dti.domaintools.com 1 Oct 2026, 16:59 UTC

Leaked Russian Projects Reveal an Automated Cyber Espionage Ecosystem

CyberSIXT Evidence Panel Source marked as original reporting

THE Spetsvuzavtomatika leak on the dark web exposes a broad Russian cyber development programme rather than a single intrusion operation.

Seven named projects are described, including Felix-23 and HAD for target discovery, scanning, enrichment and active testing; Putnik for internal‑network access and credential theft; Initiative‑24 studying cloud‑based control of software agents and data movement; Botany for modular Android collection; Blik and Glare as covert storage and offline transfer tools; and Chain‑24 focusing on anonymous procurement of hosting and other operational services.

The documentation portrays a development ecosystem capable of supporting most stages of cyber‑enabled intelligence gathering with automation, though it does not prove that every tool was deployed together. The evidence suggests authenticity of at least some samples, but the original breach’s mechanics remain uncertain.

The dump lists technical reports, source‑code fragments and attack scenarios, with Felix‑23 and HAD described as interfaces for targeting and testing across multiple protocols and platforms. Putnik is highlighted as more than a VPN—an internal‑network operations platform enabling credential theft, lateral movement and privilege escalation, including CVE‑2020‑1472 exploitation as part of its Zerologon‑related workflow.

Initiative‑24 envisions cloud‑based channels to command software agents and exfiltrate data, while Botany and Blik/Glare illustrate Android‑focused collection and covert storage with stealthy, user‑friendly interfaces. Chain‑24 is cited as researching anonymous payments to acquire infrastructure and services, though no concrete purchases are linked to a live operation.

The report also notes IP space dispersion and questions the extent to which the leaked materials reflect a fully operational threat versus a comprehensive development archive. Spetsvuzavtomatika’s ties to Russian state security work are acknowledged, including contracts with military units and government customers, underscoring the leak’s significance for understanding automated cyber‑espionage capabilities.

View full article

Article by CyberSIXT