Discovery of NTC Vulkan Infrastructure
ID: 6c8e7217-47bd-504e-860f-986bab0c15fb
STIX ID: report--6c8e7217-47bd-504e-860f-986bab0c15fb
Feed Name: Censys Blog
Date Published: 2023-11-15
Date Updated: 2026-04-27
Author: Ivonne Francia; Matt Lembright; Global Lead Of Censys Data
Censys mapped six public hosts and many certificates belonging to Moscow-based NTC Vulkan, identifying services (BigBlueButton, Jitsi, Nextcloud, GitLab, Cisco/pfSense appliances, Nginx) and discovered that certificates and website content link an internal brand, Raccoon Security, to NTC Vulkan; given previous leaked contracts indicating development of offensive tools for Russian intelligence (Scan-V, Amesit/Amezit, Krystal-2B), the report concludes these assets and affiliations merit monitoring as they could support information operations or attacks on critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
