Leak Reveals Russian Institute’s Apparent SVR-Linked Cyber Development Ecosystem

· Original article ↗

Summary

Leaked Spetsvuzavtomatika documents describe tools for reconnaissance, network access, credential theft, data collection and covert operations. The files appear authentic, but do not prove that every capability was deployed or identify how the leak occurred.

Key points

  • DomainTools assesses with high confidence that SVA2027 possessed authentic institute material. The institute acknowledged an attack but denied an internal-network compromise; the original intrusion and access method remain unconfirmed.
  • Felix-23 and HAD are described as platforms for reconnaissance, target tracking, scanning and active testing, using proxies, TOR and distributed infrastructure to obscure activity.
  • Putnik is designed to bridge operators into target networks and support credential capture, lateral movement and privilege escalation; leaked material includes a Zerologon exploitation workflow.
  • Initiative-24 examines using trusted cloud services to control agents, stage data and extract information from corporate networks while blending into ordinary traffic.
  • Other projects include Botany, a likely modular Android collection tool, and Blik and Glare, utilities for concealed storage and offline data transfer.
  • The documents describe a broad cyber-espionage development program, but do not establish that all tools were completed, deployed or used together.

Article Details

Attack Vectors
  • Felix-23 and HAD are designed to discover and track internet-facing targets, test vulnerabilities and credentials, and coordinate scanning through proxies and VPS nodes. The documents do not establish that every capability was deployed.
  • Putnik documentation describes bridging an operator into a target network with TAP-mode OpenVPN and SoftEther, then using spoofing, name-resolution poisoning, NTLM capture, and SMB access. A documented laboratory workflow includes Zerologon exploitation, credential extraction, pass-the-hash, account creation, and Domain Admin elevation.
  • Initiative-24 researches using trusted cloud services to control agents inside corporate networks, stage collected data, and transfer it out while blending with normal traffic.
  • Botany's documented Android design combines a visible application, encrypted core, and interchangeable collection modules; its full runtime code was not available.
  • Blik and Glare documentation describes camouflage applications and protected containers for concealed storage and offline transfer.

MITRE ATT&CK

CVE

Products

Tools

BerylliumManagement correspondence also requested scenarios for credential theft, printer attacks, and domain compromise. Putnik-24 was previously associated with the name Beryllium.Blikdata from corporate networks. A project named Botany appears focused on modular Android collection while Blik and Glare focuses on concealed storage and offline transfer. Finally, the project Chain-24 focuses onBoNeSiIts integrations with Nettacker and BoNeSi support scanning, vulnerability testing, and high-volume network traffic generation. Graphing functions help analysts visualize relationships between domains, IPs, providers,Botanytrusted cloud services to control software agents and move data from corporate networks. A project named Botany appears focused on modular Android collection while Blik and Glare focuses on concealed storage andChain-24collection while Blik and Glare focuses on concealed storage and offline transfer. Finally, the project Chain-24 focuses on anonymous procurement of hosting and other operational services needed for automatedFelix-23research and development program, with seven named projects defining its work. Two of the projects, Felix-23 and HAD, focus on target discovery, scanning, enrichment, and active testing. Another project, Putnik,Glarecorporate networks. A project named Botany appears focused on modular Android collection while Blik and Glare focuses on concealed storage and offline transfer. Finally, the project Chain-24 focuses on anonymousHADand development program, with seven named projects defining its work. Two of the projects, Felix-23 and HAD, focus on target discovery, scanning, enrichment, and active testing. Another project, Putnik, supportsInitiative-24and active testing. Another project, Putnik, supports internal-network access and credential theft. Initiative-24 studies the use of trusted cloud services to control software agents and move data from corporateNettackerIts integrations with Nettacker and BoNeSi support scanning, vulnerability testing, and high-volume network traffic generation. Graphing functions help analysts visualize relationships between domains, IPs, providers,PutnikFelix-23 and HAD, focus on target discovery, scanning, enrichment, and active testing. Another project, Putnik, supports internal-network access and credential theft. Initiative-24 studies the use of trusted cloudPutnik-24Management correspondence also requested scenarios for credential theft, printer attacks, and domain compromise. Putnik-24 was previously associated with the name Beryllium.ResponderNTLM capture with ResponderShodanFelix supplements direct scanning with data from search engines, Shodan, VirusTotal, WHOIS, malware repositories, and vulnerability databases. It then organizes material into persistent target records that combine thisVirusTotalFelix supplements direct scanning with data from search engines, Shodan, VirusTotal, WHOIS, malware repositories, and vulnerability databases. It then organizes material into persistent target records that combine this

Countries

Industries

Related Articles