Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Vulkan Files describe Russian contractor projects spanning network reconnaissance, online influence operations, and exercises involving operational technology. They offer evidence of what some Russian Ministry of Defense-linked project documents planned or specified—not proof that every capability worked, was deployed, or was used in an attack.

What are the Vulkan Files?

The Vulkan Files are leaked corporate records attributed to NTC Vulkan, a Moscow-based IT contractor. The Washington Post reported in 2023 that the trove contained more than 5,000 pages. Mandiant analyzed documents dated 2016–2020 and described them as requirements contracted with Russia’s Ministry of Defense, including at least one project documented in part for GRU Unit 74455, known as Sandworm.

The files are significant because they show a planned portfolio of capabilities rather than a single alleged weapon. The projects address different stages or dimensions of cyber and information operations: gathering data about networks, shaping online information, and training for disruption scenarios.

What did the three named projects describe?

Project names vary between sources and transliterations. Mandiant uses Scan, Amesit, and Krystal-2B; other reporting uses Skan, Amezit, Crystal-2, or Crystal-2V. These labels refer to descriptions in the documents, not independently confirmed products in operational use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Project Described purpose What the documents establish—and what they do not
Scan / Skan Large-scale data collection and processing to support cyber operations. Consortium reporting describes reconnaissance and mapping target vulnerabilities. Mandiant describes a framework and project requirements. The material does not establish that the system was deployed or that mapped infrastructure represented actual targets. Sources: Mandiant, March 30, 2023; The Guardian, March 30, 2023; The Washington Post, March 30, 2023.
Amesit / Amezit Control and manipulation of the online information environment, including support for psychological operations. The Guardian also reports functions involving surveillance, internet control, and fake accounts. These are reported project functions, not verified outcomes of a deployed system. Mandiant describes a framework for information operations; The Guardian reports the additional functions from the leak. Sources: Mandiant, March 30, 2023; The Guardian, March 30, 2023.
Krystal-2B / Crystal-2 / Crystal-2V A training platform for coordinated information-operation and operational-technology scenarios, including disruption exercises. The documents describe training related to disruption scenarios. Experts quoted by The Washington Post differed on whether some references meant offensive techniques or defensive exercises. The documents do not by themselves confirm real-world attacks. Sources: Mandiant, March 30, 2023; The Washington Post, March 30, 2023; The Guardian, March 30, 2023.

Why pair information operations with operational technology?

Operational technology (OT) controls or monitors physical processes, such as industrial equipment and infrastructure. Exercises that place OT disruption alongside information operations suggest that planners considered technical disruption and the surrounding information environment within a connected mission set. That is a meaningful indication of planning priorities, but it does not show that one platform combined all these functions or that a particular infrastructure attack took place.

John Hultquist, Mandiant’s vice-president of intelligence analysis, interpreted the documents this way: “These documents suggest that Russia sees attacks on civilian critical infrastructure and social media manipulation as one and the same mission”. This is his assessment of the planning reflected in the files, not a finding that the documents prove a specific attack.

How strong is the evidence that the files are authentic?

Mandiant said the source material appeared credible and that the documents’ consistency, limited external validation, and alignment with previously observed capabilities supported its suspicion that they were legitimate. It also said it “cannot conclusively confirm the authenticity” of the documents. The Guardian reported that five Western intelligence agencies said the files appeared authentic. The Washington Post likewise reported that intelligence analysts and cybersecurity experts who reviewed them thought the documents appeared real.

Those assessments support treating the leak as a credible window into project planning, but “appeared authentic” is not the same as independently verifying every document, project detail, or claim. The Washington Post also reported uncertainty over whether some mapped infrastructure examples were actual targets or illustrations used for training.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the leak does not prove

  • That the planned capabilities worked. Mandiant said it lacked evidence to prove that the capabilities described had been implemented or were feasible.
  • That the projects were used in real attacks. The Guardian reported that real-world use of Vulkan-built tools is not known.
  • That every project belonged to Sandworm. Mandiant identified documentation involving GRU Unit 74455 for at least one project; that does not establish that all the projects or tools were Sandworm operations.
  • That a planned exercise was an operational attack. Training material can describe offensive scenarios without showing that they were carried out against real systems.

The distinction matters: the files are evidence of documented requirements, designs, and training plans. They do not provide a verified inventory of deployed systems, successful operations, or attack results.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to interpret the leak

The strongest conclusion is that the documents reveal a Russian defense-linked contractor’s planned work across reconnaissance, influence operations, and cyber-physical disruption exercises. The Sandworm-linked documentation makes the files especially relevant to understanding Russian military cyber planning. But the public evidence described by Mandiant and the news organizations does not establish that the proposed tools became operational capabilities or were used in the field.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.