Digital Revolution
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor referenced in the source material is an unnamed hacker group that claims to have compromised the servers of the Kvant Scientific Research Institute, a unit embedded within Moscow’s Federal Security Services (FSB). The group states that it obtained internal documents by cracking into the institute’s network and subsequently released those files to the public. The leaked material reveals details of Kvant’s surveillance capabilities, including the use of artificial neural networks to monitor activity on major social media platforms such as Facebook, Instagram, VKontakte and Odnoklassniki for phrases that signal political dissent. The actors’ own statements indicate that the breach was motivated by a desire to expose the surveillance apparatus of a Russian security service, though no further ideological or financial motive is explicitly stated in the source.
The disclosed documents show that Kvant’s system was designed to detect political discontent by analyzing social‑media traffic, which points to a target set that includes Russian‑language online platforms and the users who generate political speech on them. The leak also highlighted that a similar surveillance architecture appears to have been replicated in Kazakhstan, where a Kazakhstan‑based Kvant unit, working with a Moscow subcontractor, was reported to have developed an analogous system; Kvant Labs in Astana has publicly denied any ties to the Russian group. In addition, the source notes that the United States Treasury Department had previously identified Kvant as an entity attempting to destabilize the United States in 2010, and that BBC Russian reported Kvant’s historical role in producing the first Soviet computers in the 1970s. The leak further drew attention to the legal environment in Kazakhstan, where prosecutors have sentenced individuals for “information support” of opposition groups and where authorities have imposed internet throttling and other punitive measures on online dissent, a situation documented by the Open Dialogue Foundation which recorded thirty cases of legal reprisals against critics between March and October 2018.
Regarding tactics, techniques and procedures, the only concrete action described is the intrusion into the Kvant Scientific Research Institute’s servers to exfiltrate internal documents; the source does not specify any malware families, phishing methods, or particular tooling used to achieve that access. The actors’ subsequent activity consisted of publishing the obtained files, thereby making the surveillance details publicly available. No additional post‑exploitation behavior, lateral movement, or data‑exfiltration techniques are mentioned in the provided material. Consequently, any inference about the group’s technical sophistication or preferred toolset would be speculative and is omitted here.
Public attribution of the threat actor to a specific state sponsor, criminal syndicate or hacktivist collective is not presented in the source. The report only relays the hackers’ own claim of having breached a FSB‑affiliated institute and references external designations of the target (such as the U.S. Treasury’s 2010 designation of Kvant). No links to known advanced persistent threat groups, cybercrime forums, or nation‑state programs are established, leaving the actor’s affiliation officially undetermined in the open‑source record.
The most concrete operation attributed to this group is the disclosure of Kvant’s surveillance documentation, which simultaneously illuminated Russian social‑media monitoring efforts, pointed to a parallel Kazakh system, and underscored subsequent legal actions against online critics in Kazakhstan. The leak prompted broader discussion about state‑run surveillance in both Russia and Kazakhstan and contributed to the documentation of reprisals against internet users by the Open Dialogue Foundation. No further campaigns or intrusion sets are described in the supplied information, so the profile remains confined to this singular disclosed incident and its immediate contextual revelations.
Incidents
Attributed incidents are available to members.
5 incidents