Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment
Between Tue, Dec 25, 2024, and Fri, Dec 28, 2024, a threat actor conducted a large-scale scanning campaign, testing over 240 different exploits against internet-facing systems. The operation collected data on every vulnerable target identified.
Between Tue, Dec 25, 2024, and Fri, Dec 28, 2024, a threat actor conducted a large-scale scanning campaign, testing over 240 different exploits against internet-facing systems. The operation collected data on every vulnerable target identified.
This reconnaissance activity, using two IP addresses linked to CTG Server Limited (AS152194), marks a sophisticated approach to securing initial access for ransomware operations. The attacker systematically probed targets at intervals of one to five seconds, employing 11 different exploit types per system to identify vulnerabilities.
The campaign indicates a shift in ransomware strategies. Instead of direct attacks, threat actors are acting as Initial Access Brokers (IABs), compiling catalogs of vulnerable systems for sale to ransomware groups. The data collected during this period will likely contribute to targeted intrusions in 2026.
The timing took advantage of holiday periods when security teams are reduced, and detection systems receive minimal attention.
The data collected during this period will likely contribute to targeted intrusions in 2026.
Greynoise analysts identified the campaign by detecting over 57,000 unique Out-of-Band Application Security Testing (OAST) subdomains tied to ProjectDiscovery's Interactsh platform. The tooling matched Nuclei, an open-source vulnerability scanner, operated at an industrial scale.
Detection Evasion and Infrastructure Analysis
The use of CTG Server Limited raises concerns about resilient infrastructure for criminal operations. This Hong Kong-registered hosting provider manages approximately 201,000 IPv4 addresses across 672 prefixes and operates with minimal abuse enforcement.
The network has previously hosted phishing domains within FUNNULL CDN infrastructure and announces bogon routes, indicating poor network hygiene practices that make it suitable for operations requiring infrastructure capable of withstanding blocking attempts.
Organizations should review logs from the campaign dates for connections to the suspicious IP addresses 134.122.136.119 and 134.122.136.96, as well as DNS queries to OAST domains such as oast.pro, oast.site, oast.me, oast.online, oast.fun, and oast.live.
If any matches are found, it is likely that vulnerabilities in the networks have been confirmed, and this access information may already be available for purchase in criminal marketplaces.
Based on reporting by Cyber Security News.
