A few observations about this op 1) Another data point in Russian SIGINT strategically leaking stolen data to push a particular narrative.
-
-
12) To clarify: leak is the RU-lang settings, not name (cover name references "Iron Felix" https://en.wikipedia.org/wiki/Felix_Dzerzhinsky …)https://twitter.com/alcebaid/status/743202087601844225 …
-
13) Another
#opsec fail. (This happened because they did an Export as PDF, and then later saved, w/ lang set to RU)https://twitter.com/daviottenheimer/status/743199165459529728 …
-
14) Tldr: this "lone hacker" uses many VMs, speaks Russian; username is founder of USSR secret police & likes laundering docs via Wikileaks.
-
15) Spot the difference: Left: doc sent to Gawker (page 210). On right, same page in https://guccifer2.wordpress.com/ pic.twitter.com/0Wogj3TXuS
-
16) Tangentially related: "VantageUploader" is the tool DNC use to share vids. JWT arg leaks author email in base64.pic.twitter.com/05OvNYRjoE
-
17) Final piece of metadata: Creation date and software used to turn DOC into the Gawker PDF (note: could be journo)pic.twitter.com/y9PoKJqTZ0
-
-
19)
@_fl01 points out "Grizli777" indicates that pirated Office (2007) was used by the hacker.https://twitter.com/_fl01/status/743226251373060097 …
- Show more
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Pwn All The Things
Robert Pritchard