{
  "name": "Spetsvuzavtomatika leak — documented capabilities (Mobile)",
  "versions": {
    "attack": "19",
    "navigator": "5.3.2",
    "layer": "4.5"
  },
  "domain": "mobile-attack",
  "description": "Techniques described in the leaked Spetsvuzavtomatika project documents, as analysed by DomainTools Investigations (30 Sep 2026) and mapped by FireIntel Threat Research. A map of documented intent, not of observed intrusions. Source post: https://fireintel.net/blog/spetsvuzavtomatika-leak-svr-cyber-development",
  "sorting": 0,
  "hideDisabled": false,
  "techniques": [
    {
      "techniqueID": "T1517",
      "color": "#7c86f0",
      "comment": "Botany: Notification listeners collecting alerts, messages and authentication codes.",
      "enabled": true
    },
    {
      "techniqueID": "T1437.001",
      "color": "#7c86f0",
      "comment": "Botany: HTTP among several command channels, alongside SIP, WebRTC and Matrix.",
      "enabled": true
    },
    {
      "techniqueID": "T1655",
      "color": "#7c86f0",
      "comment": "Blik and Glare: Hidden functions inside apps posing as Sudoku, a calculator or an e-reader.",
      "enabled": true
    },
    {
      "techniqueID": "T1406",
      "color": "#7c86f0",
      "comment": "Blik and Glare: Protected ZIP and EPUB containers for covert storage and transfer.",
      "enabled": true
    }
  ],
  "gradient": {
    "colors": [
      "#ffffff",
      "#7c86f0"
    ],
    "minValue": 0,
    "maxValue": 1
  },
  "legendItems": [
    {
      "label": "Documented in the leaked project files",
      "color": "#7c86f0"
    }
  ],
  "showTacticRowBackground": false,
  "selectTechniquesAcrossTactics": true,
  "selectSubtechniquesWithParent": false
}