01Summary
The leak, disclosed on March 30, 2023, provided an unprecedented look into the operational cyber capabilities of Russian state actors. The documents, originating from NTC Vulkan, detail projects like 'Amesit,' which automates disinformation campaigns and can manipulate social media personas, and 'Skan,' a sophisticated network scanner targeting global infrastructure such as SCADA power grids and air traffic control. Furthermore, the files established a direct contractual link between NTC Vulkan and Military Unit 74455, the unit historically associated with the NotPetya malware, confirming the commercialization of state-level cyber espionage and sabotage tools.
02Background
The leak emerged amid heightened geopolitical tensions regarding Russian cyber aggression. It built upon previous disclosures linking Russian state actors to major cyber incidents, such as the NotPetya attack. The documents suggest a systematic, commercialized approach to cyber warfare, moving beyond ad-hoc attacks to structured, deployable toolsets.
03Key revelations
- 01The existence of 'Project Amesit,' a tool suite for automated disinformation and narrative injection.
- 02The development of 'Project Skan,' a dedicated reconnaissance tool for critical infrastructure like power grids and air traffic control.
- 03The direct contractual link between NTC Vulkan and Military Unit 74455, confirming the commercialization of state-level cyber tools.
04Technical analysis
The documents describe advanced capabilities, including GSM/GPS signal manipulation and the ability to map vulnerabilities in SCADA systems. 'Skan' is presented as a reconnaissance tool designed for pre-attack intelligence gathering, while 'Amesit' focuses on the Information Environment Control (IEC) domain, indicating a multi-layered approach combining physical, digital, and psychological warfare.
- Attack method
- Intelligence Collection / Disclosure
- Tool / malware
- Project Amesit
- Malware type
- Spyware / Disinformation Tool
Vulnerabilities exploited
- SCADA systems vulnerabilities
- Air traffic control network weaknesses
MITRE ATT&CK techniques
- T1566.001
- T1046
05Threat actor
NTC Vulkan is identified as a Russian defense contractor, suggesting its tools are state-funded and designed for military application. The leak implies that the company functions as a commercial arm for the Russian Ministry of Defense's cyber offensive capabilities.
Aliases
- Vulkan_Whistleblower
APT designations
- Sandworm
MITRE groups
- T1566.001
Attribution sources
- Anonymous
06Victims and impact
Additional victims
- GRU
- FSB
Countries affected
- United States
- Europe
- Russia
07Data exposed
Data types
- Technical Specifications
- User Manuals
- Contractual Agreements
- Classified Documents
Notable documents
- Project Amesit Technical Specifications
- Project Skan Overview
- GRU/FSB Contract Portfolio
08Timeline
- 2023-03-30Vulkan Files disclosed, revealing NTC Vulkan's cyber-warfare portfolio.
09On the record
The goal is not just to spy, but to prepare the battlefield for kinetic effects.
10Reaction and fallout
Public reaction
The leak caused immediate alarm within the cybersecurity community, highlighting the professionalization and commercialization of state-sponsored cyber warfare. It fueled international calls for stricter export controls on dual-use technology.
Political impact
The disclosure intensified Western scrutiny of Russia's military-industrial complex, particularly its cyber defense contractors. It provided concrete evidence for policymakers regarding the scope and sophistication of Russian cyber offensive planning.
Geopolitical consequences
The files reinforced the narrative of Russia's use of cyber tools not merely for espionage, but for pre-positioning for kinetic conflict, escalating international tensions and hardening cyber deterrence policies.
11Legal
No immediate legal action was reported, but the leak contributed to ongoing international discussions regarding the legal status of cyber-warfare tools and the accountability of state-sponsored entities.
12Aftermath
Policy changes
- Increased focus on critical infrastructure resilience (SCADA/ATC systems)
- Calls for stricter international export controls on dual-use cyber technology
Regulatory changes
- Enhanced national cybersecurity standards for critical infrastructure sectors
Security improvements
- Mandatory segmentation of Operational Technology (OT) networks from IT networks
- Improved monitoring for disinformation campaign indicators
13Significance and legacy
Significance
The Vulkan Files are significant because they moved the discussion of cyber warfare from theoretical capability to documented, commercialized product lines. They provided a blueprint of state-level cyber offensive planning, detailing tools for everything from disinformation (Amesit) to physical infrastructure sabotage (Skan).
Legacy
The leak solidified the understanding that modern cyber conflict is a multi-domain, commercialized industry. It accelerated the global push for 'cyber resilience' and highlighted the urgent need for international legal frameworks governing cyber-weapons.
14Disclosure and media
- Authentication
- Internal Server Exfiltration
Media partners
- Anonymous
Publishing organisations
- Anonymous
16Field notes
- 01The documents explicitly linked NTC Vulkan to Military Unit 74455, the group responsible for the NotPetya attack.
- 02The 'Amesit' project's capabilities included manipulating GSM/GPS signals, suggesting a physical layer of cyber warfare capability.
17Resolution
The documents were leaked and subsequently analyzed by security researchers and journalists, leading to increased public awareness and policy discussions.
18Sources
Official documents
- NTC Vulkan Project Portfolio
References
- [1]Vulkan_Whistleblower Disclosure
- [2]Cybersecurity Threat Reports (2023)









