HomeSecurityUS: Russian accused of selling access to corporate networks

US: Russian charged with selling access to corporate networks

A Russian national, named Evgeniy Doroshenko, is accused of providing access to corporate networks of American companies. This activity is said to have occurred from February 2019 to May 2024.

access corporate networks

Essentially, the Russian was operating as an initial access broker (IAB), a threat actor that compromises corporate networks and then sells access to other threat, allowing them to steal data and launch various attacks against victims.

Doroshenko is known online under the pseudonyms “FlankerWWH” and “Flanker.” After hacking into corporate networks, he sold access to Russian-language hacking forums.

See also: Check Point VPNs are used to compromise corporate networks

The indictment cites an incident from January 2024, when FlankerWWH attempted to sell access to network in Bergen County, New Jersey.

Examination of data on FlankerWWH activity shows that the preferred attack method was to compromise networks by brute-forcing exposed Remote Desktop Protocol services.

Additionally, the same user was spotted asking for help cracking NTLM hashes, which were likely obtained after a network breach.

Using Flare's threat intelligence system, BleepingComputer found additional posts by Russian Evgeniy Doroshenko, who was asking for help removing passwords from Excel spreadsheets and advice on contacting the developer of a keylogger.

See also: Chinese hackers turn to ORB proxy networks

In addition to all of the above, the indictment also mentions an instance where Doroshenko stole information from one of the systems he breached, worth over $5,000.

US: Russian charged with selling access to corporate networks
Russian man accused of selling access to corporate networks

For now, however, the suspect has not been arrested and is in Russia.

Initialaccess broker

The case of Evgeniy Doroshenko highlights the growing threat of initial access brokers in the world of cybercrime. These individuals or groups specialize in gaining access to vulnerable computer networks and selling that access to other criminals. This allows cybercriminals with limited technical skills to carry out sophisticated attacks, making it easier for them to profit from their illegal activities.

Initial access brokers often use various techniques to gain access to targeted networks, such as exploiting vulnerabilities , phishing emails, or social engineering tactics. They then sell this access on underground forums or marketplaces for a significant profit.

This type of criminal activity is particularly concerning, as it not only puts individuals and businesses at risk, but also has greater implications for national security. Cybercriminals who gain access to sensitive government networks could potentially cause significant damage and disrupt critical infrastructure.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Unfading Sea Haze was hidden in government networks for 6 years

Russian Evgeniy Doroshenko
Russian man accused of selling access to corporate networks

Law enforcement agencies are constantly working to identify and apprehend these criminals, but it is a difficult task. With the ever-evolving cybercrime landscape and the anonymity provided by the dark web, these individuals are difficult to track down.

To protect against this type of threat, it is vital for individuals and organizations to measures cybersecurity and remain vigilant against potential attacks. This includes regularly updating software and systems, implementing strong passwords and multi-factor authentication, and educating employees about the dangers of phishing scams.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS