Back to advisories
HighAdvisory
4 min read

Threat Advisory: Resurgence of Persistent Threat Actor Involved in the Nigeria BreachGate Incident Across Eastern Europe

Whitehat.NG has detected the resurgence of a highly persistent threat actor (bytetobreach) previously observed operating within Nigerian digital ecosystem and targeting critical infrastructure during Q1/Q2 2026 (Nigeria BreachGate Incident). After a period of dormancy, the actor has re-emerged with active cyber operations across Europe, specifically targeting infrastructure in Latvia, Romania, and most recently, Georgia.

Executive Summary

Whitehat.NG has detected the resurgence of a highly persistent threat actor (bytetobreach) previously observed operating within the Nigerian digital ecosystem and targeting critical infrastructure during Q1/Q2 2026 (Nigeria BreachGate Incident). After a period of dormancy, the actor has re-emerged with active cyber operations across Europe, specifically targeting infrastructure in Latvia, Romania, and most recently, Georgia.
The adversary focuses heavily on exploiting known vulnerabilities in Geographic Information Systems (GIS), Identity and Access Management (IAM) platforms, and virtualization layers in these recent attacks. This advisory provides actionable Indicators of Compromise (IOCs) and technical breakdowns of the infrastructure mapped in Latvia and Romania to assist national CERTs in proactive hunting and perimeter defense.

Actor Profile & Behavioural Evolution

  • Agnostic Targeting: The actor compromises varied industry verticals but prioritizes entry via high-value niche systems (e.g., Latvia State Forests (LVM) and Romania Cadastre (ANCPI)) and recently Government of Georgia.
  • Infrastructure Reuse: The actor is actively reusing specific IP infrastructure previously deployed during the Q1/Q2 2026 Nigerian campaigns, indicating a shared operational resource pool or static infrastructure provisioning.
  • Objective: The tactical progression—from initial foothold to local persistence, domain takeover, and finally targeting backup architectures (Veeam) and virtualization layers (ESXi)—strongly indicates financial extortion (ransomware) or high-impact operational disruption.

Country-Specific Technical Breakdowns

3.1 Operational Activity: Latvia

In Latvia, the adversary targeted vulnerable geospatial data environments to establish an initial foothold before pivoting deeper into internal network segments.

  • Initial Foothold Vectors: Targeted internet-facing ArcGIS environments and GeoServer instances (version 2.26.1 and earlier).
  • Exploited Vulnerabilities:
    • CVE-2024-36401 (GeoServer Remote Code Execution)
    • CVE-2025-58360 (Recent Remote Code Execution / Authorization Bypass)
    • CVE-2023-46214 (Splunk Enterprise Remote Code Execution)
  • Pivoting & Escalation: Once inside, the actor successfully targeted SIP Gateways, Splunk logging servers, ManageEngine Password Manager, and pursued Active Directory Domain Controller Takeover.
  • Impact Operations: Final actions targeted virtualization layers and backup continuity via VMware ESXi, vCenter (vSphere Client), and Veeam Backup & Replication Service.

Network Indicators (Latvia Campaign)

Indicator Type Description / Role
185.44.76[.]137 IPv4 Command & Control (C2) Server
80.96.108[.]88 IPv4 Command & Control (C2) Server
185.103.164[.]149 IPv4 Ransomware Mount Box / Data Exfiltration
38.29.212[.]164 IPv4 Threat Actor Infra (Matches historical Nigerian campaign activity)
172.241.228[.]78 IPv4 Threat Actor Infra (Matches historical Nigerian campaign activity)
66.163.117[.]146 IPv4 Threat Actor Infrastructure (Cross-campaign overlap)
159.26.105[.]137 IPv4 Threat Actor Infrastructure
62.169.136[.]21 IPv4 Threat Actor Infrastructure
66.163.117[.]25 IPv4 Threat Actor Infrastructure

3.2 Operational Activity: Romania

In Romania, the actor shifted entry tactics, leveraging identity management and enterprise application servers instead of geospatial assets.

  • Initial Foothold Vectors: Targeted OpenAM instances via Pre-Authentication Remote Code Execution (RCE) vectors.
  • Exploited Vulnerabilities:
    • CVE-2021-35464 (OpenAM Pre-Auth RCE)
    • CVE-2020-14882 (Oracle WebLogic Server RCE)
    • CVE-2021-22205 (GitLab ExifTool RCE)
  • Pivoting & Escalation: Exploited integrated OpenDJ LDAP servers, unpatched internal GitLab instances, Oracle WebLogic Server (EMCC), FortiSIEM, Juniper network appliances, and achieved Active Directory Domain Controller Takeover.
  • Persistence Mechanisms: Maintained continuous network presence through Silver C2 implant on Zabbix monitoring server, compromised OpenAM layers, and Oracle WebLogic Server.
  • Impact Operations: Replicated the Latvian playbook by targeting VMware vCenter (vSphere Client) and Veeam Backup & Replication Service.

Network Indicators (Romania Campaign)

Indicator Type Description / Role
66.163.118[.]52 IPv4 Metasploit Framework C2 Node
194.102.105[.]193 IPv4 Multi-Tool Hub (Sliver C2, Nessus, VNC, Metasploit)
66.163.117[.]146 IPv4 Threat Actor Infrastructure (Overlaps directly with Latvian Campaign)
42.205.[1.]223 IPv4 Threat Actor Infrastructure

Key Cross-Campaign Overlaps

  1. Infrastructure Overlap: The IP address 66.163.117[.]146 was observed operating in both the Latvian and Romanian campaigns, proving a centralized operational entity.
  2. The Nigerian Connection: IPs 38.29.212[.]164 and 172.241.228[.]78 bridge this current European push directly back to the Q1/Q2 2026 intrusions handled by Whitehat.NG in West Africa.
  3. Impact Monopolization: Regardless of how the actor gains access (GeoServer vs. OpenAM), the end-stage playbook remains identical: take over the Domain Controller, isolate vCenter/ESXi, and disable or compromise Veeam backups.

Recommended Mitigations & Hunting Actions

5.1 Perimeter & Patch Management

  • Urgent Patching: Immediate validation and patching of enterprise systems against the connected CVEs list (specifically CVE-2024-36401, CVE-2025-58360, and legacy RCEs in OpenAM/WebLogic).
  • Isolate Virtualization Layers: Restrict network access to VMware vCenter and ESXi management interfaces. Ensure they are completely inaccessible from general user subnets and require multi-factor authentication (MFA) via a dedicated administrative jump box.
  • Secure Backups: Enforce immutable backup repositories for Veeam. Isolate backup servers from the primary Active Directory domain to prevent lateral compromise following a Domain Controller takeover.

5.2 Network Defense & Intelligence Hunting

  • Ingest IOCs: Deploy all listed IP addresses into local SIEM, EDR, and network firewalls for immediate blocking and retroactive 90-day log hunting.
  • Monitor IAM & Monitoring Tools: Audit unexpected configuration modifications or outbound connections from OpenAM, OpenDJ, and Zabbix servers.
  • Feedback & Intelligence Sharing: For updates regarding activities related to this threat actor in Georgia, or to correlate historical telemetry, please contact the Whitehat.NG Threat Intelligence Desk at cert@whitehat.ng