Contents18 sections
- The System That Was Supposed to See Everything
- The Entry Point: Not a Complex Exploit, But a Person
- Why Social Engineering Proved More Effective Than a Complex Cyberattack
- Access That No One Noticed
- Propaganda as a Production Conveyor Belt
- "Digital Konashenkov"
- A System Worth Hundreds of Millions, "Cobbled Together"
- Where the Money Might Have Dissolved
- A Developer with an Unusual Biography
- The Administrator's Failure
- The Security Service's Failure
- The Developer's Failure
- Konashenkov's and His Department's Failure
- What Exactly the Adversary Gained
- How "Katusha" Became an Intelligence Tool Against Russia
- Why This Failure Is More Than Just One Breach
- Who Is the Commander of Failure Here?
- The Finale: "No Losses," Except for the Entire System
The System That Was Supposed to See Everything
The Russian Ministry of Defense paid hundreds of millions of rubles for a system designed to continuously monitor the information space, identify threats, and help leadership control its own propaganda machine.
Ultimately, however, the controllers themselves became controlled.
"Katusha" was positioned by its developer as an information-analytical system for online media monitoring. It was intended to collect publications around the clock, classify them by topics, events, persons, and source types, determine the sentiment of materials, assess audience reach, and alert users to the most important information events.
The developer company, "M 13," claimed that messages appeared in the system within one to ten minutes of publication, and critical notifications could be sent to users via email, SMS, and push messages. The database included approximately 40,000 Russian and foreign sources.
In 2016, the Kremlin confirmed the transition to an adapted version of the "M 13" company's monitoring system. The cost of that contract until the end of the year was 79 million rubles.
In 2021, the Russian Ministry of Defense announced the procurement of rights to use "Katusha" at a cost of approximately 320 million rubles. The license was intended to be valid until the end of 2023.
For this money, the Russian military department expected to receive a kind of information command post: a system capable of showing who, where, and in what context mentioned the armed forces, the country's leadership, military operations, and individual units.
Instead, the system failed to detect those who were observing it.
The Entry Point: Not a Complex Exploit, But a Person
According to additional information used by the "Commanders of Failure" project, access was gained through phishing and social engineering elements. The target was an administrator who had access to the system and official information. As a result of the manipulation, they effectively opened access to their own email.
"Katusha" didn't need to be directly breached. There was no need to start with a server attack, search for an unknown technical vulnerability, or overcome complex multi-layered protection. It was enough to gain access to a person through whom notifications, correspondence, documents, and information necessary for working with the system passed.
The administrator's email could become a link between an external actor and the internal infrastructure. It might contain official letters, links, instructions, notifications, documents, user information, and other data that allowed for gradual expansion of access.
The main error didn't occur in the code. It occurred in the mind of an employee who was not taught to recognize manipulation or who ignored elementary security requirements.
Why Social Engineering Proved More Effective Than a Complex Cyberattack
Government agencies often build defenses around servers, firewalls, and antivirus software, but leave the human element as the weakest link in the system. Formally, an employee might work within a secure network, their computer might be certified, and access might be limited by job responsibilities. But all of this loses meaning when the user themselves grants an outsider access to their mailbox or provides information that allows their account to be recovered.
Such a failure typically consists of several elements. The employee fails to recognize an attempt at manipulation. Official and personal correspondence are not sufficiently separated. Linked accounts are used for access to critical resources, and the system does not require robust multi-factor authentication. Unusual logins do not trigger automatic blocking, and user actions are not analyzed by the security department. As a result, after one account is compromised, the attacker can proceed further.
In the case of "Katusha," what is most telling is not just the initial access, but also the fact that the unauthorized presence, according to available information, remained unnoticed for a long time. The administrator made the first mistake. The Ministry of Defense's security system turned it into a strategic failure.
Access That No One Noticed
A quick breach usually gives an attacker a limited picture. They manage to grab a few files, take screenshots, and leave before access is closed. With "Katusha," judging by the volume of published materials, it happened differently.
The Ukrainian side gained the ability to study the system from the inside. Hacktivists observed the interface, filter operations, information categories, reports, and monitoring of social networks and Telegram channels. Internal documents of the Department of Information and Mass Communications became available to them.
InformNapalm published examples of daily reviews of Russian media, monitoring of foreign publications, transcripts of television segments, weekly reports, and plans for information activities. The documents showed how reporting passed through department employees and was distributed to the press services of military districts, fleets, and branches of service.
Hacktivists gained the ability to reconstruct the operational model of the Russian department: which sources it tracked, which topics it considered priorities, which documents were prepared daily, who compiled and approved reports, to whom information activity plans were sent, which channels were considered loyal, which platforms fell into the problematic category, and how leadership assessed the effectiveness of its information work.
This is no longer just a document leak. This is a compromise of the management process.
Propaganda as a Production Conveyor Belt
The obtained materials showed that Russian military propaganda functioned as a bureaucratic production. Employees tracked publications, prepared daily and weekly reports, counted the number of materials released, and compared metrics against plans.
A closed loop emerged: topic establishment → material production → publication → mention collection → performance report → new plan approval. On paper, this system was supposed to allow the command to manage the army's information support.
In practice, it created conditions where the main metric was not the accuracy of information or an understanding of the real situation, but the quantity of content produced. If a unit published the required number of messages, and the system showed high reach and predominantly positive sentiment, the task was considered accomplished. It didn't matter how much this picture corresponded to reality.
"Digital Konashenkov"
InformNapalm, analyzing the accessible version of "Katusha," called it a kind of "Potemkin village" and a "digital Konashenkov." According to researchers' assessment, the system incorrectly determined the sentiment of messages. Negative publications about the Russian armed forces might not be accounted for or could be labeled as neutral.
As a result, the system might not have been measuring reality, but rather the reflection of Russian propaganda within Russian propaganda itself. State and loyal media published a coordinated picture of events. "Katusha" collected these publications, identified them as positive or neutral, and generated a summary report. The leadership received figures confirming that the information situation was under control.
The Ministry of Defense formed the desired picture, then its own monitoring system found this picture in controlled sources and reported to the Ministry of Defense that its version of events prevailed.
Critical messages did not necessarily disappear entirely. However, dozens of positive publications could overshadow a single negative piece, reducing its impact on the final statistics. This allowed for two tasks to be accomplished simultaneously: demonstrating high activity from press services and reporting a favorable information environment.
A System Worth Hundreds of Millions, "Cobbled Together"
Outwardly, "Katusha" appeared to be a serious state product: dashboards, filters, graphs, sentiment distribution of messages, search by persons and organizations, and monitoring of social networks and Telegram.
However, according to experts who studied the accessible implementation of the system, behind the expensive facade lay a software product created at a significantly lower technical level than one would expect from a platform used by the Russian military department. The architecture, logic of individual modules, quality of classification, and overall organization of work gave the impression of a system developed hastily, without full testing.
What exactly did the Ministry of Defense pay approximately 320 million rubles for? A fully protected analytical platform? Or a visually convincing shell that collected publications, built diagrams, and helped leadership see exactly what it wanted to see?
Where the Money Might Have Dissolved
A large government contract in itself does not prove corruption. The cost of such systems includes database access, infrastructure, technical support, continuous material collection, analyst work, software updates, and adaptation to customer requirements.
However, in the case of "Katusha," the contract cost sharply contrasts with the outcome. The Ministry of Defense received a system that failed to protect critical administrative access and did not detect a prolonged unauthorized presence. It allowed internal documentation to be obtained and incorrectly classified some publications. A significant portion of its analytics was based on a censored information field, and the system itself was primarily used to confirm plan fulfillment rather than to provide leadership with an objective picture.
This is where a mechanism characteristic of the Russian state system emerges: the client receives an expensive platform, the contractor gets a large contract, officials get convenient reporting, and real effectiveness interests no one until the system faces an adversary. Everything works during presentations. In combat conditions, it falls apart.
A Developer with an Unusual Biography
"Katusha" was developed by the Moscow-based company "M 13." The owner of the company was Vladislav Klyushin. In March 2021, he was arrested in Switzerland and subsequently extradited to the United States. In February 2023, a U.S. court found him guilty of a criminal scheme involving hacking corporate networks and trading securities using stolen confidential information. In September 2023, Klyushin received a nine-year prison sentence.
The U.S. Department of Justice indicated that participants in the scheme worked at "M 13," which, in addition to media monitoring, offered services for penetration testing and simulating advanced cyber threats.
A company linked to a person convicted of computer intrusions created an expensive monitoring tool for the Russian authorities. Then, Ukrainian hacktivists gained access to this tool through the compromise of an employee of the state client itself.
The Administrator's Failure
The first link in the chain was a person. The administrator possessed elevated rights and access to official information but proved vulnerable to social engineering. They either failed to recognize the manipulation or did not adhere to proper procedures for working with email and credentials.
In any secure system, an administrator is not just a user. Their account is part of the security perimeter. Therefore, working with administrators should involve a separate secure email and mandatory multi-factor authentication, restrictions on logins from unknown devices, and behavioral analysis of actions. Equally important are regular changes and revocation of access keys, automatic notifications of suspicious operations, segregation of administrative duties, and continuous monitoring by the security unit.
If a single phishing incident is enough to gain prolonged access to the infrastructure of a military department, it means not only a specific employee failed. The entire access management system failed.
The Security Service's Failure
Even a successful email compromise does not necessarily lead to a large-scale leak. A modern security system should detect unusual logins, new devices, changes in connection geography, mass opening of documents, atypical downloads, anomalous requests, and attempts to move between services.
According to available data, the presence was not detected in a timely manner. This allowed the attackers not just to enter, but to establish a foothold, study the environment, and gradually collect information. Consequently, several protective mechanisms might have been absent or non-functional: centralized security event monitoring, comprehensive activity logging, and analysis of anomalous user behavior. Added to these are procedures for responding to email compromise, regular checking of active sessions, segmentation of official systems, and independent auditing of administrator actions.
The Russian Ministry of Defense monitored thousands of media outlets and Telegram channels but failed to notice an unauthorized user within its own infrastructure.
The Developer's Failure
A developer of state software is obligated to consider not only interface convenience but also the threat model. Especially when the product is used by a military department during wartime. The system should operate on the assumption that a user account can be compromised. It should limit the volume of accessible information, segregate roles, log actions, prevent mass copying, and quickly detect unusual behavior.
If the compromise of a single email opened the way to prolonged observation of the system, this indicates either insufficient architectural security or extremely negligent administration on the part of the client.
Konashenkov's and His Department's Failure
The Department of Information and Mass Communications should have understood the nature of information warfare better than most units of the Ministry of Defense. Its employees daily dealt with information attacks, fakes, manipulations, Telegram channels, and foreign publications. They themselves managed information flows.
Yet, it was within this very department, according to published data, that outsiders gained access to the monitoring system and internal documents. The unit that was supposed to recognize information influence failed to protect its own administrator from social engineering. The structure that compiled lists of reliable and unreliable channels could not determine that its own infrastructure was already unreliable.
What Exactly the Adversary Gained
The value of the access was not just in individual documents. Even if most materials did not contain state secrets in the classical sense, their totality allowed for an insight into the internal mechanics of the department: the structure of employee interaction, working addresses and user roles, the regularity of report preparation, and the command's information priorities. The documents revealed how the department reacted to specific events, which sources it tracked, and by what criteria it assessed their loyalty. Finally, the materials exposed templates for information activities, the procedure for approving materials, weaknesses in internal analytics, the competence level of personnel, and the technical features of the services used.
Hundreds of reports, emails, and observations collected over a long period transform into an organizational model. This is why the duration of undetected access is often more important than the notoriety of the initial breach.
How "Katusha" Became an Intelligence Tool Against Russia
Initially, the system was supposed to collect data for the Russian Ministry of Defense. After compromise, it effectively began working in reverse. Every opened tab showed what exactly interested the Russian department. Every report demonstrated its priorities. Every classification of Telegram channels revealed its attitude towards specific sources. Every mailing list showed the chain of recipients.
The monitoring system transformed into a sensor installed within the Russian propaganda apparatus itself. Russian employees continued to collect and structure information, unaware that the results of their work were being used by the adversary.
This is the main paradox of "Katusha": Ukrainian hacktivists did not have to independently organize the entire data array. The Russian department had already distributed documents by topics, dates, units, and work areas. The propagandists themselves prepared their own dossier.
Why This Failure Is More Than Just One Breach
The story could be reduced to a single formula: an administrator fell for a phishing message, hackers accessed their email, obtained documents, and published them. But such a retelling conceals the scale of the problem. The failure of "Katusha" consisted of several sequential decisions:
The Ministry of Defense acquired an expensive system. The system was integrated into the work of the information department. Users with insufficient training were granted access to it. One of the administrators proved vulnerable to social engineering. The email compromise did not lead to immediate access revocation. The system did not recognize an unauthorized presence. The security service did not detect anomalous activity. Access was maintained long enough to collect a large array of data. The obtained materials revealed not only documents but also the department's operational procedures. Analysis showed that the system itself could mislead leadership.
At each stage, there was an opportunity to stop the incident from escalating. Not a single protective layer functioned.
Who Is the Commander of Failure Here?
It is impossible to name a single culprit. The administrator created the entry point. The security service failed to detect the compromise. The developer did not ensure sufficient system resilience against account takeover. The department's leadership structured its work around formal reporting. The Ministry of Defense paid hundreds of millions for a platform that primarily showed a picture convenient for superiors. Konashenkov and his subordinates spent years telling the Russian audience that the situation was under control.
In reality, outsiders could be inside their information infrastructure, reading documents, studying reports, and observing how Russian propaganda daily produced an alternative reality. This is the collective command of failure.
The Finale: "No Losses," Except for the Entire System
"Katusha" was conceived as a means of information superiority. It was supposed to detect attacks, show threats, and help the Russian leadership control the narrative. But the system proved incapable of protecting its own access. Its administrator fell victim to social engineering. Its infrastructure failed to notice a prolonged presence. Its analytics, according to researchers, distorted reality. Its reports helped superiors convince themselves that everything was going according to plan.
For hundreds of millions of rubles, the Ministry of Defense received an expensive screen reflecting the propaganda narrative it itself created. And Ukrainian hacktivists gained a window into the internal world of the Russian military department.
In Konashenkov's public briefings, there were traditionally no losses. In the "Katusha" story, almost everything was lost: access, documents, internal processes, confidentiality, reputation, and the illusion of control.
Details of the initial access via phishing, the compromise of the administrator's email, the duration of presence, and the volume of collected information are based on data used by the "Commanders of Failure" project. These details were not fully disclosed in InformNapalm's public publication and require independent documentary confirmation.
The assessment of the system being "cobbled together" reflects the conclusion of specialists who studied its accessible implementation. Problems with sentiment determination, analytical quality, and the system's focus on formal reporting have been publicly confirmed; a full source code audit is not publicly available.
This material was prepared based on InformNapalm's investigation into the penetration of the "Cyber Resistance" group into the infrastructure of the Department of Information and Mass Communications of the Russian Ministry of Defense, open information about the procurement of the "Katusha" system, the public product description by "M 13" company, and materials from the U.S. Department of Justice regarding Vladislav Klyushin.


