744)
OM (997)
PA (444)
PE (333)
PF (495)
PG (764)
PH (234)
PK (206)
PL (850)
PM (353)
PN (770)
PR (342)
PS (154)
PT (786)
PW (637)
PY (344)
QA (947)
RE (363)
RO (647)
RS (102)
RU (298)
RW (340)
SA (760)
SB (778)
SC (724)
SD (167)
SE (715)
SG (317)
SH (238)
SI (776)
SJ (115)
SK (559)
SL (743)
SM (784)
SN (95)
SO (624)
SR (523)
SS (742)
ST (182)
SV (52)
SX (16)
SY (692)
SZ (195)
TC (352)
TD (351)
TF (972)
TG (637)
TH (662)
TJ (727)
TK (912)
TL (269)
TM (783)
TN (887)
TO (729)
TR (187)
TT (341)
TV (534)
TW (549)
TZ (506)
UA (495)
UG (432)
UM (574)
US (85)
UY (166)
UZ (425)
VA (217)
VC (506)
VE (843)
VG (230)
VI (173)
VN (758)
VU (149)
WF (234)
WS (221)
XK (665)
YE (580)
YT (246)
ZA (346)
ZM (283)
ZW (529)