Keypoints
- Spetsvuzavtomatika leaked documents appear to come from a broad internal archive, not a single isolated system.
- The sale was advertised by the handle SVA2027 in May 2026 using forum posts, Proton Drive, and private negotiation via Tox.
- Evidence supports the authenticity of the leaked institute material, including matching filenames and consistent metadata.
- Felix-23 and HAD are reconnaissance and targeting platforms built for scanning, enrichment, testing, and campaign management.
- Putnik enables internal-network access, credential theft, lateral movement, and privilege escalation inside target environments.
- Initiative-24 focuses on cloud services for controlling agents and moving data out of corporate networks, while Botany, Blik, Glare, and Chain-24 cover Android collection, covert storage, and anonymous service procurement.
- The leak suggests a coordinated cyber-development ecosystem supporting automated intelligence collection and espionage operations.
MITRE Techniques
- [T1595 ] Active Scanning â Used to discover remote infrastructure, services, and targets through scanning and enrichment (âtarget discovery, scanning, enrichment, and active testingâ).
- [T1589 ] Gather Victim Identity Information â Collected and stored emails, machine names, personnel, contract numbers, and project codes to tie documents to the institute (âemail addresses of individuals and machine names both in English and Cyrillicâ).
- [T1110 ] Brute Force â Felix-23 was designed to test credentials and try brute-force attacks against targets (âTest credentialsâ âTry brute-force attacksâ).
- [T1210 ] Exploitation of Remote Services â The platform was built to confirm and exploit vulnerabilities such as remote code execution and SQL injection (âCheck for remote code executionâ âTest SQL injectionâ).
- [T1078 ] Valid Accounts â Putnik and related workflows focused on credential theft and pass-the-hash use to access systems with reused credentials (âcredential theftâ âexecute commands through pass-the-hashâ).
- [T1021 ] Remote Services â Used TAP-mode VPN and tunneling to interact with internal networks as if locally connected (âbridge Ethernet traffic so an outside operator can interact with the network as though locally connectedâ).
- [T1557 ] Adversary-in-the-Middle â Putnik scenarios included ARP spoofing, DHCP abuse, LLMNR/NBT-NS poisoning, and NTLM capture (âARPâ âDHCPâ âLLMNR and NBT-NS poisoningâ âNTLM captureâ).
- [T1114 ] Email Collection â Initiative-24 examined cloud and email services for staging and transfer, including hidden Exchange folders (âemail, virtual-machine, and serverless servicesâ âhidden Exchange foldersâ).
- [T1095 ] Non-Application Layer Protocol â Botany referenced multiple communications channels including SIP, WebRTC, torrent, and Matrix (âHTTP, SIP, WebRTC, torrent⌠and Matrix communicationsâ).
- [T1407 ] Download New Code in an Existing Module â Botanyâs modular Android design supports interchangeable modules and background updates (âinterchangeable modulesâ âsupport for background monitoring and updatesâ).
- [T1027 ] Obfuscated Files or Information â Blik and Glare hide protected data inside disguised apps and encrypted containers (âcamouflage applicationâ âprotected ZIP or EPUB containersâ).
- [T1105 ] Ingress Tool Transfer â The leak describes offline transfer and moving data into concealed containers for exchange (âoffline transferâ âcreate, open, add files to, edit, or review the contents of a containerâ).
- [T1587 ] Develop Capabilities â The instituteâs documents show research and development of tools, prototypes, and specialized hardware for cyber operations (âturning intelligence and security-service requirements into software, operator procedures, prototypes, and specialized hardwareâ).
- [T1071 ] Application Layer Protocol â Initiative-24 leveraged trusted public cloud services to blend communications into normal business traffic (âcloud platform services can be used for remote control⌠while blending into normal business trafficâ).
- [T1090 ] Proxy â Felix-23 used proxies, TOR, and rotating IPs to conceal activity (âTOR, proxies, distributed VPS nodes, rotating IP addressesâ).
Indicators of Compromise
- [Handles / usernames ] threat actor or related account names â SVA2027, Spetsvuvatom
- [Project names ] leaked internal program names â Felix-23, HAD, Putnik, Initiative-24, Botany, Blik, Glare, Chain-24
- [Organizations / systems ] affected or referenced entities â Spetsvuzavtomatika, Proton Drive, DarkforumsRU
- [Accounts / infrastructure identifiers ] customer or operational references â Military Units 33949, 64829, niisva.org
- [File names ] referenced dump artifacts â 9jhgraoitew.txt, Const.kt, 6.pdf, project-management spreadsheet
- [Network data ] public IP inventory and ranges â 2,403 individual IPv4 addresses, three CIDR ranges, and 1,656 distinct /24 networks
- [External services / tools ] operational services referenced in the dump â Tox, Shodan, VirusTotal, WHOIS, Responder, Nettacker, BoNeSi