Internal documents from Russia’s Spetsvuzavtomatika Research Institute exposed a large ecosystem of tools for cyberespionage, credential theft, attacks on corporate networks, and covert intelligence gathering. DomainTools researchers link the institute to the development of technologies for Russian intelligence services and military units.
In May 2026, a user operating under the nickname SVA2027 began selling data on the dark web that they claimed had been stolen from Spetsvuzavtomatika. The materials included internal technical documents, lists of IP addresses, and files from the institute’s Git environment. Some samples were distributed through forums and Proton Drive.
The institute itself acknowledged that its systems had been attacked, but denied that its internal network had been compromised. At the same time, DomainTools researchers noted in their detailed analysis of the leak that genuine confidential data belonging to the organization had nevertheless entered circulation. However, it remains impossible to determine who carried out the initial breach or how access was obtained.
Analysis of the leaked materials showed that Spetsvuzavtomatika did not operate like a conventional threat group directly carrying out attacks. Instead, it appears to have functioned more as a developer of technologies for state operations. The documents mention work involving Russian military units 33949 and 64829, as well as the development of software, operator procedures, prototypes, and specialized hardware.
“Spetsvuzavtomatika acts as a developer of tools for state cyberwarfare and espionage,” DomainTools researchers said.
Researchers identified seven major projects that illustrate the institute’s areas of work.
Felix-23 and HAD are designed to identify potential targets, scan infrastructure, enrich collected data, and actively test systems. Felix-23 can work with IP addresses, domains, web applications, services, DNS records, and software versions, while also using external sources such as Shodan, VirusTotal, and WHOIS. The system supports credential testing, brute-force attacks, vulnerability checks, SQL injection testing, and attempts to achieve remote code execution.
Putnik is designed to operate inside already compromised networks. The platform enables remote access at the data-link layer and supports scenarios involving credential theft, authentication interception, lateral movement, and privilege escalation. The documentation also describes scenarios involving exploitation of Zerologon, obtaining domain controller data, and elevating an account to Domain Admin privileges.
Initiative-24 explores the use of legitimate cloud services to control software agents inside corporate networks and covertly exfiltrate information. The idea is to disguise command traffic and data transfers as normal activity from popular cloud platforms, making detection by security tools more difficult.
Botany appears to be a modular system for collecting information from Android devices. Its architecture includes a visible application, an encrypted core, and interchangeable modules. Its listed capabilities include background monitoring, use of Accessibility services, and interception of notifications, messages, and authentication codes.
Two other tools, Blik and Glare, are designed for covert data storage and offline data transfer. Protected information can be hidden inside applications that outwardly look like Sudoku games, calculators, or e-readers. Hidden functions are activated through specific sequences of taps.
The final project identified by researchers, Chain-24, focuses on the anonymous purchase of infrastructure and other services required for operations. The documents describe the use of digital currencies and automated payment methods intended to conceal the sender, recipient, amount, and timing of transactions. Potential purchases mentioned include VPS and VDS servers, email accounts, virtual SIM cards, access to closed forums, and leaked databases. At the same time, researchers found no evidence confirming specific transactions or deployed systems associated with the project.
Officially, Spetsvuzavtomatika is a research institute based in Rostov-on-Don that works in information security, software development, reverse engineering, electronics, testing, and hardware development.
The organization’s ties to Russian intelligence services attracted attention long before the current leak. In April 2021, the US Department of the Treasury added Spetsvuzavtomatika to its sanctions list over its work for Russia’s Foreign Intelligence Service. According to US authorities, the institute developed technical tools used by Russian intelligence.
The latest leak provides a much more detailed look at the internal structure of that work. The archive contains technical reports, project requirements, fragments of source code, attack scenarios, and other internal materials. According to DomainTools, the files appear to have originated from several internal systems or from a source with broad privileges.
At the same time, the mere presence of these tools in the documentation does not mean that all of them were completed, deployed, or used in real-world operations. Researchers specifically stress that the leak primarily demonstrates the capabilities of the development environment and the directions in which the institute was working.
“The programs found in these documents demonstrate a powerful platform of Russian cyberespionage capabilities that are being automated so operations can function more autonomously,” DomainTools researchers said.
According to the researchers, this approach to automation could continue to evolve, including through the addition of artificial intelligence components intended to expand the capabilities of online espionage and other operations.