Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
initial-access-methodstate-sponsored-espionagegovernment-diplomatic-threattelecommunications-sector-threat

State-Backed Intrusions Exploit RDP, VPN, SSH, and Supply Chains for Initial Access

Updated 28d agoFirst seen May 22, 20266 sources

Russian and China-linked threat activity has relied on common but effective entry points to penetrate government, telecom, defense, energy, and other critical-sector networks. Ukrainian officials said CERT-UA recorded 5,927 cyber incidents in 2025, a 37.4% increase over the prior year, with Russian groups including UAC-0002 (Sandworm), UAC-0001 (APT28), UAC-0010 (Gamaredon), and UAC-0190 (Void Blizzard) using exposed RDP services, vulnerable VPN appliances, supply-chain compromise, phishing, and stolen credentials to gain access. Separately, telecom intrusions tied to the China-linked cluster UAT-9244 used exposed web applications, ProxyLogon, exposed SSH services, weak credentials, and unpatched server software to establish footholds in Linux-heavy environments.

Once inside, the actors deployed a broad toolset for espionage, persistence, and disruption, including RATs, stealers, ransomware, wipers, and Linux malware such as PeerTime, which supports multiple architectures and uses peer-to-peer, BitTorrent-like communications to avoid reliance on centralized command-and-control. The reporting highlights exploitation of products including Cisco ASA/AnyConnect, Roundcube, Fortinet, WinRAR, 7-Zip, and legacy Microsoft Office components, alongside social-engineering tactics such as ClickFix, device-code phishing, OAuth phishing, and QR-code hijacking. The campaigns also abused legitimate services and native system tools, while under-monitored embedded Linux devices, routers, edge systems, and container hosts were described as especially attractive for long-term persistence, lateral movement, scanning, and covert communications.

Share:
State-Backed Intrusions Exploit RDP, VPN, SSH, and Supply Chains for Initial Access
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
May 22, 20261mo ago

PeerTime Linux malware identified in telecom-linked intrusion activity

A Linux malware payload called PeerTime was highlighted as supporting multiple architectures including ARM, AArch64, MIPS, PowerPC, and x86, suggesting targeting of embedded appliances, routers, and virtualized infrastructure. The malware reportedly uses peer-to-peer and BitTorrent-like traffic patterns and checks for Docker before execution, indicating an effort to persist in modern enterprise and telecom environments.

Telecom intrusions tied to UAT-9244 use exposed services and weak credentials

Recent telecom-focused intrusions associated with the China-linked cluster UAT-9244 were reported as using exposed web applications, ProxyLogon exploitation, exposed SSH services, weak credentials, and unpatched server-side software for access. The operations emphasized persistence and infrastructure abuse rather than novel exploitation.

Apr 1, 20263mo ago

CERT-UA reports H2 2025 decline in incidents but more advanced tradecraft

CERT-UA published a report on the second half of 2025 stating that the number of cyber incidents had decreased, while attackers increasingly relied on more sophisticated social engineering and more standardized toolkits. The report added an official Ukrainian assessment of changing threat quality during late 2025 rather than only overall annual volume.

CERT-UA Reports Drop in Cyber Incidents but Warns of Advanced Social Engineering and Standardised Hacker Toolkits in H2 2025
Feb 10, 20264mo ago

Mandiant publishes threat intelligence on attacks targeting the defense industrial base

Google Cloud/Mandiant published a threat-intelligence report detailing cyber threats affecting the defense industrial base, adding a distinct disclosure focused on DIB-targeting activity. This represents a new reporting development separate from the existing Ukraine-wide and telecom-focused entries.

Threats to the Defense Industrial Base | Google Cloud Blog
Dec 31, 20256mo ago

Russian state-linked groups intensify 2025 campaigns using varied initial access methods

During 2025, Russian state-sponsored groups including UAC-0002 (Sandworm), UAC-0001 (APT28), UAC-0010 (Gamaredon), and UAC-0190 (Void Blizzard) intensified operations using exposed RDP, VPN vulnerabilities, supply-chain compromise, phishing, messaging-app lures, and brokered stolen credentials for initial access. Reported exploitation included flaws in Cisco ASA/AnyConnect, Roundcube, Fortinet, WinRAR, 7-Zip, and legacy Microsoft Office, alongside social-engineering techniques such as ClickFix, Device Code phishing, OAuth phishing, and GhostPairing QR-code hijacking.

CERT-UA records 5,927 cyber incidents in Ukraine during 2025

Ukraine’s CERT-UA recorded about 5,927 cyber incidents in 2025, representing a 37.4% increase over 2024. The activity was described as deliberate and persistent, with government, defense, energy, and other critical sectors in Ukraine and across Europe heavily targeted.

Oct 16, 20233y ago

Sandworm breaches 11 Ukrainian telecom providers

Ukraine's CERT-UA disclosed that the Russian state-backed Sandworm group had compromised 11 Ukrainian telecommunications providers since May 2023. The intrusions targeted telecom infrastructure during the war, marking a specific campaign against Ukraine's communications sector.

Russian Sandworm hackers breached 11 Ukrainian telcos since May
Mar 15, 20188y ago

CISA alerts on Russian targeting of energy and critical infrastructure

CISA issued alert TA18-074A describing Russian government cyber activity targeting U.S. energy, nuclear, commercial facilities, water, aviation, and other critical infrastructure sectors. The alert publicly documented intrusion tactics and warned that the activity enabled access to operationally sensitive networks.

Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors | CISA
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

75 LINKEDOpen in app
Affected products
11 linked
TelegramWhatsappRoundcube WebmailZimbraRedisDropbox7-ZipWinrarGoogle DriveMicrosoft OfficeDocker
Organizations
8 linked
Cisco SystemsCloudflareDropboxFortinetAppleMicrosoft CorporationCyber Security NewsGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.