Executive summary
The Spetsvuzavtomatika leak found on the darknet exposes a broad Russian cyber research and development program, with seven named projects defining its work. Two of the projects, Felix-23 and HAD, focus on target discovery, scanning, enrichment, and active testing. Another project, Putnik, supports internal-network access and credential theft. Initiative-24 studies the use of trusted cloud services to control software agents and move data from corporate networks. A project named Botany appears focused on modular Android collection while Blik and Glare focuses on concealed storage and offline transfer. Finally, the project Chain-24 focuses on anonymous procurement of hosting and other operational services needed for automated campaigns.
Based on the information contained in the leak, the strongest assessment is that Spetsvuzavtomatika functions as a developer rather than a conventional front-line intrusion group. The documents do not prove that every exposed tool was deployed or used together, but they show a development environment capable of supporting most stages of cyber-enabled intelligence collection with automation.
The collection and the user SVA2027’s possession of authentic samples are assessed with high confidence, while the original breach occurrence and how it happened are still in question today and cannot be assessed with certainty.
The Leak
In May 2026, an actor using the handle SVA2027 began advertising data allegedly stolen from the Russian state research institute Spetsvuzavtomatika. The actor claimed to possess internal technical documents, IPaddress data, and material taken from the institute’s Git environment. Public samples were distributed through forum attachments and Proton Drive, while prospective buyers were directed to a Tox account for private negotiations.

The evidence strongly indicates that SVA2027 possessed authentic Spetsvuzavtomatika material. Two filenames shown in the public sale post also appear in the analyzed collection, including a project-management spreadsheet and a large IPaddress list. The wider archive is internally consistent with the same contract numbers, project codes, personnel, and development stages appearing across the document cache.
The metadata attributes documents directly to the organization, containing email addresses of individuals and machine names both in English and Cyrillic. These artifacts tie the dump documents to the reported leak and give credibility to the authenticity of the files on offer..



The evidence does not prove that the actor SVA2027 carried out the original intrusion. No public evidence of attacks or prior victim history has been tied directly to the account.
Spetsvuzavtomatika acknowledged the attack against its systems but denied that its internal network was compromised. However, that denial is difficult to reconcile with the breadth of the leaked material, which appears to come from multiple internal systems or a broadly privileged source. The initial access method remains unknown, but authentic and sensitive institute data clearly entered criminal circulation.
Spetsvuzavtomatika (Спецвузавтоматика)
Spetsvuzavtomatika is a Russian research institute in Rostov-on-Don that has been sanctioned by the U.S. for activities tied to Russia’s Foreign Intelligence Service (the SVR). The institute’s work includes information security, software, reverse engineering, electronics, testing, and hardware development.

The leaked records suggest that Spetsvuzavtomatika serves as a government cyber warfare and espionage developer rather than a front-line intrusion group. Its role appears to be turning intelligence and security-service requirements into software, operator procedures, prototypes, and specialized hardware.
The documents show direct work with Russian military-unit customers, including Military Units 33949 and 64829. Such work includes Initiative-24, which describes controlling software agents inside corporate networks and extracting information for intelligence purposes. Overall, the institute appears to sit at the nexus of research, engineering, government contracting, and operational cyber support.
The Dump Data
The dump includes technical reports, project requirements, source-code fragments, and attack scenarios among other internal documents and data, suggesting whoever initially exfiltrated the documents had access to a broad shared archive rather than one isolated computer or folder.

The documents show a repeatable government research and development process. Customers define requirements, institute staff research and build solutions, and later projects expand on earlier work. The repository inventory also shows the institute’s technical range, including cloud identity, Windows and Android tooling, communications-layer compromise, and payload delivery. The programs cover embedded systems, communications hardware, and reverse engineering as well. Not every repository was necessarily completed or deployed, but together the files show a connected capability-development ecosystem.
Discovered Tool Sets
Felix-23 (Феликс-23)
Felix-23 is an Internet-facing reconnaissance and active-penetration platform identified in a Git repo document. It is designed to discover remote infrastructure, enrich the results with outside data, maintain target history, and support controlled follow-on activity. The platform processes:
- IP addresses
- Network ranges
- Domains
- Subdomains
- Web applications
- Services
- DNS records
- Files
- Directories
- Software versions
Felix supplements direct scanning with data from search engines, Shodan, VirusTotal, WHOIS, malware repositories, and vulnerability databases. It then organizes material into persistent target records that combine this data into reporting and is designed to revisit targets over time to identify changes.


The system does more than collect information. It is also built for testing and exploitation, with functions to:
- Test credentials
- Try brute-force attacks
- Check for remote code execution
- Test SQL injection
- Bypass access controls
- Confirm vulnerabilities
- Measure DDoS impacts
Felix-23 also hides its activity through TOR, proxies, distributed VPS nodes, rotating IP addresses, and traffic that resembles normal browsing or search-engine crawling. Overall, Felix-23 is a target-development platform for finding, tracking, assessing, and selectively testing remote systems.
HAD (ХАД)
HAD appears to be an earlier or working version of the same capability as Felix-23. Its API manages the following processes:
- Targeting
- Managing hosts
- Managing IP ranges
- Managing VPS nodes
- Managing proxy chains
- Telemetry monitoring
- Vulnerability testing
- Data graphing
- Data export into reports
The platform stores results in structured target records that analysts can review over time to track service changes, IP moves, provider changes, and newly linked infrastructure.


HAD also manages operational tasking and can automatically assign work to other tools within the program. VPS systems are handled as managed resources with details such as:
- SSH access
- Tunneling state
- Permitted routing chains
- Software deployment status
- Active locks
- Forwarded ports
This indicates a centralized multi-user platform rather than a loose collection of scripts, making HAD a fully automated platform for cyber attacks and campaign management.
Its integrations with Nettacker and BoNeSi support scanning, vulnerability testing, and high-volume network traffic generation. Graphing functions help analysts visualize relationships between domains, IPs, providers, and other infrastructure. Export functions allow results to move into reporting or other operational systems. While HAD’s functionality is similar to Felix-23, the exact relationship between the two projects remains unresolved. Felix-23 may represent the formal modernization program while HAD served as the backend or earlier platform.
Putnik (Путник)
Putnik creates remote Layer 2 access inside a target network. It uses TAP-mode OpenVPN and SoftEther to bridge Ethernet traffic so an outside operator can interact with the network as though locally connected. The documented scenarios include:
- ARP (Address Resolution Protocol)
- DHCP (Dynamic Host Configuration Protocol)
- DNS spoofing
- LLMNR and NBT-NS poisoning
- mDNS abuse
- NTLM capture with Responder
- SMB access
- Printer interception
- Authentication coercion.
Management correspondence also requested scenarios for credential theft, printer attacks, and domain compromise. Putnik-24 was previously associated with the name Beryllium.

The Zerologon material shows the platform’s intended depth. It covers:
- Network discovery
- Domain-controller identification
- CVE-2020-1472 exploitation
- NTDS extraction
- Kerberos-key recovery
- Pass-the-hash
- Registry collection
- Account creation
- Domain Admin elevation
Putnik is therefore more than a VPN. It is an internal-network operations platform for credential theft, lateral movement, privilege escalation, and collection within the larger program that Spetsvuzavtomatika has designed and implemented.
Initiative-24 (Инициатива-24)
Initiative-24 is a Spetsvuzavtomatika research and development project focused on using trusted public cloud services to communicate with specialized software agents operating inside corporate networks. The project examines how cloud platform services can be used for remote control, temporary data storage, and information transfer while blending into normal business traffic to avoid detection.

Machine Translation: Introduction
The task of obtaining information from corporate networks is currently highly relevant to the activities of special services, because a large portion of the information of interest is processed, in one way or another, within such networks. This task has many different aspects, one of which is the organization of communication channels with software agents operating inside corporate networks, that is, channels for controlling software agents and channels for extracting information.
In recent years, the approach taken by organizations of interest to the construction of their corporate systems and to information security has changed significantly. Key changes include:
- the widespread use of cloud technologies to deploy an organization’s infrastructure or individual services, and to provide continuous access to infrastructure from geographically remote locations;
- the use of modern integrated information-security tools, including antivirus products, SIEM systems, intrusion detection and prevention systems, and firewalls, which provide control over the execution of processes and monitor the use of communication channels leading outside the organization.
At the same time, modern security products generally transmit information about security incidents to cloud infrastructure. This substantially increases the cost of potential mistakes when organizing data collection. This, in turn, drives the search for and development of new methods for controlling software agents and extracting information that are more difficult for existing security tools to detect.

Initiative-24 is a cloud-based system for controlling agents, staging data, and moving information out of target networks. Potential channels include major cloud storage, email, virtual-machine, and serverless services commonly used in the cloud today. The report also describes hidden Exchange folders that could store instructions or collected data without appearing in normal Outlook or webmail views.
Botany (Ботани)
Botany appears to be a modular Android collection framework. The Const.kt file from the dump outlines an architecture built around a visible application, an encrypted core, and interchangeable modules, with support for background monitoring and updates, protected configuration, and multiple communications channels.


The design separates the visible Android app from an encrypted core, allowing different modules to be used for different tasks. Accessibility services monitor or interact with apps, while notification listeners could collect alerts, messages, and authentication codes.
The files also reference HTTP, SIP, WebRTC, torrent, NAT traversal, and Matrix communications as means of command and control. Because the full runtime code is missing, Botany is best assessed with moderate confidence as a modular mobile surveillance or collection tool for the Android platform.
Blik and Glare (Блик и Глэр)
Blik and Glare are separate Android tools focused on covert storage and offline transfer. The system hides protected data inside applications that resemble Sudoku, calculator, or e-reader software. A desktop generator builds modified APKs and configuration files, while a coder-decoder creates protected ZIP or EPUB containers. Hidden functions are activated through repeated taps on an inconspicuous interface element.

Machine Translation: III. Camouflage Applications
1) Entering special mode
a) Sudoku
Quickly tap the timer in the upper-right corner five times. See the screenshot.
b) Calculator
Quickly tap the backspace/delete button five times. See the screenshot.
c) AlReaderX
Open the settings, then quickly tap the text field showing the application version five times. The field is located at the bottom between the gear icon and the checkmark. See the screenshot.

- Open the camouflage application.
- Use the designated control to enter special mode.
- Enter special mode.
- Grant the required permissions. The application will then automatically search for containers.
- After the search completes, a list of available containers will appear. Close the list by tapping outside the dialog. It can be reopened with the List button.
- Press the Key button.
- Follow the instructions in the dialog. Remove the storage device, then reconnect it.
- Wait for the device to mount. Within five seconds, the application will automatically search it for compatible containers.
- Continue with the normal container workflow to create, open, add files to, edit, or review the contents of a container.

The SimSim mode detects removable-media events, searches mounted storage for compatible containers, and displays them through the hidden interface. Blik and Glare are covert field-storage and transfer utilities rather than remote-access malware. Their role is concealment, offline exchange, and resistance to casual inspection.
Chain-24 (Цепь-24)
Chain-24 is a research and development project for anonymously purchasing operational internet services. It evaluates privacy-focused digital currencies, automated payment methods intended to conceal the payer and recipient, transaction amounts, and timing. The project focuses on acquiring services such as VPS and VDS hosting, email accounts provisioning, virtual SIM card use, closed-forum access, and leaked databases access.

Machine Translation:
This page describes the research goals, tasks, and technical requirements for the “Chain-24” (Цепь-24) R&D project.
Purpose of the research
The project is intended to study how decentralized digital financial instruments can be used to anonymously pay for Internet services. It also calls for development of specialized software, designated “Chain-24,” to automate the use of these financial instruments.
Research tasks
The contractor must:
- Study at least five current decentralized financial instruments and assess how effectively they can conceal information about financial transactions.
- Identify at least five common Internet services that can be purchased using those instruments.
- Identify at least three online financial/exchange services capable of converting the selected instruments between one another and into Bitcoin.
- Agree the selected cryptocurrencies, services, and exchanges with the customer during the first phase of the research.
Anonymity requirements
The study specifically seeks financial instruments that prevent an outside observer from reconstructing the transaction chain. It evaluates whether they can conceal:
- Sender and recipient addresses.
- Transaction amounts.
- Transaction timing.
For each selected instrument, the report must assess:
- Total value stored in the system, expressed in USD.
- Size of its user/community base, including number of wallets.
- Average transaction volume and value by day, week, and month.
- Periods of highest transaction activity.
- Compatibility with BitPay and CoinGate.
- Whether transactions can be conducted through a locally operated full node.
The researchers must also determine whether each system has:
- Open-source code.
- A closed/private blockchain.
- Independent research evaluating its anonymity.
- Identifiable authors or origin.
- The ability to operate the blockchain locally.
- Cross-platform support.
- Desktop x86 clients, browser plugins, or mobile applications.

Chain-24 could support other programs by supplying anonymously purchased or disposable infrastructure and access to restricted online services. This would allow operational teams to separate their activity from directly attributable payment methods or long-term infrastructure. However, the available documents describe research goals and procurement requirements rather than confirmed transactions. They do not link any specific purchase to an IP address, named operation, customer, or deployed system. Thus, this program may not be fully operational at this time, but it does show a desire for automation of tradecraft that often leads to OSINT leaks that can cause issues for covert programs.
Credential, Payload, and Tunneling Projects
The Git repository inventory suggests a development environment designed to manage the full intrusion process. Some projects focus on stealing and reusing credentials from local systems, cloud services, email, and messaging platforms. Others appear intended to deliver code, maintain access, hide activity, and bypass security controls.


A separate program group supports covert communications and remote access through tunnels, proxies, and alternative network channels. Together, the repositories indicate an effort to build tools for full spectrum cyber espionage campaigns that will be automated and managed by small teams. The project names show intended capability areas, but they do not prove that every tool was completed or used operationally.
Identified IP Spaces Used
The file 9jhgraoitew.txt from the dump contains 2,406 entries, including 2,403 individual public IPv4 addresses and three CIDR ranges. The data spans 1,656 distinct /24 networks, 925 distinct /16 networks, 501 ASNs, and 88 countries. The IPs include a myriad of address spaces from public-facing infrastructure that include VPN and other obfuscation services. This level of dispersion makes it highly unlikely that the addresses represent systems owned directly by Spetsvuzavtomatika.

The most likely interpretation is that the file is a mixed working dataset containing reconnaissance targets, vulnerable systems, proxies, scanning nodes, and possibly command and control infrastructure. Felix-23 and HAD provide the strongest connection to this database because both are designed to ingest IP addresses and use them for targeting and attacks. The inclusion of this database infers that this was a testing document in the process of creating and maintaining the Felix and HAD programs.
Conclusion
The Spetsvuzavtomatika leak exposes a broad cyber-development program, rather than one tool or operation, indicating a larger, holistic approach to cyber enabled espionage tradecraft. The documents do not prove that every capability was deployed together, but they show that the institute developed components that integrate across the full intelligence-collection workflow and could be deployed for use as a modular system to automate tradecraft.
In essence, the programs found within these documents show a robust platform of Russian cyber espionage capabilities being automated for operations to function more autonomously. Additionally, the programs show a doctrinal approach to using automation that likely will expand in the future with the addition of AI components to augment online espionage and other activities. While automated systems to scan and hack infrastructure already exist elsewhere in the world, it is certain that other government entities are working on similar capabilities globally. However, this leak specifically gives us a window into operations within the Russian cyber warfare and espionage space that are rare and enlightening.



