| Line 138: |
Line 138: |
| | ===Theft of DCCC and DNC Documents=== | | ===Theft of DCCC and DNC Documents=== |
| | | | |
| − | 27. The Conspirators searched for and identified computers within the DCCC and DNC networks that stored information related to the 2016 U.S. presidential election. For example, on or about April 15, 2016, the Conspirators searched one hacked DCCC computer for terms that included “hillary,” “cruz,” and “trump .” The Conspirators also copied select DCCC folders , including “Benghazi Investigations.” The Conspirators targeted computers containing information such as opposition research and field operation plans for the 2016 elections. | + | 27. The Conspirators searched for and identified computers within the DCCC and DNC networks that stored information related to the 2016 U.S. presidential election. For example, on or about April 15, 2016, the Conspirators searched one hacked DCCC computer for terms that included “hillary,” “[[Ted Cruz|cruz]],” and “trump .” The Conspirators also copied select DCCC folders , including “[[Benghazi massacre|Benghazi Investigations]].” The Conspirators targeted computers containing information such as opposition research and field operation plans for the 2016 elections. |
| | | | |
| − | 28. To enable them to steal a large number of documents at once without detection , the Conspirators used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks. The Conspirators then used other GRU malware, known as “X-Tunnel,” to move the stolen documents outside the DCCC and DNC networks through encrypted channels. | + | 28. To enable them to steal a large number of documents at once without detection, the Conspirators used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks. The Conspirators then used other GRU malware, known as “X-Tunnel,” to move the stolen documents outside the DCCC and DNC networks through encrypted channels. |
| | | | |
| − | :a. For example, on or about April 22, 2016, the Conspirators compressed gigabytes of data from DNC computers, including opposition research. The Conspirators later moved the compressed DNC data using X-Tunnel to a GRU-leased computer located in Illinois. | + | :a. For example, on or about April 22, 2016, the Conspirators compressed gigabytes of data from DNC computers, including opposition research. The Conspirators later moved the compressed DNC data using X-Tunnel to a GRU-leased computer located in [[Illinois]]. |
| | | | |
| − | :b. On or about Apri l 28, 2016, the Conspirators connected to and tested the same computer located in Illinois . Later that day, the Conspirators used X-Tunnel to connect to that computer to steal additional documents from the DCCC network. | + | :b. On or about April 28, 2016, the Conspirators connected to and tested the same computer located in Illinois . Later that day, the Conspirators used X-Tunnel to connect to that computer to steal additional documents from the DCCC network. |
| | | | |
| − | 29. Between on or about May 25, 2016 and June 1, 2016, the Conspirators hacked the DNC Microsoft E xchange Server and stole thousands of emails from the work accounts of DNC employees. During that time, YERMAKOV researched PowerShell commands related to accessing and managing the Microsoft Exchange S erver. | + | 29. Between on or about May 25, 2016 and June 1, 2016, the Conspirators hacked the DNC Microsoft Exchange Server and stole thousands of emails from the work accounts of DNC employees. During that time, YERMAKOV researched PowerShell commands related to accessing and managing the Microsoft Exchange Server. |
| | | | |
| | 30. On or about May 30, 2016, MALYSHEV accessed the AMS panel in order to upgrade custom AMS software on the server. That day, the AMS panel received updates from approximately thirteen different X-Agent malware implants on DCCC and DNC computers. | | 30. On or about May 30, 2016, MALYSHEV accessed the AMS panel in order to upgrade custom AMS software on the server. That day, the AMS panel received updates from approximately thirteen different X-Agent malware implants on DCCC and DNC computers. |
| | | | |
| − | 31. During the hacking of the DCCC and DNC networks, the Conspirators covered their tracks by intentionally deleting logs and computer files. For example, on or about May 13, 2016, the Conspirators cleared the event logs from a DNC computer. On or about June 20, 2016, the Conspirators deleted logs from the AMS panel that documented the ir activities on the panel, including the login history. Efforts to Remain on the DCCC and DNC Networks | + | 31. During the hacking of the DCCC and DNC networks, the Conspirators covered their tracks by intentionally deleting logs and computer files. For example, on or about May 13, 2016, the Conspirators cleared the event logs from a DNC computer. On or about June 20, 2016, the Conspirators deleted logs from the AMS panel that documented their activities on the panel, including the login history. |
| | | | |
| − | 32. Despite the Conspirators’ efforts to hide their activity , beginning in or around May 2016, both the DCCC and DNC became aware that they had been hacked and hired a security company [[CrowdStrike|(“Company 1”)]] to identify the extent of the intrusions. By in or around June 2016, Company 1 took steps to exclude intruders from the networks. D espite these efforts, a Linux-based version of X-Agent, programmed to communicate with the GRU-registered domain linuxkrnl.net, remained on the DNC network until in or around October 2016. | + | ===Efforts to Remain on the DCCC and DNC Networks=== |
| | + | |
| | + | 32. Despite the Conspirators’ efforts to hide their activity , beginning in or around May 2016, both the DCCC and DNC became aware that they had been hacked and hired a security company [[CrowdStrike|(“Company 1”)]] to identify the extent of the intrusions. By in or around June 2016, Company 1 took steps to exclude intruders from the networks. Despite these efforts, a Linux-based version of X-Agent, programmed to communicate with the GRU-registered domain linuxkrnl.net, remained on the DNC network until in or around October 2016. |
| | | | |
| | 33. In response to Company 1’s efforts , the Conspirators took countermeasures to maintain access to the DCCC and DNC networks. | | 33. In response to Company 1’s efforts , the Conspirators took countermeasures to maintain access to the DCCC and DNC networks. |
| | | | |
| − | :a. On or about May 31, 2016, YERMAKOV search ed for open-source information about Company 1 and its reporting on X-Agent and X-Tunnel. On or about June 1, 2016, the Conspirators attempted to delete traces of their presence on the DCCC network using the computer program CCleaner. | + | :a. On or about May 31, 2016, YERMAKOV searched for open-source information about Company 1 and its reporting on X-Agent and X-Tunnel. On or about June 1, 2016, the Conspirators attempted to delete traces of their presence on the DCCC network using the computer program CCleaner. |
| | | | |
| − | :b. On or about June 14, 2016, the Conspirators registered the domain actblues.com, which mimic ked the domain of a political fundraising platform that included a DCCC donations page. Shortly thereafter, the Conspirators used stolen DCCC credentials to modify the DCCC website and redirect visitors to the actblues.com domain. | + | :b. On or about June 14, 2016, the Conspirators registered the domain actblues.com, which mimicked the domain of a political fundraising platform that included a DCCC donations page. Shortly thereafter, the Conspirators used stolen DCCC credentials to modify the DCCC website and redirect visitors to the actblues.com domain. |
| | | | |
| − | :c. On or a bout June 20, 2016, after Company 1 had disabled X-Agent on the DCCC network, the Conspirators spent over seven hours unsuccessfully trying to connect to X-Agent. The Conspirators also tried to access the DCCC network using previously stolen credentials. | + | :c. On or about June 20, 2016, after Company 1 had disabled X-Agent on the DCCC network, the Conspirators spent over seven hours unsuccessfully trying to connect to X-Agent. The Conspirators also tried to access the DCCC network using previously stolen credentials. |
| | | | |
| − | 34. In or around September 2016, the Conspirators also successfully gained access to DNC computers hosted on a third -party cloud-computing service. These computers contained test applications related to the DNC’s analytics. After conducting reconnaissance, the Conspirators gathered data by creating backups, or “snapshots,” of the DNC’s cloud- based systems using the cloud provider’s own technology. The Conspirators then moved the snapshots to cloud- based accounts they had registered with the same service, thereby stealing the data from the DNC. | + | 34. In or around September 2016, the Conspirators also successfully gained access to DNC computers hosted on a third -party cloud-computing service. These computers contained test applications related to the DNC’s analytics. After conducting reconnaissance, the Conspirators gathered data by creating backups, or “snapshots,” of the DNC’s cloud-based systems using the cloud provider’s own technology. The Conspirators then moved the snapshots to cloud-based accounts they had registered with the same service, thereby stealing the data from the DNC. |
| | | | |
| | ===Stolen Documents Released through DCLeaks=== | | ===Stolen Documents Released through DCLeaks=== |