2 Remove Virus

Leak reveals Russian institute’s alleged role in building cyber espionage tools

A major leak from a Russian research institute has provided a rare look inside what researchers describe as a development ecosystem supporting Russia’s foreign intelligence service and its cyber espionage operations.

 

 

According to research from DomainTools Investigations (DTI), leaked files connected to Spetsvuzavtomatika, also known as SVA, contain internal technical documents, project specifications, reports, and material from software development repositories. Together, the files appear to show how the organization researched and developed tools that could support different stages of intelligence-gathering operations.

Spetsvuzavtomatika is based in Rostov-on-Don and publicly works in areas including information security, software, electronics, and hardware development. Its connections to Russian intelligence are not a completely new discovery. The US government sanctioned the institute in 2021, saying it developed technical tools for Russia’s Foreign Intelligence Service, commonly known as the SVR.

The newly analyzed leak provides considerably more detail about what that work may involve. Rather than revealing a single piece of malware or one hacking operation, the documents describe multiple projects covering different parts of a potential cyber espionage campaign.

DTI identified seven projects that help illustrate the institute’s work. Projects called Felix-23 and HAD focused on finding and studying potential targets, including automatically scanning internet-connected systems and collecting information about them.

Another project, Putnik, dealt with activity inside compromised corporate networks. Its capabilities included identifying systems and credentials that could potentially help operators move deeper into an organization’s network.

Initiative-24 explored another important part of cyber espionage: communicating with software operating inside a target’s network and extracting information. According to the leaked documents, the project examined ways to use trusted cloud services for those communications, potentially making suspicious traffic more difficult to distinguish from normal internet activity.

Other projects addressed mobile devices and the infrastructure required to conduct operations. Botany appears to have focused on collecting information from Android devices, while Blik and Glare involved methods for discreetly storing and transferring information.

Chain-24, meanwhile, dealt with acquiring infrastructure such as hosting services while making it harder to identify who was behind the purchases. This type of supporting infrastructure can be important for espionage operations because attackers need servers and other online resources without easily connecting those assets to themselves.

The documents also appear to connect SVA’s work with Russian military units. DTI’s analysis identified references to Military Units 33949 and 64829 among the institute’s government customers.

What makes the leak particularly revealing is the way these projects fit together. Instead of treating reconnaissance, access, information collection, and infrastructure as completely separate tasks, the documents describe components that could support several stages of an intelligence operation.

Researchers believe automation is an important part of that approach. Tasks that previously required substantial manual work could increasingly be performed by software, potentially allowing intelligence operators to investigate more targets and manage more complex campaigns with fewer people.

However, the leaked documents need to be interpreted carefully. They show research projects, technical requirements, source-code fragments and possible attack scenarios, but their existence does not demonstrate that every capability was completed or used against real targets.

Spetsvuzavtomatika has also denied that its internal network was compromised. DTI nevertheless concluded that authentic and sensitive information associated with the institute entered criminal circulation after material began appearing on the dark web.

The leak therefore provides a window into how sophisticated cyber espionage capabilities can be developed behind the scenes rather than proof of a specific new attack. DomainTools Investigations’ analysis suggests SVA was working on a collection of interconnected technologies capable of supporting reconnaissance, network access, intelligence collection, and the infrastructure needed to keep those activities running.