13 de septiembre de 2026

SOCaaS

Centro de Operaciones de Seguridad como servicio

NTC Vulkan leak shows evolving Russian cyberwar capabilities


National habits and perspectives on waging war are not just apparent in terrestrial conflict. In cyberspace, national ways of cyberwar clearly exist. From the unusually aggressive style of Israeli responses to regional cyber threat activities to the consistent correlation between Communist Party interests and China-attributed cyber espionage, a host of examples show that diverse geopolitical interests, national political imperatives, and institutional cultures seem to produce unique flavors of cybersecurity practice.

Now, the NTC Vulkan leak of thousands of pages of secret documentation related to the development of Moscow’s cyber and information operations capabilities adds more weight to this view. The documents paint a picture of a government obsessed with social control and committed to scaling their capacity for non-kinetic interference.

NTC Vulkan: What we know

An apparently unhappy employee of a contracting firm linked to Russian military and security services passed several thousand documents to a German reporter working for Süddeutsche Zeitung. They detailed a collaboration centered on fleshing out Moscow’s cyber conflict toolkit. The employee, who has remained anonymous and disappeared soon after the transfer of documents, claimed extreme discomfort with Vladimir Putin’s administration. “The company is doing bad things, and the Russian government is cowardly and wrong,” the whistle blower stated. “I am angry about the invasion of Ukraine and the terrible things that are happening there…. I hope you can use this information to show what is happening behind closed doors.”

The leaked documents constitute a cache of over 5,000 manuals, reports, company communications, software specification sheets, and other media covering a period between 2016 and 2021. The portfolio details applications and database resources developed by a company called NTC Vulkan for use by the intelligence agencies of the Russian Federation. Reporting on the leak highlights the close relationship held by the company across the period with key spy agencies and military units. These include the Federal Security Service (FSB), the Foreign Intelligence Service (SVR), and both military intelligence divisions of Russia’s armed forces: the Main Directorate (GRU) and Main Operational Directorate (GOU) of the General Staff.

Authoritative voices in Western cybersecurity circles have said the leak is remarkably credible. Representatives of five national intelligence agencies along with researchers from Mandiant and other cybersecurity companies have reviewed parts of the cache and stated that the tools and techniques being described match with existing intelligence on Russian capabilities.

These capabilities, which for the first time appear to link a private firm directly to known threat actors like Military Unit 74455 (the advanced persistent threat actor commonly known as Sandworm), include tools that are clearly geared toward large-scale attack preparation and the widespread, automated dissemination of disinformation. Several tools are described in some detail. One, a project called “Skan-V” or just “Scan,” appears to be a background taskmaster and coordination tool that can enable other software for malicious purpose. According to Mandiant analysis, the tool is an information gathering application that is focused on efficiently conducting early operational reconnaissance activities. Scan appears to be so comprehensive as to substantially automate cyber operations preparation.

Copyright © 2023 IDG Communications, Inc.



Nos llegó este contenido de ciberseguridad de: CSO Online

Llegarás a la noticia original en el enlace que se encuentra a continuación: https://www.csoonline.com/article/3692821/ntc-vulkan-leak-shows-evolving-russian-cyberwar-capabilities.html#tk.rss_news

Deja una respuesta

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *