Key judgments
- High confidenceSpetsvuzavtomatika builds; it does not operate. The leaked documents describe customer requirements, seven named development projects and a Git estate — the same role the US Treasury described in 2021, when it sanctioned the institute for research and development supporting the SVR’s cyber operations.
- Moderate confidenceSome of this tooling has probably changed hands. The seller marketed the files for eleven weeks, claimed on 27 July to have sold the mobile tools, and closed the thread on 7 August saying it had been paid. A seller’s claim is marketing, not proof of a sale.
- Moderate confidenceThe danger is assembly, not novelty. The projects stitch public components — Shodan, Nettacker, Responder, OpenVPN, SoftEther — around a 2020 vulnerability. Defenders already own the controls; what the leak shows is an intent to run them faster, at scale, with fewer people.
- Moderate confidenceRussia’s cyber capability is now most visible through its contractors, and DarkForums has become where their files surface. Three of the four Russian contractor leaks since 2023 passed through it.
- No assessmentWe cannot say who breached the institute, whether any of these tools was deployed against a real target, or who bought what was sold.
- named development projects in the leaked documents
- 7
- IP entries across 88 countries in one working file
- 2,406
- from the first sale post to “the thread is closed”
- 11 weeks
- tool named in the sale thread but absent from the published analysis
- 1
On 30 September 2026, DomainTools Investigations published the first detailed look at files stolen from Spetsvuzavtomatika, a state research institute in Rostov-on-Don that the US Treasury sanctioned in 2021 for supporting the SVR, Russia’s foreign intelligence service. The documents describe a development programme rather than a hacking unit: seven projects that, between them, cover almost every stage of an intelligence operation. This analysis adds what the published report does not have — the complete sale thread from our dark-web collection, the institute’s own account of the breach, and a tool name that appears only in the seller’s posts — and turns the documented techniques into detection content.
| Status | Finding | Source |
|---|---|---|
| Observed | A sanctioned institute’s documents describe seven development projects spanning reconnaissance, network access, cloud command and control, mobile collection and anonymous procurement. | DomainTools analysis of the leak |
| Observed | The files were marketed on Spear and DarkForums from 24 May to 7 August 2026; on 27 July the seller claimed the mobile tools were sold. | FireIntel DDW Advance collection |
| Observed | The institute confirmed an attack and an extortion demand, but said only one server in its DMZ was affected. | Institute statement, 22 May 2026 (archived) |
| Assessed | The material is authentic and the institute develops capability for the SVR rather than running operations itself. | DomainTools; US Treasury |
| Unknown | Who breached the institute and how, whether any tool was deployed operationally, and who bought what was sold. | Not established by any source |
What Spetsvuzavtomatika is
On 15 April 2021 — the day the United States formally blamed the SVR for the SolarWinds compromise — the Treasury sanctioned six Russian technology companies for supporting Russia’s intelligence services. One was the Federal State Autonomous Scientific Establishment “Scientific Research Institute Specialized Security Computing Devices and Automation”, abbreviated SVA. Treasury said it “conducted research and development in support of the SVR’s malicious cyber operations.” Its Russian name is Spetsvuzavtomatika.
Publicly, the institute presents itself as a regional information-security and software house. The leaked documents show customers that are military units, including Military Units 33949 and 64829. The Insider, citing leaked SVR correspondence, has identified unit 33949 as part of the SVR’s Department S, which supports intelligence officers operating abroad without diplomatic cover. Western governments associate the SVR’s cyber operations with the group tracked as APT29, or Cozy Bear. Nothing in the published analysis ties a specific tool to a specific APT29 operation; the link is institutional, not operational.
Seven projects, one production line
Read together, the projects form a pipeline: buy infrastructure anonymously, find and test targets, get onto a network, take the domain, control implants through ordinary cloud services, collect from phones, and move data out — some of it offline. Each stage has at least one project behind it.
| Project | What the documents describe | Built on |
|---|---|---|
| Felix-23 | Internet-facing reconnaissance and active testing: discovery, enrichment, persistent target records, credential and brute-force testing, RCE and SQL-injection checks, DDoS impact measurement | Shodan, WHOIS, search engines and malware repositories; Tor, proxies and rotating VPS nodes |
| HAD | An earlier or parallel backend: a targeting API, a VPS fleet tracked by tunnelling state and routing chain, automatic task assignment, graphing and report export | OWASP Nettacker for scanning; BoNeSi for high-volume traffic |
| Putnik | Remote Layer 2 access into a target network; spoofing and name-resolution poisoning; a lab workflow from Zerologon to Domain Admin. Previously called Beryllium | TAP-mode OpenVPN, SoftEther, Responder |
| Initiative-24 | Controlling implants and moving data through trusted cloud services so the traffic looks like business as usual — including hidden Exchange folders | Cloud storage, email, virtual-machine and serverless services |
| Botany | A modular Android collection framework: a visible app, an encrypted core and swappable modules designed to read notifications and authentication codes | HTTP, SIP, WebRTC, torrent and Matrix as command channels |
| Blik and Glare | Covert storage and offline transfer hidden inside apps that look like Sudoku, a calculator or an e-reader, unlocked by five quick taps | Protected ZIP and EPUB containers on removable media |
| Chain-24 | Research into paying anonymously for hosting, email accounts, virtual SIM cards, closed-forum access and leaked databases | Privacy-focused cryptocurrencies; BitPay and CoinGate compatibility |
Descriptions summarise DomainTools’ analysis of the leaked documents. Project status varies: some are research specifications, some have code, and DomainTools found no proof that the tools were deployed together.
Two details deserve emphasis. Putnik’s laboratory workflow uses Zerologon, CVE-2020-1472 — a flaw rated 10.0 that Microsoft patched in August 2020 and that CISA ordered federal agencies to fix within days. A project carrying a 2024 designation still treats it as a working route to Domain Admin, which says something about the networks its customers expect to meet. And Initiative-24 spells out its reasoning in its own introduction: modern security tools report incidents to the cloud, which “substantially increases the cost of potential mistakes” — so the channels to an implant should look like the cloud services a company already trusts.
Built before, for another service
None of this is a first. In 2023, Mandiant analysed files from NTC Vulkan, a Moscow contractor, and described Scan: a framework for scanning the internet for vulnerabilities, storing the results in a large target database and coordinating operators — contracted at least in part by GRU Unit 74455, the unit behind Sandworm. Felix-23 and HAD describe the same idea for the SVR. Mandiant’s caution then applies now: it “lacks evidence to prove that the capabilities we discuss have been implemented or are feasible.” The two leaks show two intelligence services commissioning the same kind of system from contractors, years apart.
What the dark web shows
DomainTools places the sale on DarkForums. Our collection holds the whole thread, and it begins somewhere else. Querying DDW Advance on 4 October 2026 for the institute’s name and the seller’s handle returns 24 results; the seller’s own posts, in order, trace an eleven-week campaign. In the captures below, links to the stolen files, the seller’s Tox contact ID and the seller’s profanity are covered with bars.

| Date | Forum | What the seller said |
|---|---|---|
| 24 May | Spear | Claims to have stolen “all the data”; offers IP data, technical documents and the Git repository; posts a sample and a Tox contact |
| 29 May | Spear | Releases four documents “because SpetsVuzAvtomatika still very bad at cyber security” |
| 8 Jun | DarkForums | “Still negotiating with several buyers”; releases one document from the institute’s Git to prove access |
| 19 Jun | DarkForums | “You buy or we will sell” — pressure aimed at the institute and at what its customers would think |
| 27 Jul | DarkForums | Claims the mobile tools were sold and names KAVLogHooker; offers remaining source code; final bids within two weeks |
| 7 Aug | DarkForums | “The thread is closed. We make our money” |
Quotations are the seller’s own words, in the seller’s English. Reposts of the same message are not listed.
The pressure in the thread is unusual. Ransomware crews threaten to publish; this seller threatened the institute’s standing with its customers — “Curious to see how your customers will think when they know the whole story.” For a contractor whose business is trust with an intelligence service, that is the sharper threat. On 8 June the seller made the same point: the institute “can imagine what their customers will do to them next.”

KAVLogHooker does not appear in the published analysis. It appears exactly twice in our entire collection, both times in copies of this post. KAV is the common shorthand for Kaspersky Anti-Virus, the Russian vendor’s product, and “evader” suggests a component that hooks or suppresses its logging; we have not seen the code, so that reading is inference. If it is right, it fits Initiative-24’s stated concern with security products that report back to the cloud. The claim that employees say “Felix works well” is the seller’s, but it is the only statement in either source that any of these tools works as intended.
The institute’s version
The institute published its own account on 22 May 2026, two days before the first public sale post we hold — which suggests the extortion demand came privately first. In its statement, now preserved by the Internet Archive, the institute says it has faced a series of attacks since 2024; that a 2026 attack by “foreign criminals” temporarily disrupted one server in its demilitarised zone; that the internal network was not affected; and that the attackers demanded payment to remove what it called “fakes” about the intrusion. It refused to pay and said it was investigating with law enforcement.
One DMZ server is hard to square with what the seller produced and DomainTools analysed: Git repository contents, a project-management spreadsheet, customer requirements and documents whose metadata carries staff email addresses and machine names. Either the DMZ server held far more than a DMZ server should, or the breach went further than the statement says.

A month after the breach, our collection picked up a job advertisement from the institute: an information-security specialist for monitoring, explicitly inviting beginners, to watch security events, give first response and escalate — on a rota of day and night shifts with two days off. The institute’s statement had said it was building up a departmental information-security centre. This is what staffing it looked like in June. One advert is not an audit, but the picture is telling: the SVR’s tool-builder was recruiting entry-level security monitoring staff to defend itself.
Contractors leak
- Russian contractor leak
- Chinese contractor leak
- 30 Mar 2023 · NTC Vulkan
Mandiant described Scan, a Moscow contractor’s internet-scanning and target-database framework contracted at least in part by GRU Unit 74455 (Sandworm) — and said it lacked evidence the capabilities were ever deployed.
- 16 Feb 2024 · i-Soon
Files from the Chinese contractor i-Soon appeared on GitHub, exposing work for China’s Ministry of Public Security and Ministry of State Security.
- 9 Oct 2025 · Okenit
A DarkForums account claimed to have hacked the SVR; the files came from Okenit, a St Petersburg contractor. DomainTools found Lemmings, a framework for manufacturing synthetic personas, and could not establish that it was deployed.
- Nov 2025 · Knownsec
A Knownsec dump appeared on GitHub; DomainTools described exploitation tooling and a target database of 378 million IP addresses.
- 7 May 2026 · Bauman
A media consortium published records from Bauman University’s Department No. 4, a training pipeline whose graduates reporting placed in GRU units 26165 (APT28) and 74455 (Sandworm). The files later circulated on DarkForums.
- 24 May 2026 · Spetsvuzavtomatika
SVA2027 advertises the institute’s files on Spear and DarkForums; the thread closes on 7 August with a claimed sale. The subject of this post.
Russia and China both build much of their cyber capability through contractors and institutes, and contractors keep leaking. Since 2023 those leaks — not government disclosures — have been the clearest public view of how state programmes are specified and built. Three of the four Russian cases passed through DarkForums: an account calling itself okenit_hackers posted Okenit’s files there in October 2025, the Bauman University records circulated there in 2026, and SVA2027 sold Spetsvuzavtomatika’s files there this summer.
The Okenit case carries a warning. Its leaker claimed to have hacked the SVR; DomainTools found the files came from a contractor connected to the Ministry of Defence and the FSB instead. Leakers inflate their targets. What sets the Spetsvuzavtomatika case apart is that the SVR link does not rest on the leaker’s word: the US government made it independently, five years earlier.
Detection and response
Nothing in the leak is a new class of attack. Its value to defenders is a clear list of what a well-resourced service has asked its contractor to automate — and every item on that list has a known control. Putnik’s documented workflow is the most concrete, so it comes first.
- Lab workflow step
- Domain compromise
- Bridge onto the LAN
TAP-mode OpenVPN or SoftEther bridges Ethernet, so a remote operator works as if plugged into the target network. Watch for: A new TAP or virtual adapter, or an OpenVPN or SoftEther service installed on a host that has no reason to run one.
- Spoof ARP, DHCP, DNS
ARP, DHCP and DNS spoofing put the operator in the path of local traffic. Watch for: Conflicting ARP replies for the gateway, a second DHCP server, DNS answers from a workstation.
- Poison names, capture NTLM
LLMNR, NBT-NS and mDNS poisoning with Responder, plus authentication coercion and printer interception, harvest NTLM authentication. Watch for: LLMNR (UDP 5355) or NBT-NS (UDP 137) answers from a non-server host; spooler RPC coercion against domain controllers.
- Find the domain controller
Domain discovery and domain-controller identification. Watch for: LDAP and DNS SRV lookups for _ldap._tcp.dc._msdcs from a host that has never made them.
- Zerologon CVE-2020-1472
The Netlogon flaw patched in August 2020 is used to take over the domain controller’s machine account. Watch for: Netlogon events 5827–5829 on domain controllers; event 4742 showing the DC’s own computer account password changed by ANONYMOUS LOGON.
- Extract NTDS, Kerberos keys
Domain credentials are pulled from NTDS and Kerberos keys recovered. Watch for: Event 4662 with the directory-replication rights from an account that is not a domain controller, or access to ntds.dit.
- Pass the hash
Commands run with stolen NTLM hashes instead of passwords. Watch for: Event 4624 logon type 9 via seclogo, or NTLM network logons to many hosts from one source in a short window.
- Collect registry
Registry data is collected from compromised hosts. Watch for: Remote Registry started on demand; reg save of the SAM, SECURITY or SYSTEM hives.
- New account, Domain Admin
A domain account is created and raised to Domain Admin. Watch for: Event 4720 (account created) followed by 4728 (added to Domain Admins) for the same account.
| Project | Technique | What the documents describe |
|---|---|---|
| Felix-23 / HAD | T1596.005Scan Databases | Target records enriched from Shodan and similar scan databases. |
| Felix-23 / HAD | T1595.002Vulnerability Scanning | Vulnerability confirmation; scanning through OWASP Nettacker. |
| Felix-23 / HAD | T1110Brute Force | Credential testing and brute-force attacks against discovered services. |
| Felix-23 / HAD | T1190Exploit Public-Facing Application | Remote-code-execution checks and SQL-injection tests. |
| Felix-23 / HAD | T1583.003Virtual Private Server | Distributed VPS nodes managed as resources, with tunnelling state and forwarded ports. |
| Felix-23 / HAD | T1090.003Multi-hop Proxy | Activity routed through Tor, proxy chains and rotating addresses. |
| Felix-23 / HAD | T1498Network Denial of Service | DDoS impact measurement; high-volume traffic through BoNeSi. |
| Putnik | T1572Protocol Tunneling | Ethernet bridged over TAP-mode OpenVPN or SoftEther for remote Layer 2 access. |
| Putnik | T1557.002ARP Cache Poisoning | ARP spoofing scenarios. |
| Putnik | T1557.003DHCP Spoofing | DHCP spoofing scenarios. |
| Putnik | T1557.001Name Resolution Poisoning and SMB Relay | LLMNR, NBT-NS and mDNS poisoning; NTLM capture with Responder. |
| Putnik | T1187Forced Authentication | Authentication coercion and printer interception. |
| Putnik | T1068Exploitation for Privilege Escalation | Zerologon, CVE-2020-1472, against the domain controller. |
| Putnik | T1003.003NTDS | NTDS extraction and Kerberos-key recovery. |
| Putnik | T1550.002Pass the Hash | Command execution with recovered hashes. |
| Putnik | T1136.002Domain Account | A domain account created and raised to Domain Admin. |
| Initiative-24 | T1102Web Service | Implants controlled through trusted public cloud services. |
| Initiative-24 | T1567.002Exfiltration to Cloud Storage | Collected data staged and moved through cloud storage. |
| Initiative-24 | T1564Hide Artifacts | Hidden Exchange folders holding instructions or data out of normal view. |
| Botany | T1517Access NotificationsMobile | Notification listeners collecting alerts, messages and authentication codes. |
| Botany | T1437.001Web ProtocolsMobile | HTTP among several command channels, alongside SIP, WebRTC and Matrix. |
| Blik and Glare | T1655MasqueradingMobile | Hidden functions inside apps posing as Sudoku, a calculator or an e-reader. |
| Blik and Glare | T1406Obfuscated Files or InformationMobile | Protected ZIP and EPUB containers for covert storage and transfer. |
| Chain-24 | T1583Acquire Infrastructure | Anonymous purchase of VPS and VDS hosting. |
| Chain-24 | T1585.002Email Accounts | Email accounts provisioned through anonymous payment. |
IDs follow MITRE ATT&CK version 19.2 and were checked against MITRE’s published data; rows marked Mobile come from the Mobile matrix. Because the documents describe capabilities rather than an intrusion, this is a map of intent, not of observed activity. SVR operators’ shift toward cloud services is also documented independently: in February 2024, CISA, the UK NCSC and partners warned that SVR actors were moving to target cloud accounts and to use residential proxies to hide.
The queries below turn Putnik’s domain-takeover steps into searches for Microsoft Sentinel, using Windows Security and System events. Each was checked with Microsoft’s Kusto language parser against the table schema; none has been run against live data for this post, so tune them before alerting.
union
(Event
| where TimeGenerated > ago(30d)
| where Source == "NETLOGON" and EventID in (5827, 5828, 5829)
| project TimeGenerated, Computer, EventID, Detail = RenderedDescription),
(SecurityEvent
| where TimeGenerated > ago(30d)
| where EventID == 4742 and SubjectUserName == "ANONYMOUS LOGON"
| project TimeGenerated, Computer, EventID, Detail = TargetUserName)SecurityEvent
| where TimeGenerated > ago(30d)
| where EventID == 4662
| where Properties has_any ("1131f6aa-9c07-11d1-f79f-00c04fc2dcd2",
"1131f6ad-9c07-11d1-f79f-00c04fc2dcd2")
| where SubjectUserName !endswith "$"
| project TimeGenerated, Computer, SubjectUserName, SubjectDomainNamelet created = SecurityEvent
| where TimeGenerated > ago(30d) and EventID == 4720
| project CreatedAt = TimeGenerated, AccountSid = TargetSid, Account = TargetUserName, CreatedBy = SubjectUserName;
SecurityEvent
| where TimeGenerated > ago(30d) and EventID == 4728 and TargetUserName == "Domain Admins"
| project AddedAt = TimeGenerated, AccountSid = MemberSid, AddedBy = SubjectUserName, Computer
| join kind=inner created on AccountSid
| where AddedAt between (CreatedAt .. CreatedAt + 1d)
| project CreatedAt, AddedAt, Account, CreatedBy, AddedBy, Computer- Confirm Netlogon secure-channel enforcement on every domain controller and alert on events 5827 to 5829; a Zerologon attempt against a patched DC still leaves a trace.
- Disable LLMNR and NetBIOS over TCP/IP through Group Policy and require SMB signing. That removes most of what Putnik’s poisoning and relay scenarios depend on.
- Treat a new TAP or virtual network adapter, or an OpenVPN or SoftEther service, on a server or workstation outside the approved VPN estate as an incident until explained.
- For cloud command and control, inventory OAuth applications and mailbox permissions, and enable mailbox auditing: a hidden folder is still a folder that was created.
- On managed Android devices, restrict which apps may hold accessibility and notification-listener permissions — the two hooks Botany is built around.
Indicators
There are no network indicators to publish. The leak’s 2,406-address file has not been released, and DomainTools describes it as a mix of reconnaissance targets, vulnerable systems, proxies and scanning nodes — most of the addresses would be victims, not attackers, so blocking them would be wrong. What defenders can use is behaviour: the technique map, as layers for MITRE’s ATT&CK Navigator, and seven Sigma rules for the Windows activity Putnik’s domain takeover would leave — vulnerable Netlogon connections, a computer account changed by an anonymous logon, directory replication from a non-DC account, a registry hive saved with reg.exe, a pass-the-hash logon, a member added to Domain Admins, and OpenVPN or SoftEther bridge tooling.
Every rule passes sigma-cli’s checks and converts to Splunk SPL and to Microsoft Sentinel KQL, and the converted KQL was checked with Microsoft’s Kusto parser. Each rule is tagged with the most specific technique it detects, which can be narrower than the table above: the DCSync rule is T1003.006 within credential dumping. Like the queries, the rules are marked experimental and have not been run against live data for this post; the archive’s README lists the log sources each one needs.
Detection content
- Sigma rules 7 experimental Windows rules, with a README on the logs each one needs
- Enterprise layer 21 Enterprise techniques, each annotated with the project that documents it
- Mobile layer 4 Mobile techniques from Botany and Blik and Glare
Method, confidence and limits
We have not seen the leaked archive. Descriptions of the projects, the IP file and the document metadata come from DomainTools’ analysis. The sale thread, the KAVLogHooker reference and the job advertisement come from FireIntel’s DDW Advance collection, queried on 4 October 2026. The institute’s statement was read from the Internet Archive’s copy rather than from the sanctioned institute’s own site. Treasury, Mandiant, The Insider, the Congressional Research Service and CISA supply the institutional and historical context, each cited where it is used.
Confidence follows common intelligence practice. High confidence means the judgment rests on direct observation or on several independent sources that agree. Moderate means the evidence is credible but incomplete, or comes from one source or from a party with a motive to exaggerate. “No assessment” means we lack an independent basis to judge.
Screenshots were captured from the FireIntel console on 4 October 2026. Links to the stolen files, the seller’s Tox contact ID and the seller’s profanity are covered with bars; beyond choosing and ordering which of the seller’s posts to show, nothing in them was altered.
Sources
- DomainTools Investigations — Spetsvuzavtomatika Leak Exposes an SVR Cyber Development Ecosystem (30 September 2026)
- US Department of the Treasury — sanctions on Russian technology companies supporting the intelligence services (15 April 2021)
- Spetsvuzavtomatika — “Важная новость” (Important news), 22 May 2026, Internet Archive copy
- Mandiant — analysis of leaked NTC Vulkan documents (30 March 2023)
- DomainTools Investigations — Lemmings: Russian Industrialized Persona Provisioning and Management for Active Measures Campaigns (16 September 2026)
- DomainTools Investigations — Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline (26 August 2026)
- DomainTools Investigations — the Knownsec leak and China’s contractor-driven cyber espionage ecosystem (9 January 2026)
- The Insider — “Morality and ethics should play no part”: leaks reveal how Russia’s foreign intelligence agency runs disinformation campaigns in the West (4 July 2024)
- Congressional Research Service — Russian Cyber Units (IF11718)
- CISA, NCSC and partners — SVR Cyber Actors Adapt Tactics for Initial Cloud Access (February 2024)