Initial Access Brokers have Shifted to High-Value Targets and Premium Pricing
2026-04-01T07:23:50Z•7055826684beff42f0fea0110c21e25fe95c2174dc05c93338d5790757fab5db
BPFdoorCVSSESC-POSIABIoTMetasploitNTLM-relayRDPRDWebRed-MenshenVPNVector-Commandcellularespionageexposure-managementinitial-accessnation-statered-teamingtelecomweb-application-security
What happened
Collection of Rapid7 posts covering: (1) Initial Access Broker (IAB) market trends — IABs shifting toward higher-value targets and premium pricing, with RDP/VPN/RDWeb remaining the primary advertised access vectors; (2) a high-impact telecom intrusion report attributing stealthy BPFdoor sleeper cells to a China-nexus actor (Red Menshen) enabling long-term espionage against carrier infrastructure and government targets; (3) Metasploit Framework updates including improved SMB NTLM relay behavior and a new auxiliary module exploiting an unauthenticated ESC/POS network printer vulnerability (CVE-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 7055826684beff42f0fea0110c21e25fe95c2174dc05c93338d5790757fab5db
- Enrichment time
- 2026-04-01T07:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.