Threat Intelligence

Exposed Server Reveals Russia-Linked Espionage Campaign Against Ukraine's Defense Sector

SOCRadar · 26 Sept 2026
Key Takeaway Businesses, especially those in defense, logistics or critical supply chains, should monitor for unusual outbound connections and unauthenticated exposure of their own infrastructure, since attacker mistakes can reveal campaigns but defenders should not assume they'll be this lucky.

SOCRadar researchers have exposed an ongoing Russia-linked cyber espionage campaign, dubbed OPERATION TALKED, after discovering the threat actor's own command-and-control server was left wide open on the internet. A misconfigured directory on port 8090 exposed more than 8,400 files, including attack tools, stolen credentials, target lists and full session logs, effectively handing researchers a 14-month record of the operation.

The campaign runs on two tracks: broad, opportunistic scanning and exploitation of over 1.1 million internet-facing devices worldwide, alongside a targeted effort that breached nine Ukrainian defense and aerospace contractors and stole their source code repositories. SOCRadar attributes the activity to a Russia-nexus actor with high confidence, citing overlaps with known groups UAC-0056 and UAC-0114, Moscow-timezone activity patterns, and Russian-language artefacts found in the attacker's own shell history.

At the time of publication, the operation was still active. An interactive shell remained open on a compromised Ukrainian railway logistics operator, and the actor's Sliver command-and-control framework, WireGuard VPN and admin panel were all still responding. The entire investigation was made possible because the attacker's infrastructure, hosted on Yandex Cloud with no protective layer in front of it, left its tools and logs openly accessible.

Primary source scpc.gov.ua ->

Summarised by CISO AI from SOCRadar. We link back to every original so you can read it yourself.