Vulkan files leak
The Vulkan files are a collection of thousands of leaked documents from the Russian cybersecurity company NTC Vulkan (Russian: НТЦ Вулкан), a contractor for Russian military and intelligence agencies. Dating from 2016 to 2021, the files describe software developed by Vulkan to support Russian cyberwarfare and information warfare, including systems for identifying vulnerabilities in computer networks, coordinating cyber operations, controlling internet and telecommunications traffic in designated areas, and conducting disinformation campaigns through social media. The activities include political interference in foreign affairs (such as in the 2016 United States presidential election).[1][2]
Among the projects revealed by the files were Skan, designed to identify and catalogue vulnerable computer systems; Amezit, a system combining internet surveillance and control with tools for online disinformation; and Crystal-2, a training platform for cyber operations against transportation and other critical infrastructure.[2] The documents link Vulkan's work to several Russian security and intelligence organizations, including the Federal Security Service (FSB), Foreign Intelligence Service (SVR) and the military GRU, and contain evidence connecting its projects to GRU Unit 74455, associated with the Sandworm hacking group.[1][2][3][4][5][6]
The documents were leaked to the German newspaper Süddeutsche Zeitung shortly after the beginning of the Russian invasion of Ukraine in February 2022 by an anonymous whistleblower who said they opposed the war. They were subsequently investigated by an international consortium of news organizations and first reported publicly in March 2023. Five Western intelligence agencies and several independent cybersecurity experts assessed the documents as authentic. The files provide evidence of the development and testing of Russian cyberwarfare capabilities, but do not establish that every system described became operational or directly connect Vulkan's software to particular known cyberattacks.[1][2]
Background
[edit]The company NTC Vulkan was founded by Anton Markov and Alexander Irzhavsky in 2010.[1] Both are graduates of St Petersburg military academy and have served in the Russian army, with Markov reaching the rank of captain and Irzhavsky reaching the rank of major.[1]
Vulkan received special licences to work on classified military and state projects from 2011.[1] Vulkan held an FSB security licence allowing it to undertake classified work, and FSB officers were also stationed within the company.[7]
It has more than 120 staff, 60 of whom are programmers,[1] and describes its speciality as information security.[1] It lists Sberbank, Aeroflot and Russian Railways as customers.[1]
Leaks
[edit]The documents, numbering in their thousands, were leaked to the German newspaper Süddeutsche Zeitung within days of the 24 February 2022 Russian invasion of Ukraine by a whistleblower who opposed that war,[1] and were analysed by journalists from that publication and The Guardian, Le Monde and Washington Post, with several other media outlets, as part of a consortium led by Paper Trail Media and Der Spiegel.[1][8][4] The consortium published the first details of its investigation on 30 March 2023.[3][4]
Five Western intelligence agencies and several independent cybersecurity experts authenticated the files.[1][2][4]
Contents
[edit]The cache consists of more than 5,000 pages of documents dating from 2016 to 2021, including internal emails, contracts, financial records, manuals and technical specifications for software developed by Vulkan for Russian military and intelligence agencies. The documents describe systems intended to automate disinformation campaigns, identify and catalogue vulnerabilities in computer networks, coordinate cyber operations and monitor or control internet activity. They also contain documentation concerning the testing of systems and payments made to Vulkan by Russian security services and associated research institutes. Financial records independently obtained by the journalists matched references in the documents and showed millions of dollars in transactions between Vulkan and known Russian military/intelligence organizations. Experts described contractors like Vulkan as an important part of GRU offensive cyber R&D, supplying capabilities and expertise to state agencies.[2]
The documents do not contain malware source code, verified lists of intended targets or evidence directly connecting the Vulkan systems with known Russian cyberattacks. Western intelligence officials and cybersecurity researchers therefore cautioned that it was unclear which systems had become operational. However, references to government testing, requested modifications and completed projects indicated that at least trial versions of some systems had been deployed.[2]
Amezit
[edit]Vulkan won an initial contract to create a system called Amezit in 2016.[1] Amezit was designed to enable its operator to control internet and telecommunications traffic within a designated area, including mobile networks and social media. The system could be used to isolate such an area from external communications and impose an information blackout. A subsystem known as PRR was intended to disseminate disinformation through social media.[1][7]
The documents describe methods for automatically creating large numbers of fake social-media accounts, including the use of banks of SIM cards to circumvent account-verification procedures on services such as Facebook and Twitter. A 2017 draft manual also described the preparation, distribution and promotion of propaganda material through social media, telephone calls, emails and text messages.[2]
Journalists examining Twitter accounts identified in the leaked documents found evidence suggesting that the tools had been used in several countries. Examples included accounts promoting narratives associated with Russian state propaganda concerning the Syrian civil war and, during the 2016 United States presidential election, material attacking Hillary Clinton. Amezit also contained functions for surveillance and control of internet access in areas under Russian control. Project documents described an "information restriction of the local area" and the creation of an autonomous segment of a data-transmission network. Mock-ups showed the system mapping computer networks associated with physical infrastructure. Examples used in the documentation included the Swiss Foreign Ministry in Bern and the Mühleberg Nuclear Power Plant, with technical information concerning potential means of gaining access to their networks, although cybersecurity experts cautioned that these examples did not constitute evidence that the facilities were actual Russian targets.[2]
In 2018 some NTC Vulkan employees went in connection to Amezit to Rostov-on-Don to visit the Radio Research Institute, which is linked to the Federal Security Service.[1] According to Russian security-services expert Andrei Soldatov, however, the institute was acting as an intermediary for the Russian military, which was the intended user of the system. Development of Amezit began six years before the 2022 Russian invasion of Ukraine, indicating that the Russian military's interest in systems combining territorial communications control, censorship and disinformation predated the invasion.[7] It is not known if it has been used in parts of Ukraine occupied by the Russian Army.[1]
Internal emails indicate that Russian intelligence customers were testing Amezit by 2020. A May 2019 email recorded customer feedback and requested modifications, while an associated spreadsheet recorded components of the project as completed.[2]
Crystal-2
[edit]The documents also describe Crystal-2, a cyberwarfare training platform that Vulkan was contracted to develop in 2018 to support searching for weak spots in systems to be targeted.[4][1][2] Scan-V was commissioned in May 2018.[1]
It was intended to allow up to 30 trainees to operate simultaneously. Its documentation described exercises involving the use of Amezit to disable control systems for rail, air and maritime transportation, as well as training in methods for obtaining unauthorized access to local computer and technological networks supporting infrastructure in populated and industrial areas. The documentation classified information processed and stored by the system as "Top Secret". It is unclear whether the proposed training programme became operational.[2]
Skan
[edit]Skan was designed to continuously scan the Internet for vulnerable computer systems and compile information about them in a database for possible future cyber operations. A 2019 document described the system as capable of displaying possible attack scenarios and identifying network nodes that could be involved in them. It was also intended to permit data exchange between geographically dispersed Russian cyber units.[2]
The leaked correspondence provides evidence that at least part of Skan was delivered to a Russian military customer. In May 2020, a Vulkan developer discussed sending company personnel to the premises of the project's "functional user" to install and configure equipment and software and demonstrate the system. The location was identified as Khimki, the Moscow suburb in which the GRU unit associated with the Sandworm hacking group is based.[1][4][2]
Another leaked document dated 2019 refers to Sandworm's military unit number, 74455, and records an official from the unit approving a data-transfer protocol for one of Vulkan's platforms. Cybersecurity analysts regarded this as evidence that Vulkan was developing software for the GRU hacking unit.[2]
Connections with other organisations
[edit]The documents link Vulkan to the Cozy Bear hacker group, according to Google researchers.[1][4]
References
[edit]- 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 Harding, Luke; Ganguly, Manisha; Sabbagh, Dan (30 March 2023). "'Vulkan files' leak reveals Putin's global and domestic cyberwarfare tactics". The Guardian. Retrieved 20 December 2023.
- 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 Timberg, Craig; Nakashima, Ellen; Munzinger, Hannes; Tanriverdi, Hakan (30 March 2023). "Secret trove offers rare look into Russian cyberwar ambitions". Washington Post. Archived from the original on 25 October 2023. Retrieved 30 March 2023.
- 1 2 "The Washington Post joins news organizations in Vulkan Files investigation". Washington Post. 30 March 2023. Archived from the original on 30 March 2023. Retrieved 30 March 2023.
- 1 2 3 4 5 6 7 Claburn, Thomas (31 March 2023). "Leaked IT contractor files detail Kremlin's stockpile of cyber-weapons". The Register. Archived from the original on 1 April 2023. Retrieved 1 April 2023.
- ↑ Lister, Tim (17 March 2023). "Secret document reveals Russia's 10-year plan to destabilize Moldova". CNN. Archived from the original on 29 August 2023. Retrieved 1 April 2023.
- ↑ Myroniuk, Anna (21 February 2023). "Leaked document reveals alleged Kremlin plan to take over Belarus by 2030". Kyiv Independent. Archived from the original on 1 April 2023. Retrieved 1 April 2023.
- 1 2 3 Soldatov, Andrei (30 March 2023). "Cyberwarfare leaks show Russian army is adopting mindset of secret police". The Guardian. Retrieved 2 April 2023.
- ↑ Antoniadis, Nikolai; Baumann, Sophia; Buschek, Christo; Christoph, Maria; Diehl, Jörg; Epp, Alexander; Grozev, Christo; Höfner, Roman; Hoppenstedt, Max; Huppertz, Carina; Kollig, Dajana; Kornfeld, Anna-Lena; Lehberger, Roman; Munzinger, Hannes; Obermaier, Frederik; Obermayer, Bastian; Petrov, Fedir; Rojkov, Alexandra; Rosenbach, Marcel; Schulz, Thomas; Tanriverdi, Hakan; Wiedmann-Schmidt, Wolf (30 March 2023). "The Vulcan Files: A Look Inside Putin's Secret Plans for Cyber-Warfare". Der Spiegel International. Archived from the original on 2 April 2023. Retrieved 3 April 2023.
External links
[edit]- "Putins Krieg im Netz [Putin's Cyber-War]". Der Spiegel (in German). Hamburg, Germany.
- 2023 in international relations
- 21st-century military history of Russia
- Cybercrime
- Data journalism
- Investigative journalism
- Whistleblowing
- Propaganda in Russia
- Foreign relations of Russia
- Russian intelligence operations
- Russian interference in the 2016 United States elections
- Russian interference in British politics
- Russo-Ukrainian war
- Russia–NATO relations
- Federal Security Service
- GRU
- The Guardian
- Der Spiegel
- Süddeutsche Zeitung
- News leaks