Inside an SVR contractor’s workshop, and how its tools were sold

Seven projects from a sanctioned Rostov-on-Don institute cover almost every stage of an intelligence operation. Our dark-web collection shows how the files were marketed for eleven weeks — and names a tool the published analysis does not.

Key judgments

  • High confidenceSpetsvuzavtomatika builds; it does not operate. The leaked documents describe customer requirements, seven named development projects and a Git estate — the same role the US Treasury described in 2021, when it sanctioned the institute for research and development supporting the SVR’s cyber operations.
  • Moderate confidenceSome of this tooling has probably changed hands. The seller marketed the files for eleven weeks, claimed on 27 July to have sold the mobile tools, and closed the thread on 7 August saying it had been paid. A seller’s claim is marketing, not proof of a sale.
  • Moderate confidenceThe danger is assembly, not novelty. The projects stitch public components — Shodan, Nettacker, Responder, OpenVPN, SoftEther — around a 2020 vulnerability. Defenders already own the controls; what the leak shows is an intent to run them faster, at scale, with fewer people.
  • Moderate confidenceRussia’s cyber capability is now most visible through its contractors, and DarkForums has become where their files surface. Three of the four Russian contractor leaks since 2023 passed through it.
  • No assessmentWe cannot say who breached the institute, whether any of these tools was deployed against a real target, or who bought what was sold.
named development projects in the leaked documents
7
IP entries across 88 countries in one working file
2,406
from the first sale post to “the thread is closed”
11 weeks
tool named in the sale thread but absent from the published analysis
1

On 30 September 2026, DomainTools Investigations published the first detailed look at files stolen from Spetsvuzavtomatika, a state research institute in Rostov-on-Don that the US Treasury sanctioned in 2021 for supporting the SVR, Russia’s foreign intelligence service. The documents describe a development programme rather than a hacking unit: seven projects that, between them, cover almost every stage of an intelligence operation. This analysis adds what the published report does not have — the complete sale thread from our dark-web collection, the institute’s own account of the breach, and a tool name that appears only in the seller’s posts — and turns the documented techniques into detection content.

Evidence assessment
StatusFindingSource
ObservedA sanctioned institute’s documents describe seven development projects spanning reconnaissance, network access, cloud command and control, mobile collection and anonymous procurement.DomainTools analysis of the leak
ObservedThe files were marketed on Spear and DarkForums from 24 May to 7 August 2026; on 27 July the seller claimed the mobile tools were sold.FireIntel DDW Advance collection
ObservedThe institute confirmed an attack and an extortion demand, but said only one server in its DMZ was affected.Institute statement, 22 May 2026 (archived)
AssessedThe material is authentic and the institute develops capability for the SVR rather than running operations itself.DomainTools; US Treasury
UnknownWho breached the institute and how, whether any tool was deployed operationally, and who bought what was sold.Not established by any source

What Spetsvuzavtomatika is

On 15 April 2021 — the day the United States formally blamed the SVR for the SolarWinds compromise — the Treasury sanctioned six Russian technology companies for supporting Russia’s intelligence services. One was the Federal State Autonomous Scientific Establishment “Scientific Research Institute Specialized Security Computing Devices and Automation”, abbreviated SVA. Treasury said it “conducted research and development in support of the SVR’s malicious cyber operations.” Its Russian name is Spetsvuzavtomatika.

Publicly, the institute presents itself as a regional information-security and software house. The leaked documents show customers that are military units, including Military Units 33949 and 64829. The Insider, citing leaked SVR correspondence, has identified unit 33949 as part of the SVR’s Department S, which supports intelligence officers operating abroad without diplomatic cover. Western governments associate the SVR’s cyber operations with the group tracked as APT29, or Cozy Bear. Nothing in the published analysis ties a specific tool to a specific APT29 operation; the link is institutional, not operational.

Seven projects, one production line

Read together, the projects form a pipeline: buy infrastructure anonymously, find and test targets, get onto a network, take the domain, control implants through ordinary cloud services, collect from phones, and move data out — some of it offline. Each stage has at least one project behind it.

Capability coverage · analyst reconstruction
Which stages of an intelligence operation each Spetsvuzavtomatika project coversSeven projects mapped across six stages, from buying infrastructure to moving data out. Chain-24 buys infrastructure; HAD and Felix-23 find and test targets; Putnik gets in and moves inside a network; Initiative-24 controls agents and moves data out through cloud services; Botany collects from Android phones; Blik and Glare move data offline. Every stage is covered by at least one project.BuyinfrastructureFindtargetsGet inMoveinsideCollectMove dataoutProjectChain-24anonymous procurementChain-24: Buy infrastructureHADtargeting backend, VPS fleetHAD: Buy infrastructure, Find targets, Get inFelix-23recon and active testingFelix-23: Find targets, Get inPutnikLayer 2 access, AD takeoverPutnik: Get in, Move inside, CollectInitiative-24cloud-hosted agent controlInitiative-24: Move inside, Collect, Move data outBotanyAndroid collectionBotany: Collect, Move data outBlik and Glarecovert offline transferBlik and Glare: Move data outCoverage as the documents describe it — not evidence that every tool was finished, deployed or used together.
Built from DomainTools’ description of each project. The bars show where each project’s documents place it, not where it was used. Felix-23 and HAD overlap because HAD appears to be an earlier or parallel backend for the same capability.
The seven projects and what they are built on
ProjectWhat the documents describeBuilt on
Felix-23Internet-facing reconnaissance and active testing: discovery, enrichment, persistent target records, credential and brute-force testing, RCE and SQL-injection checks, DDoS impact measurementShodan, WHOIS, search engines and malware repositories; Tor, proxies and rotating VPS nodes
HADAn earlier or parallel backend: a targeting API, a VPS fleet tracked by tunnelling state and routing chain, automatic task assignment, graphing and report exportOWASP Nettacker for scanning; BoNeSi for high-volume traffic
PutnikRemote Layer 2 access into a target network; spoofing and name-resolution poisoning; a lab workflow from Zerologon to Domain Admin. Previously called BerylliumTAP-mode OpenVPN, SoftEther, Responder
Initiative-24Controlling implants and moving data through trusted cloud services so the traffic looks like business as usual — including hidden Exchange foldersCloud storage, email, virtual-machine and serverless services
BotanyA modular Android collection framework: a visible app, an encrypted core and swappable modules designed to read notifications and authentication codesHTTP, SIP, WebRTC, torrent and Matrix as command channels
Blik and GlareCovert storage and offline transfer hidden inside apps that look like Sudoku, a calculator or an e-reader, unlocked by five quick tapsProtected ZIP and EPUB containers on removable media
Chain-24Research into paying anonymously for hosting, email accounts, virtual SIM cards, closed-forum access and leaked databasesPrivacy-focused cryptocurrencies; BitPay and CoinGate compatibility

Descriptions summarise DomainTools’ analysis of the leaked documents. Project status varies: some are research specifications, some have code, and DomainTools found no proof that the tools were deployed together.

Two details deserve emphasis. Putnik’s laboratory workflow uses Zerologon, CVE-2020-1472 — a flaw rated 10.0 that Microsoft patched in August 2020 and that CISA ordered federal agencies to fix within days. A project carrying a 2024 designation still treats it as a working route to Domain Admin, which says something about the networks its customers expect to meet. And Initiative-24 spells out its reasoning in its own introduction: modern security tools report incidents to the cloud, which “substantially increases the cost of potential mistakes” — so the channels to an implant should look like the cloud services a company already trusts.

Built before, for another service

None of this is a first. In 2023, Mandiant analysed files from NTC Vulkan, a Moscow contractor, and described Scan: a framework for scanning the internet for vulnerabilities, storing the results in a large target database and coordinating operators — contracted at least in part by GRU Unit 74455, the unit behind Sandworm. Felix-23 and HAD describe the same idea for the SVR. Mandiant’s caution then applies now: it “lacks evidence to prove that the capabilities we discuss have been implemented or are feasible.” The two leaks show two intelligence services commissioning the same kind of system from contractors, years apart.

What the dark web shows

DomainTools places the sale on DarkForums. Our collection holds the whole thread, and it begins somewhere else. Querying DDW Advance on 4 October 2026 for the institute’s name and the seller’s handle returns 24 results; the seller’s own posts, in order, trace an eleven-week campaign. In the captures below, links to the stolen files, the seller’s Tox contact ID and the seller’s profanity are covered with bars.

Source: FireIntel DDW Advance · captured 4 Oct 2026Open full image
DDW Advance results for the seller SVA2027: six posts from 24 May to 7 August 2026 on the Spear and DarkForums forums, from the first offer of the institute’s data to the closing post claiming payment
SVA2027’s posts in date order, from the first offer on 24 May to “The thread is closed” on 7 August. File links, the Tox contact ID and profanity are covered.
The sale, post by post
DateForumWhat the seller said
24 MaySpearClaims to have stolen “all the data”; offers IP data, technical documents and the Git repository; posts a sample and a Tox contact
29 MaySpearReleases four documents “because SpetsVuzAvtomatika still very bad at cyber security”
8 JunDarkForums“Still negotiating with several buyers”; releases one document from the institute’s Git to prove access
19 JunDarkForums“You buy or we will sell” — pressure aimed at the institute and at what its customers would think
27 JulDarkForumsClaims the mobile tools were sold and names KAVLogHooker; offers remaining source code; final bids within two weeks
7 AugDarkForums“The thread is closed. We make our money”

Quotations are the seller’s own words, in the seller’s English. Reposts of the same message are not listed.

The pressure in the thread is unusual. Ransomware crews threaten to publish; this seller threatened the institute’s standing with its customers — “Curious to see how your customers will think when they know the whole story.” For a contractor whose business is trust with an intelligence service, that is the sharper threat. On 8 June the seller made the same point: the institute “can imagine what their customers will do to them next.”

Source: FireIntel DDW Advance · DarkForums · 27 Jul 2026Open full image
The 27 July 2026 DarkForums post by SVA2027 claiming the institute’s mobile tools were sold, naming the KAVLogHooker evader, saying employees report Felix works well, and setting a two-week deadline for final bids
The 27 July post. It claims a completed sale of the mobile tools, names KAVLogHooker, and says the institute’s own employees report that Felix “works well”. The file link and an insult are covered.

KAVLogHooker does not appear in the published analysis. It appears exactly twice in our entire collection, both times in copies of this post. KAV is the common shorthand for Kaspersky Anti-Virus, the Russian vendor’s product, and “evader” suggests a component that hooks or suppresses its logging; we have not seen the code, so that reading is inference. If it is right, it fits Initiative-24’s stated concern with security products that report back to the cloud. The claim that employees say “Felix works well” is the seller’s, but it is the only statement in either source that any of these tools works as intended.

The institute’s version

The institute published its own account on 22 May 2026, two days before the first public sale post we hold — which suggests the extortion demand came privately first. In its statement, now preserved by the Internet Archive, the institute says it has faced a series of attacks since 2024; that a 2026 attack by “foreign criminals” temporarily disrupted one server in its demilitarised zone; that the internal network was not affected; and that the attackers demanded payment to remove what it called “fakes” about the intrusion. It refused to pay and said it was investigating with law enforcement.

One DMZ server is hard to square with what the seller produced and DomainTools analysed: Git repository contents, a project-management spreadsheet, customer requirements and documents whose metadata carries staff email addresses and machine names. Either the DMZ server held far more than a DMZ server should, or the breach went further than the statement says.

Source: FireIntel DDW Advance · captured 4 Oct 2026Open full image
A June 2026 job advertisement from Spetsvuzavtomatika in Rostov-on-Don for an entry-level information security monitoring specialist, salary from 50,000 roubles
A job advertisement aggregated on 23 June 2026 from the hh.ru jobs site: an entry-level information-security monitoring specialist in Rostov-on-Don, from 50,000 roubles a month, on a day-and-night shift rota.

A month after the breach, our collection picked up a job advertisement from the institute: an information-security specialist for monitoring, explicitly inviting beginners, to watch security events, give first response and escalate — on a rota of day and night shifts with two days off. The institute’s statement had said it was building up a departmental information-security centre. This is what staffing it looked like in June. One advert is not an audit, but the picture is telling: the SVR’s tool-builder was recruiting entry-level security monitoring staff to defend itself.

Contractors leak

Contractor leaks · public reporting and FireIntel collection
  • Russian contractor leak
  • Chinese contractor leak
Contractor leaks that exposed state cyber programmes, 2023 to 2026Two lanes, Russia and China. Russian leaks: NTC Vulkan in March 2023, Okenit in October 2025, Bauman University on 7 May 2026 and Spetsvuzavtomatika on 24 May 2026. Chinese leaks: i-Soon in February 2024 and Knownsec in November 2025.2023202420252026RussiaChina1NTC VulkanGRU2i-SoonMPS, MSS3OkenitMoD, FSB4Knownsecstate-aligned5BaumanGRU training6SpetsvuzavtomatikaSVR
  1. 30 Mar 2023 · NTC Vulkan

    Mandiant described Scan, a Moscow contractor’s internet-scanning and target-database framework contracted at least in part by GRU Unit 74455 (Sandworm) — and said it lacked evidence the capabilities were ever deployed.

  2. 16 Feb 2024 · i-Soon

    Files from the Chinese contractor i-Soon appeared on GitHub, exposing work for China’s Ministry of Public Security and Ministry of State Security.

  3. 9 Oct 2025 · Okenit

    A DarkForums account claimed to have hacked the SVR; the files came from Okenit, a St Petersburg contractor. DomainTools found Lemmings, a framework for manufacturing synthetic personas, and could not establish that it was deployed.

  4. Nov 2025 · Knownsec

    A Knownsec dump appeared on GitHub; DomainTools described exploitation tooling and a target database of 378 million IP addresses.

  5. 7 May 2026 · Bauman

    A media consortium published records from Bauman University’s Department No. 4, a training pipeline whose graduates reporting placed in GRU units 26165 (APT28) and 74455 (Sandworm). The files later circulated on DarkForums.

  6. 24 May 2026 · Spetsvuzavtomatika

    SVA2027 advertises the institute’s files on Spear and DarkForums; the thread closes on 7 August with a claimed sale. The subject of this post.

Each marker is the date a contractor’s files first surfaced publicly. The Spetsvuzavtomatika date comes from our collection; the others from the reports listed under Sources.

Russia and China both build much of their cyber capability through contractors and institutes, and contractors keep leaking. Since 2023 those leaks — not government disclosures — have been the clearest public view of how state programmes are specified and built. Three of the four Russian cases passed through DarkForums: an account calling itself okenit_hackers posted Okenit’s files there in October 2025, the Bauman University records circulated there in 2026, and SVA2027 sold Spetsvuzavtomatika’s files there this summer.

The Okenit case carries a warning. Its leaker claimed to have hacked the SVR; DomainTools found the files came from a contractor connected to the Ministry of Defence and the FSB instead. Leakers inflate their targets. What sets the Spetsvuzavtomatika case apart is that the SVR link does not rest on the leaker’s word: the US government made it independently, five years earlier.

Detection and response

Nothing in the leak is a new class of attack. Its value to defenders is a clear list of what a well-resourced service has asked its contractor to automate — and every item on that list has a known control. Putnik’s documented workflow is the most concrete, so it comes first.

Putnik laboratory workflow · analyst reconstruction
  • Lab workflow step
  • Domain compromise
The Putnik laboratory workflow, from a Layer 2 bridge to Domain AdminNine steps in three phases. Get on the wire: bridge onto the LAN, spoof ARP, DHCP and DNS, poison name resolution and capture NTLM. Take the domain: find the domain controller, exploit Zerologon, extract NTDS and Kerberos keys. Hold and spread: pass the hash, collect registry data, create an account and raise it to Domain Admin.Get on the wireTake the domainHold and spread1Bridge onto the LAN2Spoof ARP, DHCP, DNS3Poison names,capture NTLM4Find the domaincontroller5ZerologonCVE-2020-14726Extract NTDS,Kerberos keys7Pass the hash8Collect registry9New account,Domain AdminA laboratory workflow documented in the leak (6.pdf), not a recorded intrusion.
  1. Bridge onto the LAN

    TAP-mode OpenVPN or SoftEther bridges Ethernet, so a remote operator works as if plugged into the target network. Watch for: A new TAP or virtual adapter, or an OpenVPN or SoftEther service installed on a host that has no reason to run one.

  2. Spoof ARP, DHCP, DNS

    ARP, DHCP and DNS spoofing put the operator in the path of local traffic. Watch for: Conflicting ARP replies for the gateway, a second DHCP server, DNS answers from a workstation.

  3. Poison names, capture NTLM

    LLMNR, NBT-NS and mDNS poisoning with Responder, plus authentication coercion and printer interception, harvest NTLM authentication. Watch for: LLMNR (UDP 5355) or NBT-NS (UDP 137) answers from a non-server host; spooler RPC coercion against domain controllers.

  4. Find the domain controller

    Domain discovery and domain-controller identification. Watch for: LDAP and DNS SRV lookups for _ldap._tcp.dc._msdcs from a host that has never made them.

  5. Zerologon CVE-2020-1472

    The Netlogon flaw patched in August 2020 is used to take over the domain controller’s machine account. Watch for: Netlogon events 5827–5829 on domain controllers; event 4742 showing the DC’s own computer account password changed by ANONYMOUS LOGON.

  6. Extract NTDS, Kerberos keys

    Domain credentials are pulled from NTDS and Kerberos keys recovered. Watch for: Event 4662 with the directory-replication rights from an account that is not a domain controller, or access to ntds.dit.

  7. Pass the hash

    Commands run with stolen NTLM hashes instead of passwords. Watch for: Event 4624 logon type 9 via seclogo, or NTLM network logons to many hosts from one source in a short window.

  8. Collect registry

    Registry data is collected from compromised hosts. Watch for: Remote Registry started on demand; reg save of the SAM, SECURITY or SYSTEM hives.

  9. New account, Domain Admin

    A domain account is created and raised to Domain Admin. Watch for: Event 4720 (account created) followed by 4728 (added to Domain Admins) for the same account.

Steps from the Putnik scenarios and the 6.pdf laboratory workflow described by DomainTools, each paired with the Windows telemetry that would show it.
Techniques the documents describe, by project
ProjectTechniqueWhat the documents describe
Felix-23 / HADT1596.005Scan DatabasesTarget records enriched from Shodan and similar scan databases.
Felix-23 / HADT1595.002Vulnerability ScanningVulnerability confirmation; scanning through OWASP Nettacker.
Felix-23 / HADT1110Brute ForceCredential testing and brute-force attacks against discovered services.
Felix-23 / HADT1190Exploit Public-Facing ApplicationRemote-code-execution checks and SQL-injection tests.
Felix-23 / HADT1583.003Virtual Private ServerDistributed VPS nodes managed as resources, with tunnelling state and forwarded ports.
Felix-23 / HADT1090.003Multi-hop ProxyActivity routed through Tor, proxy chains and rotating addresses.
Felix-23 / HADT1498Network Denial of ServiceDDoS impact measurement; high-volume traffic through BoNeSi.
PutnikT1572Protocol TunnelingEthernet bridged over TAP-mode OpenVPN or SoftEther for remote Layer 2 access.
PutnikT1557.002ARP Cache PoisoningARP spoofing scenarios.
PutnikT1557.003DHCP SpoofingDHCP spoofing scenarios.
PutnikT1557.001Name Resolution Poisoning and SMB RelayLLMNR, NBT-NS and mDNS poisoning; NTLM capture with Responder.
PutnikT1187Forced AuthenticationAuthentication coercion and printer interception.
PutnikT1068Exploitation for Privilege EscalationZerologon, CVE-2020-1472, against the domain controller.
PutnikT1003.003NTDSNTDS extraction and Kerberos-key recovery.
PutnikT1550.002Pass the HashCommand execution with recovered hashes.
PutnikT1136.002Domain AccountA domain account created and raised to Domain Admin.
Initiative-24T1102Web ServiceImplants controlled through trusted public cloud services.
Initiative-24T1567.002Exfiltration to Cloud StorageCollected data staged and moved through cloud storage.
Initiative-24T1564Hide ArtifactsHidden Exchange folders holding instructions or data out of normal view.
BotanyT1517Access NotificationsMobileNotification listeners collecting alerts, messages and authentication codes.
BotanyT1437.001Web ProtocolsMobileHTTP among several command channels, alongside SIP, WebRTC and Matrix.
Blik and GlareT1655MasqueradingMobileHidden functions inside apps posing as Sudoku, a calculator or an e-reader.
Blik and GlareT1406Obfuscated Files or InformationMobileProtected ZIP and EPUB containers for covert storage and transfer.
Chain-24T1583Acquire InfrastructureAnonymous purchase of VPS and VDS hosting.
Chain-24T1585.002Email AccountsEmail accounts provisioned through anonymous payment.

IDs follow MITRE ATT&CK version 19.2 and were checked against MITRE’s published data; rows marked Mobile come from the Mobile matrix. Because the documents describe capabilities rather than an intrusion, this is a map of intent, not of observed activity. SVR operators’ shift toward cloud services is also documented independently: in February 2024, CISA, the UK NCSC and partners warned that SVR actors were moving to target cloud accounts and to use residential proxies to hide.

The queries below turn Putnik’s domain-takeover steps into searches for Microsoft Sentinel, using Windows Security and System events. Each was checked with Microsoft’s Kusto language parser against the table schema; none has been run against live data for this post, so tune them before alerting.

Zerologon: vulnerable Netlogon connections and DC machine-account resetsKQL
union
  (Event
    | where TimeGenerated > ago(30d)
    | where Source == "NETLOGON" and EventID in (5827, 5828, 5829)
    | project TimeGenerated, Computer, EventID, Detail = RenderedDescription),
  (SecurityEvent
    | where TimeGenerated > ago(30d)
    | where EventID == 4742 and SubjectUserName == "ANONYMOUS LOGON"
    | project TimeGenerated, Computer, EventID, Detail = TargetUserName)
Directory replication requested by an account that is not a domain controllerKQL
SecurityEvent
| where TimeGenerated > ago(30d)
| where EventID == 4662
| where Properties has_any ("1131f6aa-9c07-11d1-f79f-00c04fc2dcd2",
                            "1131f6ad-9c07-11d1-f79f-00c04fc2dcd2")
| where SubjectUserName !endswith "$"
| project TimeGenerated, Computer, SubjectUserName, SubjectDomainName
An account created and added to Domain Admins within a dayKQL
let created = SecurityEvent
  | where TimeGenerated > ago(30d) and EventID == 4720
  | project CreatedAt = TimeGenerated, AccountSid = TargetSid, Account = TargetUserName, CreatedBy = SubjectUserName;
SecurityEvent
| where TimeGenerated > ago(30d) and EventID == 4728 and TargetUserName == "Domain Admins"
| project AddedAt = TimeGenerated, AccountSid = MemberSid, AddedBy = SubjectUserName, Computer
| join kind=inner created on AccountSid
| where AddedAt between (CreatedAt .. CreatedAt + 1d)
| project CreatedAt, AddedAt, Account, CreatedBy, AddedBy, Computer
  • Confirm Netlogon secure-channel enforcement on every domain controller and alert on events 5827 to 5829; a Zerologon attempt against a patched DC still leaves a trace.
  • Disable LLMNR and NetBIOS over TCP/IP through Group Policy and require SMB signing. That removes most of what Putnik’s poisoning and relay scenarios depend on.
  • Treat a new TAP or virtual network adapter, or an OpenVPN or SoftEther service, on a server or workstation outside the approved VPN estate as an incident until explained.
  • For cloud command and control, inventory OAuth applications and mailbox permissions, and enable mailbox auditing: a hidden folder is still a folder that was created.
  • On managed Android devices, restrict which apps may hold accessibility and notification-listener permissions — the two hooks Botany is built around.

Indicators

There are no network indicators to publish. The leak’s 2,406-address file has not been released, and DomainTools describes it as a mix of reconnaissance targets, vulnerable systems, proxies and scanning nodes — most of the addresses would be victims, not attackers, so blocking them would be wrong. What defenders can use is behaviour: the technique map, as layers for MITRE’s ATT&CK Navigator, and seven Sigma rules for the Windows activity Putnik’s domain takeover would leave — vulnerable Netlogon connections, a computer account changed by an anonymous logon, directory replication from a non-DC account, a registry hive saved with reg.exe, a pass-the-hash logon, a member added to Domain Admins, and OpenVPN or SoftEther bridge tooling.

Every rule passes sigma-cli’s checks and converts to Splunk SPL and to Microsoft Sentinel KQL, and the converted KQL was checked with Microsoft’s Kusto parser. Each rule is tagged with the most specific technique it detects, which can be narrower than the table above: the DCSync rule is T1003.006 within credential dumping. Like the queries, the rules are marked experimental and have not been run against live data for this post; the archive’s README lists the log sources each one needs.

Detection content

Method, confidence and limits

We have not seen the leaked archive. Descriptions of the projects, the IP file and the document metadata come from DomainTools’ analysis. The sale thread, the KAVLogHooker reference and the job advertisement come from FireIntel’s DDW Advance collection, queried on 4 October 2026. The institute’s statement was read from the Internet Archive’s copy rather than from the sanctioned institute’s own site. Treasury, Mandiant, The Insider, the Congressional Research Service and CISA supply the institutional and historical context, each cited where it is used.

Confidence follows common intelligence practice. High confidence means the judgment rests on direct observation or on several independent sources that agree. Moderate means the evidence is credible but incomplete, or comes from one source or from a party with a motive to exaggerate. “No assessment” means we lack an independent basis to judge.

Screenshots were captured from the FireIntel console on 4 October 2026. Links to the stolen files, the seller’s Tox contact ID and the seller’s profanity are covered with bars; beyond choosing and ordering which of the seller’s posts to show, nothing in them was altered.

Sources