Przejdź do treści
All posts
Workshop · OSINT22 July 2026 · ~11 min

What's really inside AZART — and why the “indestructible” radio failed

Part two. In the first part I worked out what it costs to build an AZART equivalent. Now I take the original apart: what's inside, why a “fully Russian” radio is full of Western chips, and why a network advertised as unbreakable turned out to be jammable within months.

The promise vs Ukraine

AZART was sold as a breakthrough: a sixth-generation radio, 20,000 hops per second, “unbreakable” comms. Until 2022 everything we knew about it came from the maker's brochures. Then hundreds of units ended up in Ukrainian hands — and for the first time you could look inside instead of trusting the leaflet.

PCB photos surfaced in March 2022 (Ukrainian serviceman Serhii Flash), and the crypto chip was identified by a Polish netizen. What they found clashes with the whole story of a “fully Russian, breakthrough SDR”.

Teardown: what's inside

Architecturally the AZART is a direct-sampling radio (like the Ettus USRP B200), not one integrated radio chip. The core is three parts:

BlockPartOrigin
Baseband + cryptoXilinx Spartan-6 XC6SLX75USA/AMD, fab Taiwan
TX converterAnalog Devices AD9747USA
Control processordomestic SoC ~1 GHz / 65 nmRussia (likely ELVIS)
More analog parts5× Analog DevicesUSA

“Fully Russian”? Not quite

The radio was advertised as built 100% from domestic components. Teardowns showed otherwise, and a 2024 US Senate report confirmed it: Russian military kit is dominated by four American firms — AMD (Xilinx), Analog Devices, Intel and Texas Instruments. AZART's maker had been under US sanctions since 2016, yet in 2023 radios were still assembled from Western chips. Some units were, in fact, put together in China.

The 6.7-billion-rouble scandal

The AZART contract grew into one of Russia's louder corruption scandals. General Khalil Arslanov, deputy chief of the General Staff, was responsible for the armed forces' communications — and was sentenced to 17 years in a penal colony for embezzlement around this programme (sums on the order of 6.7 billion roubles). In the background: radios bought nearly finished in China and “Russified” at home. So much for the pride of Russian engineering.

Encryption: less than advertised

The protection level is “confidential”, not “secret”. Keys are loaded from a separate device with an ignition key (like a car's) at power-up. The voice payload is encrypted, but the metadata — who's talking to whom, on what channel — goes out in the clear. There's no over-the-air rekeying (OTAR), so losing even one radio means manually rekeying all the others. For backward compatibility with the older R-168 there's also a weaker masking mode (CVSD 16 kbps).

Why it failed in Ukraine

  • The hopping is GPS-synchronised — jam navigation and the radio drops to a slow waveform or a fixed frequency, becoming easy to locate and suppress.
  • On captured radios the keys were set to 1-1-1-1-1-1, and the factory service password is 52867061.
  • No key-fill cables in the field — after losing a radio you couldn't quickly rekey the network.
  • Short of keys and infrastructure, crews transmitted in the clear, and often fell back to civilian Baofengs and phones.

What this teaches our project

Every way the original failed is a ready-made design lesson. Building the open equivalent (part one), we do exactly the opposite:

  • Hopping with no hard dependency on GPS.
  • Proper key management and over-the-air rekeying (OTAR).
  • Verified firmware boot (measured boot) — which the original simply lacks.
  • A core built on modern, legally available chips (ADRV9002 + Zynq), not a mail-order patchwork.

If you haven't read part one — that's where I work out what hardware, and at what price, would build an open equivalent of this radio using our working TETRA stack. Questions and comments welcome. 73!

SP8MB · 22 July 2026