dti.domaintools.com SpetsVuzAvtomatika Leak Reveals Russian Cyber Espionage Projects
Article Content
- •Leaked documents reveal SpetsVuzAvtomatika's support for Russian state-sponsored cyber operations.
- •Seven projects identified focus on credential theft, data extraction, and cyber intelligence.
- •The institute has denied a breach, but experts confirm sensitive data is in criminal circulation.
Leaked documents from SpetsVuzAvtomatika, a Russian cyber research institute, indicate its involvement in state-sponsored hacking and espionage. The leak, discovered on the darknet, outlines seven projects focused on cyber intelligence collection, including credential theft and data extraction from corporate networks. Notable projects include Felix-23 and HAD for target scanning, Putnik for internal network access, and Initiative-24 for using cloud services to control software agents. Despite the institute's denial of a network breach, experts assert that sensitive data has entered criminal circulation. The documents do not confirm the deployment of all tools but indicate a robust development environment for cyber operations. SpetsVuzAvtomatika has been sanctioned by the US Treasury since May 2021 for its role in developing hacking tools for Russia's foreign intelligence service, SVR.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Blik and SpetsVuzAvtomatika in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What projects were revealed in the leak?
Is there confirmation of exploitation?
What should organizations do in response?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…