Leak Reveals Russian Institute’s Apparent SVR-Linked Cyber Development Ecosystem

Summary
Leaked Spetsvuzavtomatika documents describe tools for reconnaissance, network access, credential theft, data collection and covert operations. The files appear authentic, but do not prove that every capability was deployed or identify how the leak occurred.
Key points
- DomainTools assesses with high confidence that SVA2027 possessed authentic institute material. The institute acknowledged an attack but denied an internal-network compromise; the original intrusion and access method remain unconfirmed.
- Felix-23 and HAD are described as platforms for reconnaissance, target tracking, scanning and active testing, using proxies, TOR and distributed infrastructure to obscure activity.
- Putnik is designed to bridge operators into target networks and support credential capture, lateral movement and privilege escalation; leaked material includes a Zerologon exploitation workflow.
- Initiative-24 examines using trusted cloud services to control agents, stage data and extract information from corporate networks while blending into ordinary traffic.
- Other projects include Botany, a likely modular Android collection tool, and Blik and Glare, utilities for concealed storage and offline data transfer.
- The documents describe a broad cyber-espionage development program, but do not establish that all tools were completed, deployed or used together.
Article Details
- Attack Vectors
- Felix-23 and HAD are designed to discover and track internet-facing targets, test vulnerabilities and credentials, and coordinate scanning through proxies and VPS nodes. The documents do not establish that every capability was deployed.
- Putnik documentation describes bridging an operator into a target network with TAP-mode OpenVPN and SoftEther, then using spoofing, name-resolution poisoning, NTLM capture, and SMB access. A documented laboratory workflow includes Zerologon exploitation, credential extraction, pass-the-hash, account creation, and Domain Admin elevation.
- Initiative-24 researches using trusted cloud services to control agents inside corporate networks, stage collected data, and transfer it out while blending with normal traffic.
- Botany's documented Android design combines a visible application, encrypted core, and interchangeable collection modules; its full runtime code was not available.
- Blik and Glare documentation describes camouflage applications and protected containers for concealed storage and offline transfer.
MITRE ATT&CK
T1003.003 · NTDSPutnik's documented Zerologon laboratory workflow includes extracting NTDS data.T1036 · MasqueradingBlik and Glare documentation describes hiding protected data and functions inside applications resembling ordinary Sudoku, calculator, or e-reader software.T1090 · ProxyFelix-23 is designed to conceal activity through proxies and distributed VPS nodes; HAD manages proxy chains.T1102 · Web ServiceInitiative-24 researches using trusted public cloud services as communication channels for agents operating inside corporate networks.T1110 · Brute ForceFelix-23's documented functions include trying brute-force attacks against credentials.T1136.002 · Domain AccountA documented Putnik laboratory workflow creates a domain account.T1550.002 · Pass the HashA documented Putnik laboratory workflow uses extracted credentials to execute commands through pass-the-hash.T1557.001 · Name Resolution Poisoning and SMB RelayPutnik's documented internal-network scenarios include LLMNR and NBT-NS poisoning and NTLM capture with Responder.T1595 · Active ScanningFelix-23 is designed to scan internet-facing infrastructure, while HAD supports scanning and vulnerability testing.
CVE
Products
Androidsoftware agents and move data from corporate networks. A project named Botany appears focused on modular Android collection while Blik and Glare focuses on concealed storage and offline transfer. Finally, the projectExchangeand serverless services commonly used in the cloud today. The report also describes hidden Exchange folders that could store instructions or collected data without appearing in normal Outlook or webmailMicrosoft Windowswork. The repository inventory also shows the institute’s technical range, including cloud identity, Windows and Android tooling, communications-layer compromise, and payload delivery. The programs cover embeddedOpenVPNPutnik creates remote Layer 2 access inside a target network. It uses TAP-mode OpenVPN and SoftEther to bridge Ethernet traffic so an outside operator can interact with the network as though locally connected. TheSoftEtherPutnik creates remote Layer 2 access inside a target network. It uses TAP-mode OpenVPN and SoftEther to bridge Ethernet traffic so an outside operator can interact with the network as though locally connected. The
Tools
BerylliumManagement correspondence also requested scenarios for credential theft, printer attacks, and domain compromise. Putnik-24 was previously associated with the name Beryllium.Blikdata from corporate networks. A project named Botany appears focused on modular Android collection while Blik and Glare focuses on concealed storage and offline transfer. Finally, the project Chain-24 focuses onBoNeSiIts integrations with Nettacker and BoNeSi support scanning, vulnerability testing, and high-volume network traffic generation. Graphing functions help analysts visualize relationships between domains, IPs, providers,Botanytrusted cloud services to control software agents and move data from corporate networks. A project named Botany appears focused on modular Android collection while Blik and Glare focuses on concealed storage andChain-24collection while Blik and Glare focuses on concealed storage and offline transfer. Finally, the project Chain-24 focuses on anonymous procurement of hosting and other operational services needed for automatedFelix-23research and development program, with seven named projects defining its work. Two of the projects, Felix-23 and HAD, focus on target discovery, scanning, enrichment, and active testing. Another project, Putnik,Glarecorporate networks. A project named Botany appears focused on modular Android collection while Blik and Glare focuses on concealed storage and offline transfer. Finally, the project Chain-24 focuses on anonymousHADand development program, with seven named projects defining its work. Two of the projects, Felix-23 and HAD, focus on target discovery, scanning, enrichment, and active testing. Another project, Putnik, supportsInitiative-24and active testing. Another project, Putnik, supports internal-network access and credential theft. Initiative-24 studies the use of trusted cloud services to control software agents and move data from corporateNettackerIts integrations with Nettacker and BoNeSi support scanning, vulnerability testing, and high-volume network traffic generation. Graphing functions help analysts visualize relationships between domains, IPs, providers,PutnikFelix-23 and HAD, focus on target discovery, scanning, enrichment, and active testing. Another project, Putnik, supports internal-network access and credential theft. Initiative-24 studies the use of trusted cloudPutnik-24Management correspondence also requested scenarios for credential theft, printer attacks, and domain compromise. Putnik-24 was previously associated with the name Beryllium.ResponderNTLM capture with ResponderShodanFelix supplements direct scanning with data from search engines, Shodan, VirusTotal, WHOIS, malware repositories, and vulnerability databases. It then organizes material into persistent target records that combine thisVirusTotalFelix supplements direct scanning with data from search engines, Shodan, VirusTotal, WHOIS, malware repositories, and vulnerability databases. It then organizes material into persistent target records that combine this