| Line 52: |
Line 52: |
| | 2. Defendants VIKTOR BORISOVICH NETYKSHO, BORIS ALEKSEYEVICH ANTONOV, DMITRIY SERGEYEVICH BADIN, IVAN SERGEYEVICH YERMAKOV, ALEKSEY VIKTOROVICH LUKASHEV, SERGEY ALEKSANDROVICH MORGACHEV, NIKOLAY YURYEVICH KOZACHEK, PAVEL VYACHESLAVOVICH YERSHOV, ARTEM ANDREYEVICH MALYSHEV, ALEKSANDR VLADIMIROVICH OSADCHUK, and ALEKSEY ALEKSANDROVICH POTEMKIN were GRU officers who knowingly and intentionally conspired with each other, and with persons known and unknown to the Grand Jury (collectively the “Conspirators”), to gain unauthorized access (to “hack”) into the computers of U.S. persons and entities involved in the 2016 U.S. presidential election, steal documents from those computers, and stage releases of the stolen documents to interfere with the 2016 U.S.presidential election . | | 2. Defendants VIKTOR BORISOVICH NETYKSHO, BORIS ALEKSEYEVICH ANTONOV, DMITRIY SERGEYEVICH BADIN, IVAN SERGEYEVICH YERMAKOV, ALEKSEY VIKTOROVICH LUKASHEV, SERGEY ALEKSANDROVICH MORGACHEV, NIKOLAY YURYEVICH KOZACHEK, PAVEL VYACHESLAVOVICH YERSHOV, ARTEM ANDREYEVICH MALYSHEV, ALEKSANDR VLADIMIROVICH OSADCHUK, and ALEKSEY ALEKSANDROVICH POTEMKIN were GRU officers who knowingly and intentionally conspired with each other, and with persons known and unknown to the Grand Jury (collectively the “Conspirators”), to gain unauthorized access (to “hack”) into the computers of U.S. persons and entities involved in the 2016 U.S. presidential election, steal documents from those computers, and stage releases of the stolen documents to interfere with the 2016 U.S.presidential election . |
| | | | |
| − | 3. Starting in at least March 2016, the Conspirators used a variety of means to hack the email accounts of volunteers and employees of the U.S. presidential campaign of [[Hillary Clinton]] (the “[[2016 Clinton campaign|Clinton Campaign]]”), including the email account of the [[John Podesta|Clinton Campaign’s chairman]].<ref>The DNC has never denied the authenticity or veracity of the purloined content, or suggested the emails were forgeries.</ref> | + | 3. Starting in at least March 2016, the Conspirators used a variety of means to hack the email accounts of volunteers and employees of the U.S. presidential campaign of [[Hillary Clinton]] (the “[[2016 Clinton campaign|Clinton Campaign]]”), including the email account of the [[John Podesta|Clinton Campaign's chairman]].<ref>The DNC has never denied the authenticity or veracity of the purloined content, or suggested the emails were forgeries.</ref> |
| | | | |
| | 4. By in or around April 2016, the Conspirators also hacked into the computer networks of the Democratic Congressional Campaign Committee (“DCCC”) and the [[Democratic National Committee]] (“DNC ”). The Conspirators covertly monitored the computers of dozens of DCCC and DNC employees, implanted hundreds of files containing malicious computer code (“malware ”), and stole emails and other documents from the DCCC and DNC. | | 4. By in or around April 2016, the Conspirators also hacked into the computer networks of the Democratic Congressional Campaign Committee (“DCCC”) and the [[Democratic National Committee]] (“DNC ”). The Conspirators covertly monitored the computers of dozens of DCCC and DNC employees, implanted hundreds of files containing malicious computer code (“malware ”), and stole emails and other documents from the DCCC and DNC. |
| Line 72: |
Line 72: |
| | 11. Defendant DMITRIY SERGEYEVICH BADIN (Бадин Дмитрий Сергеевич) was a Russian military officer assigned to Unit 26165 who held the title “Assistant Head of Department.” In or around 2016, BADIN, along with ANTONOV, supervised other co-conspirators who targeted the DCCC, DNC, and individuals affiliated with the Clinton Campaign. | | 11. Defendant DMITRIY SERGEYEVICH BADIN (Бадин Дмитрий Сергеевич) was a Russian military officer assigned to Unit 26165 who held the title “Assistant Head of Department.” In or around 2016, BADIN, along with ANTONOV, supervised other co-conspirators who targeted the DCCC, DNC, and individuals affiliated with the Clinton Campaign. |
| | | | |
| − | 12. Defendant IVAN SERGEYEVICH YERMAKOV (Ермаков Иван Сергеевич) was a Russian military officer assigned to ANTONOV’s department within Unit 26165. Since in or around 2010, YERMAKOV used various online personas, including “ Kate S. Milton,” “ James McMorgans, ” and “Karen W. Millen ,” to conduct hacking operations on behalf of Unit 26165. In or around March 2016, YERMAKOV participated in hacking at least two email accounts from which campaign -related documents were released through DCLeaks. In or around May 2016, YERMAKOV also participated in hacking the DNC email server and stealing DNC emails that were later released through Organization 1. | + | 12. Defendant IVAN SERGEYEVICH YERMAKOV (Ермаков Иван Сергеевич) was a Russian military officer assigned to ANTONOV's department within Unit 26165. Since in or around 2010, YERMAKOV used various online personas, including “ Kate S. Milton,” “ James McMorgans, ” and “Karen W. Millen ,” to conduct hacking operations on behalf of Unit 26165. In or around March 2016, YERMAKOV participated in hacking at least two email accounts from which campaign -related documents were released through DCLeaks. In or around May 2016, YERMAKOV also participated in hacking the DNC email server and stealing DNC emails that were later released through Organization 1. |
| | | | |
| | 13. Defendant ALEKSEY VIKTOROVICH LUKASHEV (Лукашев Алексей Викторович) was a Senior Lieutenant in the Russian military assigned to ANTONOV ’s department within Unit 26165. LUKASHEV used various online personas , including “ Den Katenberg ” and “ Yuliana Martynova.” In or around 2016, LUKASHEV sent spearphishing emails to members of the Clinton Campaign and affiliated individuals, including the chairman of the Clinton Campaign. | | 13. Defendant ALEKSEY VIKTOROVICH LUKASHEV (Лукашев Алексей Викторович) was a Senior Lieutenant in the Russian military assigned to ANTONOV ’s department within Unit 26165. LUKASHEV used various online personas , including “ Den Katenberg ” and “ Yuliana Martynova.” In or around 2016, LUKASHEV sent spearphishing emails to members of the Clinton Campaign and affiliated individuals, including the chairman of the Clinton Campaign. |
| Line 78: |
Line 78: |
| | 14. Defendant SERGEY ALEKSANDROVICH MORGACHEV (Моргачев Сергей Александрович) was a Lieutenant Colonel in the Russian military assigned to Unit 26165. MORGACHEV oversaw a department within Unit 26165 dedicated to developing and managing malware, including a hacking tool used by the GRU known as “X-Agent .” During the hacking of the DCCC and DNC networks, MORGACHEV supervised the co-conspirators who developed and monitored the X- Agent malware implanted on those computers. | | 14. Defendant SERGEY ALEKSANDROVICH MORGACHEV (Моргачев Сергей Александрович) was a Lieutenant Colonel in the Russian military assigned to Unit 26165. MORGACHEV oversaw a department within Unit 26165 dedicated to developing and managing malware, including a hacking tool used by the GRU known as “X-Agent .” During the hacking of the DCCC and DNC networks, MORGACHEV supervised the co-conspirators who developed and monitored the X- Agent malware implanted on those computers. |
| | | | |
| − | 15. Defendant NIKOLAY YURYEVICH KOZACHEK (Козачек Николай Юрьевич) was a Lieutenant Captain in the Russian military assigned to MORGACHEV’s department within Unit 26165. KOZACHEK used a variety of monikers, including “ kazak ” and “blablabla1234565.” KOZACHEK developed, customized, and monitored X-Agent malware used to hack the DCCC and DNC networks beginning in or around April 2016. | + | 15. Defendant NIKOLAY YURYEVICH KOZACHEK (Козачек Николай Юрьевич) was a Lieutenant Captain in the Russian military assigned to MORGACHEV's department within Unit 26165. KOZACHEK used a variety of monikers, including “ kazak ” and “blablabla1234565.” KOZACHEK developed, customized, and monitored X-Agent malware used to hack the DCCC and DNC networks beginning in or around April 2016. |
| | | | |
| − | 16. Defendant PAVEL VYACHESLAVOVICH YERSHOV (Ершов Павел Вячеславович) was a Russian military officer assigned to MORGACHEV’s department within Unit 26165. In or around 2016, YERSHOV assisted KOZACHEK and other co-conspirators in testing and customizing X-Agent malware before actual deployment and use. | + | 16. Defendant PAVEL VYACHESLAVOVICH YERSHOV (Ершов Павел Вячеславович) was a Russian military officer assigned to MORGACHEV's department within Unit 26165. In or around 2016, YERSHOV assisted KOZACHEK and other co-conspirators in testing and customizing X-Agent malware before actual deployment and use. |
| | | | |
| − | 17. Defendant ARTEM ANDRE YEVICH MALYSHEV (Малышев Артём Андреевич) was a Second Lieutenant in the Russian military assigned to MORGACHEV’s department within Unit 26165. MALYSHEV used a variety of monikers, including “djangomagicdev” and “realblatr.” In or around 2016, MALYSHEV monitored X-Agent malware implanted on the DCCC and DNC networks. | + | 17. Defendant ARTEM ANDRE YEVICH MALYSHEV (Малышев Артём Андреевич) was a Second Lieutenant in the Russian military assigned to MORGACHEV's department within Unit 26165. MALYSHEV used a variety of monikers, including “djangomagicdev” and “realblatr.” In or around 2016, MALYSHEV monitored X-Agent malware implanted on the DCCC and DNC networks. |
| | | | |
| | 18. Defendant ALEKSANDR VLADIMIROVICH OSADCHUK (Осадчук Александр Владимирович) was a Colonel in the Russian military and the commanding officer of Unit 74455. Unit 74455 was located at 22 Kirova Street, Khimki, Moscow, a building referred to within the GRU as the “Tower.” Unit 74455 assisted in the release of stolen documents through the DCLeaks and Guccifer 2.0 personas, the promotion of those releases, and the publication of anti-Clinton content on [[social media]] accounts operated by the GRU. | | 18. Defendant ALEKSANDR VLADIMIROVICH OSADCHUK (Осадчук Александр Владимирович) was a Colonel in the Russian military and the commanding officer of Unit 74455. Unit 74455 was located at 22 Kirova Street, Khimki, Moscow, a building referred to within the GRU as the “Tower.” Unit 74455 assisted in the release of stolen documents through the DCLeaks and Guccifer 2.0 personas, the promotion of those releases, and the publication of anti-Clinton content on [[social media]] accounts operated by the GRU. |
| | | | |
| − | 19. Defendant ALEKSEY ALEKSANDROVICH POTEMKIN (Потемкин Алексей Александрович) was an officer in the Russian military assigned to Unit 74455. POTEMKIN was a supervisor in a department within Unit 74455 responsible for the administration of computer infrastructure used in cyber operations. Infrastructure and social media accounts administered by POTEMKIN’s department were used, among other things, to assist in the release of stolen documents through the DCLeaks and Guccifer 2.0 personas. | + | 19. Defendant ALEKSEY ALEKSANDROVICH POTEMKIN (Потемкин Алексей Александрович) was an officer in the Russian military assigned to Unit 74455. POTEMKIN was a supervisor in a department within Unit 74455 responsible for the administration of computer infrastructure used in cyber operations. Infrastructure and social media accounts administered by POTEMKIN's department were used, among other things, to assist in the release of stolen documents through the DCLeaks and Guccifer 2.0 personas. |
| | | | |
| | ===Object of the Conspiracy=== | | ===Object of the Conspiracy=== |
| Line 104: |
Line 104: |
| | :d. On or about April 6, 2016, the Conspirators created an email account in the name (with a one- letter deviation from the actual spelling) of a known member of the Clinton Campaign . The Conspirators then used that account to send spearphishing emails to the work accounts of more than thirty different Clinton Campaign employees. In the spearphishing emails, LUKASHEV and his co-conspirators embedded a link purporting to direct the recipient to a document titled “hillary-clinton-favorable-rating.xlsx.” In fact, this link directed the recipients’ computers to a GRU-created website. | | :d. On or about April 6, 2016, the Conspirators created an email account in the name (with a one- letter deviation from the actual spelling) of a known member of the Clinton Campaign . The Conspirators then used that account to send spearphishing emails to the work accounts of more than thirty different Clinton Campaign employees. In the spearphishing emails, LUKASHEV and his co-conspirators embedded a link purporting to direct the recipient to a document titled “hillary-clinton-favorable-rating.xlsx.” In fact, this link directed the recipients’ computers to a GRU-created website. |
| | | | |
| − | 22. The Conspirators spearphished individuals affiliated with the Clinton Campaign throughout the summer of 2016. For example, on or about July 27, 2016, the Conspirators attempted after hours to spearphish for the first time email accounts at a domain hosted by a third - party provider and used by Clinton’s personal office.<ref>As Secretary of State, Hillary Clinton stole U.S. Government records and maintained them at her personnel office before illegally destroying them.</ref> At or around the same time, they also targeted seventy-six email addresses at the domain for the Clinton Campaign. | + | 22. The Conspirators spearphished individuals affiliated with the Clinton Campaign throughout the summer of 2016. For example, on or about July 27, 2016, the Conspirators attempted after hours to spearphish for the first time email accounts at a domain hosted by a third - party provider and used by Clinton's personal office.<ref>As Secretary of State, Hillary Clinton stole U.S. Government records and maintained them at her personnel office before illegally destroying them.</ref> At or around the same time, they also targeted seventy-six email addresses at the domain for the Clinton Campaign. |
| | | | |
| | ===Hacking into the DCCC Network=== | | ===Hacking into the DCCC Network=== |
| Line 116: |
Line 116: |
| | :c. On or about April 7, 2016, YERMAKOV ran a technical query for the DCCC’s internet protocol configurations to identify connected devices. | | :c. On or about April 7, 2016, YERMAKOV ran a technical query for the DCCC’s internet protocol configurations to identify connected devices. |
| | | | |
| − | 24. By in or around April 2016, within days of YERMAKOV’s searches regarding the DCCC, the Conspirators hacked into the DCCC computer network. Once they gained access, they installed and managed different types of malware to explore the DCCC network and steal data. | + | 24. By in or around April 2016, within days of YERMAKOV's searches regarding the DCCC, the Conspirators hacked into the DCCC computer network. Once they gained access, they installed and managed different types of malware to explore the DCCC network and steal data. |
| | | | |
| | :a. On or about April 12, 2016, the Conspirators used the stolen credentials of a DCCC Employee (“DCCC Employee 1”) to access the DCCC network. DCCC Employee 1 had received a spearphishing email from the Conspirators on or about April 6, 2016, and entered her password after clicking on the link . | | :a. On or about April 12, 2016, the Conspirators used the stolen credentials of a DCCC Employee (“DCCC Employee 1”) to access the DCCC network. DCCC Employee 1 had received a spearphishing email from the Conspirators on or about April 6, 2016, and entered her password after clicking on the link . |
| Line 126: |
Line 126: |
| | :d. For example, on or about April 14, 2016, the Conspirators repeatedly activated X-Agent’s keylog and screenshot functions to surveil DCCC Employee 1’s computer activity over the course of eight hours. During that time, the Conspirators captured DCCC Employee 1’s communications with co-workers and the passwords she entered while working on [[fundraising]] and voter outreach projects. Similarly, on or about April 22, 2016, the Conspirators activated X-Agent’s keylog and screenshot functions to capture the discussions of another DCCC Employee (“DCCC Employee 2”) about the DCCC’s [[finance]]s, as well as her individual [[banking]] information and other personal topics.<ref>Obviously DCCC Employee 2 co-mingled DCCC’s finances with her individual banking information.</ref> | | :d. For example, on or about April 14, 2016, the Conspirators repeatedly activated X-Agent’s keylog and screenshot functions to surveil DCCC Employee 1’s computer activity over the course of eight hours. During that time, the Conspirators captured DCCC Employee 1’s communications with co-workers and the passwords she entered while working on [[fundraising]] and voter outreach projects. Similarly, on or about April 22, 2016, the Conspirators activated X-Agent’s keylog and screenshot functions to capture the discussions of another DCCC Employee (“DCCC Employee 2”) about the DCCC’s [[finance]]s, as well as her individual [[banking]] information and other personal topics.<ref>Obviously DCCC Employee 2 co-mingled DCCC’s finances with her individual banking information.</ref> |
| | | | |
| − | 25. On or about April 19, 2016, KOZACHEK, Y ERSHOV, and their co-conspirators remotely configured an overseas computer to relay communications between X-Agent malware and the AMS panel and then tested X-Agent’s ability to connect to this computer. The Conspirators referred to this computer as a “middle server.” The middle server acted as a proxy to obscure the connection between malware at the DCCC and the Conspirators’ AMS panel. On or about April 20, 2016, the Conspirators directed X-Agent malware on the DCCC computers to connect to this middle server and receive directions from the Conspirators. | + | 25. On or about April 19, 2016, KOZACHEK, Y ERSHOV, and their co-conspirators remotely configured an overseas computer to relay communications between X-Agent malware and the AMS panel and then tested X-Agent's ability to connect to this computer. The Conspirators referred to this computer as a “middle server.” The middle server acted as a proxy to obscure the connection between malware at the DCCC and the Conspirators’ AMS panel. On or about April 20, 2016, the Conspirators directed X-Agent malware on the DCCC computers to connect to this middle server and receive directions from the Conspirators. |
| | | | |
| | ===Hacking into the DNC Network=== | | ===Hacking into the DNC Network=== |
| Line 156: |
Line 156: |
| | 32. Despite the Conspirators’ efforts to hide their activity, beginning in or around May 2016, both the DCCC and DNC became aware that they had been hacked and hired a security company [[CrowdStrike|(“Company 1”)]] to identify the extent of the intrusions. By in or around June 2016, Company 1 took steps to exclude intruders from the networks. Despite these efforts, a Linux-based version of X-Agent, programmed to communicate with the GRU-registered domain linuxkrnl.net, remained on the DNC network until in or around October 2016. | | 32. Despite the Conspirators’ efforts to hide their activity, beginning in or around May 2016, both the DCCC and DNC became aware that they had been hacked and hired a security company [[CrowdStrike|(“Company 1”)]] to identify the extent of the intrusions. By in or around June 2016, Company 1 took steps to exclude intruders from the networks. Despite these efforts, a Linux-based version of X-Agent, programmed to communicate with the GRU-registered domain linuxkrnl.net, remained on the DNC network until in or around October 2016. |
| | | | |
| − | 33. In response to Company 1’s efforts, the Conspirators took countermeasures to maintain access to the DCCC and DNC networks. | + | 33. In response to Company 1's efforts, the Conspirators took countermeasures to maintain access to the DCCC and DNC networks. |
| | | | |
| | :a. On or about May 31, 2016, YERMAKOV searched for open-source information about Company 1 and its reporting on X-Agent and X-Tunnel. On or about June 1, 2016, the Conspirators attempted to delete traces of their presence on the DCCC network using the computer program CCleaner. | | :a. On or about May 31, 2016, YERMAKOV searched for open-source information about Company 1 and its reporting on X-Agent and X-Tunnel. On or about June 1, 2016, the Conspirators attempted to delete traces of their presence on the DCCC network using the computer program CCleaner. |
| Line 164: |
Line 164: |
| | :c. On or about June 20, 2016, after Company 1 had disabled X-Agent on the DCCC network, the Conspirators spent over seven hours unsuccessfully trying to connect to X-Agent. The Conspirators also tried to access the DCCC network using previously stolen credentials. | | :c. On or about June 20, 2016, after Company 1 had disabled X-Agent on the DCCC network, the Conspirators spent over seven hours unsuccessfully trying to connect to X-Agent. The Conspirators also tried to access the DCCC network using previously stolen credentials. |
| | | | |
| − | 34. In or around September 2016, the Conspirators also successfully gained access to DNC computers hosted on a third -party cloud-computing service. These computers contained test applications related to the DNC’s analytics. After conducting reconnaissance, the Conspirators gathered data by creating backups, or “snapshots,” of the DNC’s cloud-based systems using the cloud provider’s own technology. The Conspirators then moved the snapshots to cloud-based accounts they had registered with the same service, thereby stealing the data from the DNC. | + | 34. In or around September 2016, the Conspirators also successfully gained access to DNC computers hosted on a third -party cloud-computing service. These computers contained test applications related to the DNC's analytics. After conducting reconnaissance, the Conspirators gathered data by creating backups, or “snapshots,” of the DNC's cloud-based systems using the cloud provider's own technology. The Conspirators then moved the snapshots to cloud-based accounts they had registered with the same service, thereby stealing the data from the DNC. |
| | | | |
| | ===Stolen Documents Released through DCLeaks=== | | ===Stolen Documents Released through DCLeaks=== |
| Line 199: |
Line 199: |
| | | | |
| | *'''Worldwide known''' cyber security company [Company 1] announced that the Democratic National Committee (DNC) servers had been hacked by “sophisticated” hacker groups. | | *'''Worldwide known''' cyber security company [Company 1] announced that the Democratic National Committee (DNC) servers had been hacked by “sophisticated” hacker groups. |
| − | *I’m very pleased the company appreciated my skills so highly))) [. . .] | + | *I'm very pleased the company appreciated my skills so highly))) [. . .] |
| − | *Here are just a few docs from many thousands I extracted when hacking into DNC’s network. [. . .] | + | *Here are just a few docs from many thousands I extracted when hacking into DNC's network. [. . .] |
| − | *'''Some hundred sheets!''' This’s a serious case, isn’t it? [. . .] | + | *'''Some hundred sheets!''' This's a serious case, isn't it? [. . .] |
| − | *I guess [Company 1] customers should '''think twice about company’s competence.''' | + | *I guess [Company 1] customers should '''think twice about company's competence.''' |
| | *F[***] the '''Illuminati''' and their conspiracies!!!!!!!!! F[***] [Company 1] !!!!!!!!! | | *F[***] the '''Illuminati''' and their conspiracies!!!!!!!!! F[***] [Company 1] !!!!!!!!! |
| | | | |
| Line 289: |
Line 289: |
| | 61. On occasion, the Conspirators facilitated bitcoin payments using the same computers that they used to conduct their hacking activity, including to create and send test spearphishing emails. Additionally, one of these dedicated accounts was used by the Conspirators in or around 2015 to renew the registration of a domain (linuxkrnl.net) encoded in certain X-Agent malware installed on the DNC network. | | 61. On occasion, the Conspirators facilitated bitcoin payments using the same computers that they used to conduct their hacking activity, including to create and send test spearphishing emails. Additionally, one of these dedicated accounts was used by the Conspirators in or around 2015 to renew the registration of a domain (linuxkrnl.net) encoded in certain X-Agent malware installed on the DNC network. |
| | | | |
| − | 62. The Conspirators funded the purchase of computer infrastructure for their hacking activity in part by “mining” bitcoin. Individuals and entities can mine bitcoin by allowing their computing power to be used to verify and record payments on the bitcoin public ledger, a service for which they are rewarded with freshly -minted bitcoin. The pool of bitcoin generated from the GRU’s mining activity was used, for example, to pay a Romanian company to register the domain dcleaks.com through a payment processing company located in the United States. | + | 62. The Conspirators funded the purchase of computer infrastructure for their hacking activity in part by “mining” bitcoin. Individuals and entities can mine bitcoin by allowing their computing power to be used to verify and record payments on the bitcoin public ledger, a service for which they are rewarded with freshly -minted bitcoin. The pool of bitcoin generated from the GRU's mining activity was used, for example, to pay a Romanian company to register the domain dcleaks.com through a payment processing company located in the United States. |
| | | | |
| | 63. In addition to mining bitcoin, the Conspirators acquired bitcoin through a variety of means designed to obscure the origin of the funds. This included purchasing bitcoin through peer -to-peer exchanges, moving funds through other digital currencies, and using pre-paid cards. They also enlisted the assistance of one or more third -party exchangers who facilitated layered transactions through digital currency exchange platforms providing heightened anonymity. | | 63. In addition to mining bitcoin, the Conspirators acquired bitcoin through a variety of means designed to obscure the origin of the funds. This included purchasing bitcoin through peer -to-peer exchanges, moving funds through other digital currencies, and using pre-paid cards. They also enlisted the assistance of one or more third -party exchangers who facilitated layered transactions through digital currency exchange platforms providing heightened anonymity. |
| Line 313: |
Line 313: |
| | 67. Paragraph 18 of this Indictment relating to ALEKSANDR VLADIMIROVICH OSADCHUK is re -alleged and incorporated by reference as if fully set forth herein. | | 67. Paragraph 18 of this Indictment relating to ALEKSANDR VLADIMIROVICH OSADCHUK is re -alleged and incorporated by reference as if fully set forth herein. |
| | | | |
| − | 68. Defendant ANATOLIY SERGEYEVICH KOVALEV (Ковал ев Анатолий Сергеевич) was an officer in the Russian military assigned to Unit 74455 who worked in the GRU’s 22 Kirova Street building (the Tower). | + | 68. Defendant ANATOLIY SERGEYEVICH KOVALEV (Ковал ев Анатолий Сергеевич) was an officer in the Russian military assigned to Unit 74455 who worked in the GRU's 22 Kirova Street building (the Tower). |
| | | | |
| | 69. Defendants OSADCHUK and KOVALEV were GRU officers who knowingly and intentionally conspired with each other and with persons, known and unknown to the Grand Jury, to hack into the computers of U.S. persons and entities responsible for the administration of 2016 U.S. elections, such as state boards of elections, secretaries of state, and U.S. companies that supplied software and other technology related to the administration of U.S. elections. | | 69. Defendants OSADCHUK and KOVALEV were GRU officers who knowingly and intentionally conspired with each other and with persons, known and unknown to the Grand Jury, to hack into the computers of U.S. persons and entities responsible for the administration of 2016 U.S. elections, such as state boards of elections, secretaries of state, and U.S. companies that supplied software and other technology related to the administration of U.S. elections. |
| Line 325: |
Line 325: |
| | 71. In or around June 2016, KOVALEV and his co-conspirators researched domains used by U.S. state boards of election s, secretaries of state, and other election -related entities for website vulnerabilities. KOVALEV and his co-conspirators also searched for state political party email addresses, including filtered queries for email addresses listed on state Republican Party websites. | | 71. In or around June 2016, KOVALEV and his co-conspirators researched domains used by U.S. state boards of election s, secretaries of state, and other election -related entities for website vulnerabilities. KOVALEV and his co-conspirators also searched for state political party email addresses, including filtered queries for email addresses listed on state Republican Party websites. |
| | | | |
| − | 72. In or around July 2016, KOVALEV and his co-conspirators hacked the website of a state board of elections (“SBOE 1”) and stole information related to approximately 500,000 voters, including names, addresses, partial social security numbers, dates of birth, and driver’s license numbers. | + | 72. In or around July 2016, KOVALEV and his co-conspirators hacked the website of a state board of elections (“SBOE 1”) and stole information related to approximately 500,000 voters, including names, addresses, partial social security numbers, dates of birth, and driver's license numbers. |
| | | | |
| | 73. In or around August 2016, KOVALEV and his co -conspirators ha cked into the computers of a U.S. vendor (“ Vendor 1”) that supplied software used to verify voter registration information for the 2016 U.S. elections. KOVALEV and his co-conspirators used some of the same infrastructure to hack into Vendor 1 that they had used to hack into SBOE 1. | | 73. In or around August 2016, KOVALEV and his co -conspirators ha cked into the computers of a U.S. vendor (“ Vendor 1”) that supplied software used to verify voter registration information for the 2016 U.S. elections. KOVALEV and his co-conspirators used some of the same infrastructure to hack into Vendor 1 that they had used to hack into SBOE 1. |
| Line 333: |
Line 333: |
| | 75. In or around October 2016, KOVALEV and his co-conspirators further targeted state and county offices responsible for administering the 2016 U.S. Elections. For example, on or about October 28, 2016, KOVALEV and his co-conspirators visited the websites of certain counties in Georgia, Iowa, and Florida to identify vulnerabilities. | | 75. In or around October 2016, KOVALEV and his co-conspirators further targeted state and county offices responsible for administering the 2016 U.S. Elections. For example, on or about October 28, 2016, KOVALEV and his co-conspirators visited the websites of certain counties in Georgia, Iowa, and Florida to identify vulnerabilities. |
| | | | |
| − | 76. In or around November 2016 and prior to the 2016 U.S. presidential election, KOVALEV and his co-conspirators used an email account designed to look like a Vendor 1 email address to send over 100 spearphishing emails to organizations and personnel involved in administering elections in numerous Florida counties. The spearphishing emails contained malware that the Conspirators embedded into Word documents bearing Vendor 1’s logo. | + | 76. In or around November 2016 and prior to the 2016 U.S. presidential election, KOVALEV and his co-conspirators used an email account designed to look like a Vendor 1 email address to send over 100 spearphishing emails to organizations and personnel involved in administering elections in numerous Florida counties. The spearphishing emails contained malware that the Conspirators embedded into Word documents bearing Vendor 1's logo. |
| | | | |
| | ===Statutory Allegations=== | | ===Statutory Allegations=== |