Attackers Use Over 240 Exploits Ahead of Ransomware Attacks
Ransomware attacks commence with reconnaissance rather than encryption. Recently, security researchers documented a significant reconnaissance operation conducted over the Christmas holiday.
Ransomware attacks commence with reconnaissance rather than encryption. Recently, security researchers documented a significant reconnaissance operation conducted over the Christmas holiday.
From December 25 to 28, a single operator systematically scanned the internet for vulnerable systems, testing over 240 different exploits and logging successful hits. The data collected—a fresh inventory of confirmed vulnerabilities—could fuel targeted intrusions in 2026 and be used by threat actors seeking initial access points.
Initial Access Brokers (IABs) operate as reconnaissance units within the ransomware ecosystem. They specialize in identifying exploitable systems and compiling catalogs of vulnerable targets. This division of labor allows IABs to focus on reconnaissance, while ransomware groups handle monetization and extortion.
Access to compromised networks is traded in criminal marketplaces, with prices varying based on the target's value. The reconnaissance operation observed over Christmas exemplifies the supply side of this illicit market.
The operation originated from two IP addresses associated with CTG Server Limited (AS152194): 134.122.136.119 and 134.122.136.96.
Requests were made at intervals of 1–5 seconds, testing each target against 11 different exploit types. The attacker employed Out-of-Band Application Security Testing (OAST) domains to confirm vulnerabilities, with compromised systems transmitting outbound requests to the attacker's callback infrastructure.
Ransomware attacks commence with reconnaissance rather than encryption.
Researchers identified over 57,000 unique OAST subdomains linked to ProjectDiscovery’s Interactsh platform.
The tooling used aligns with Nuclei, an open-source vulnerability scanner, operating at an industrial scale. The attacker's domain selection allowed security analysts to decode subdomains using techniques previously outlined in a 2024 LabsCon presentation on OAST infrastructure analysis.
The operation executed in two waves: the first utilized both IP addresses on Christmas day, while the second occurred 12 hours later with a single IP address and 13 additional exploit templates.
JA4 network fingerprints and shared Machine ID signatures across 98 percent of attempts confirm it was a single operator rather than a coordinated group effort. The timing suggests calculated planning, exploiting weakened security defenses during holiday periods.
CTG Server Limited, despite existing for about a year, manages roughly 201,000 IPv4 addresses across 672 prefixes. Identified as the leading ASN for phishing domains within the FUNNULL CDN infrastructure, the network also announces bogon routes, and multiple IP ranges appear on abuse blocklists.
This provider profile suggests minimal abuse enforcement, making it appealing for operations requiring resilience and evasion capabilities.
Organizations should review server and network logs from December 25–28 for connections from the identified IP addresses. DNS log examination for queries to OAST domains (.pro, .site, .me, .online, .fun, .live) is recommended for additional detection opportunities. Identified matches indicate confirmed vulnerabilities, meaning attackers possess technical knowledge for access, and this intelligence may already be listed for sale in criminal marketplaces.
While no evidence currently links this campaign to state-aligned actors, high-quality vulnerability intelligence often circulates beyond criminal markets. State-aligned groups have previously acquired similar data through broker purchases or parallel efforts, potentially enabling infrastructure access and espionage operations.
Follow us on Google News , LinkedIn , and X for updates and set GBH as a preferred source in Google .
Based on reporting by GBHackers.
