Changes

Jump to navigation Jump to search
Line 180: Line 180:  
===Stolen Documents Released through Guccifer 2.0===
 
===Stolen Documents Released through Guccifer 2.0===
   −
40.  On or about June 14, 2016, the DNC—through Company 1—publicly announced that it had been hacked by Russian government actors.  In response, the Conspirators created the online persona Guccifer 2.0 and falsely claimed to be a lone Romanian hacker to undermine the allegations of Russian responsibility for the intrusion.
+
40.  On or about June 14, 2016, the DNC—through Company 1—publicly announced that it had been hacked by Russian government actors.  In response, the Conspirators created the online persona Guccifer 2.0 and falsely claimed to be a lone [[Romania]]n hacker to undermine the allegations of Russian responsibility for the intrusion.
   −
41.  On or about June 15, 2016, the Conspirators logged into a Moscow- based server used and managed by Unit 74455 and, between 4:19 PM and 4:56 PM Moscow Standard Time, searched for certain words and phrases, including:
+
41.  On or about June 15, 2016, the Conspirators logged into a Moscow-based server used and managed by Unit 74455 and, between 4:19 PM and 4:56 PM Moscow Standard Time, searched for certain words and phrases, including:
    
<center>Search Term(s)</center>
 
<center>Search Term(s)</center>
Line 189: Line 189:  
“some hundreds of sheets”
 
“some hundreds of sheets”
 
dcleaks
 
dcleaks
illuminati
+
[[illuminati]]
 
широко известный перевод [widely known translation]
 
широко известный перевод [widely known translation]
 
“worldwide known”
 
“worldwide known”
Line 196: Line 196:     
42.  Later that day, at 7:02 PM Moscow Standard Time, the online
 
42.  Later that day, at 7:02 PM Moscow Standard Time, the online
persona Guccifer 2.0 published its first post on a blog site created
+
persona Guccifer 2.0 published its first post on a blog site created through WordPress.  Titled “DNC’s servers hacked by a lone hacker,”the post used numerous English words and phrases that the Conspirators had searched for earlier that day (bolded below):
through WordPress.  Titled “DNC’s servers hacked by a lone hacker,
  −
the post used numerous English words and phrases that the Conspirators
  −
had searched for earlier that day (bolded below):
      
*'''Worldwide known''' cyber security company [Company 1] announced that the Democratic National Committee (DNC) servers had been hacked by “sophisticated” hacker groups.
 
*'''Worldwide known''' cyber security company [Company 1] announced that the Democratic National Committee (DNC) servers had been hacked by “sophisticated” hacker groups.
Line 210: Line 207:  
43.  Between in or around June 2016 and October 2016, the Conspirators used Guccifer 2.0 to release documents through WordPress that they had stolen from the DCCC and DNC.  The Conspirators, posing as Guccifer 2.0, also shared stolen documents with certain individuals.
 
43.  Between in or around June 2016 and October 2016, the Conspirators used Guccifer 2.0 to release documents through WordPress that they had stolen from the DCCC and DNC.  The Conspirators, posing as Guccifer 2.0, also shared stolen documents with certain individuals.
   −
:a.  On or about August 15, 2016, the Conspirators, posing as Guccifer 2.0, received a request for stolen documents from a candidate for the U.S. Congress.  The Conspirators responded using the Guccifer 2.0 persona and sent the candidate stolen documents related to the candidate’s opponent.
+
:a.  On or about August 15, 2016, the Conspirators, posing as Guccifer 2.0, received a request for stolen documents from a candidate for the U.S. Congress.  The Conspirators responded using the Guccifer 2.0 persona and sent the candidate stolen documents related to the candidate’s opponent.
    
:b.  On or about August 22, 2016, the Conspirators, posing as Guccifer 2.0, transferred approximately 2.5 gigabytes of data stolen from the DCCC to a then-registered state lobbyist and online source of political news.  The stolen data included donor records and personal identifying information for more than 2,000 Democratic donors.
 
:b.  On or about August 22, 2016, the Conspirators, posing as Guccifer 2.0, transferred approximately 2.5 gigabytes of data stolen from the DCCC to a then-registered state lobbyist and online source of political news.  The stolen data included donor records and personal identifying information for more than 2,000 Democratic donors.
   −
:c.  On or about August 22, 2016, the Conspirators, posing as Guccifer 2.0, sent a reporter stolen documents pertaining to the Black Lives Matter movement.  The reporter responded by discussing when to release the documents and offering to write an article about their release.
+
:c.  On or about August 22, 2016, the Conspirators, posing as Guccifer 2.0, sent a reporter stolen documents pertaining to the [[Black Lives Matter]] movement.  The reporter responded by discussing when to release the documents and offering to write an article about their release.
   −
44.  The Conspirators, posing as Guccifer 2.0, also communicated with U.S. persons about the release of stolen documents.  On or about August 15, 2016, the Conspirators, posing as Guccifer 2.0, wrote to a person who was in regular contact with senior members of the presidential campaign of Donald J. Trump, “ thank u for writing back . . . do u find anyt[h]ing interesting in the docs i posted ?”  On or about August 17, 2016, the Conspirators added, “ please tell me if i can help u anyhow . . .  it would be a great pleasure to me. ” On or about September 9, 2016, the Conspirators, again posing as Guccifer 2.0, referred to a stolen DCCC document posted online and asked the person, “what do u think of the info on the turnout model for the democrats entire presidential campaign. ” The person responded, “[p]retty standard.”
+
44.  The Conspirators, posing as Guccifer 2.0, also communicated with U.S. persons about the release of stolen documents.  On or about August 15, 2016, the Conspirators, posing as Guccifer 2.0, wrote to a person who was in regular contact with senior members of the presidential campaign of Donald J. Trump, “thank u for writing back . . . do u find anyt[h]ing interesting in the docs i posted ?”  On or about August 17, 2016, the Conspirators added, “ please tell me if i can help u anyhow . . .  it would be a great pleasure to me.” On or about September 9, 2016, the Conspirators, again posing as Guccifer 2.0, referred to a stolen DCCC document posted online and asked the person, “what do u think of the info on the turnout model for the democrats entire presidential campaign.” The person responded, “[p]retty standard.”
   −
45.  The Conspirators conducted operations as Guccifer 2.0 and DCLe aks using overlapping computer infrastructure and financing.
+
45.  The Conspirators conducted operations as Guccifer 2.0 and DCLesks using overlapping computer infrastructure and financing.
   −
:a.  For example, between on or about March 14, 2016 and April 28, 2016, the Conspirators used the same pool of bitcoin funds to purchase a virtual private network (“VPN”) account and to lease a server in Malaysia.  In or around June 2016, the Conspirators used the Malaysian server to host the dcleaks.com website.  On or about July 6, 2016, the Conspirators used the VPN to log into the @Guccifer_2 Twitter account.  The Conspirators opened that VPN account from the same server that was also used to register malicious domains for the hacking of the DCCC and DNC networks.
+
:a.  For example, between on or about March 14, 2016 and April 28, 2016, the Conspirators used the same pool of [[bitcoin]] funds to purchase a virtual private network (“[[VPN]]”) account and to lease a server in [[Malaysia]].  In or around June 2016, the Conspirators used the Malaysian server to host the dcleaks.com website.  On or about July 6, 2016, the Conspirators used the VPN to log into the @Guccifer_2 Twitter account.  The Conspirators opened that VPN account from the same server that was also used to register malicious domains for the hacking of the DCCC and DNC networks.
   −
:b.  On or about June 27, 2016, the Conspirators, posing as Guccifer 2.0, contacted a U.S. reporter with an offer to provide stolen emai ls from “ Hillary Clinton ’s staff.  ” The Conspirators then sent the reporter the password to access a nonpublic, password-protected portion of dcleaks.com containing emails stolen from Victim 1 by LUKASHEV, YERMAKOV, and their co-conspirators in or around March 2016.
+
:b.  On or about June 27, 2016, the Conspirators, posing as Guccifer 2.0, contacted a U.S. reporter with an offer to provide stolen emails from “ Hillary Clinton ’s staff.  ” The Conspirators then sent the reporter the password to access a nonpublic, password-protected portion of dcleaks.com containing emails stolen from Victim 1 by LUKASHEV, YERMAKOV, and their co-conspirators in or around March 2016.
    
46.  On or about January 12, 2017, the Conspirators published a statement on the Guccifer 2.0 WordPress blog, falsely claiming that the intrusions and release of stolen documents had “totally no relation to the Russian government.”
 
46.  On or about January 12, 2017, the Conspirators published a statement on the Guccifer 2.0 WordPress blog, falsely claiming that the intrusions and release of stolen documents had “totally no relation to the Russian government.”
Block, Siteadmin, SkipCaptcha, Upload, Automoderated users, delete, edit, move, nsTeam2RO, nsTeam2RW, nsTeam2_talkRO, nsTeam2_talkRW, protect, rollback, Administrators, template
292,404

edits

Navigation menu