Report on the Investigation into Russian Interference in the 2016 Presidential Election · 2019
Intrusions into the DCCC and DNC Networks
Intrusions into the DCCC and DNC Networks
Initial Access
¶By no later than April 12, 2016, the GRU had gained access to the DCCC computer network using the credentials stolen from a DCCC employee who had been successfully spearphished th e week before. Over th e ensuing weeks, the GRU ti·aversed the network, identifying different computers connected to the DCCC network. By stealing network access credentials along the way (including those of IT administi·ators with miresti·icted access to the system), the GRU compromised approximately 29 different computers on the DCCC network. 119
¶Approximately six days after first hacking into th e DCCC network, on April 18, 2016, GRU officers gained access to the DNC network via a virtual private network (VPN) connection120 between the DCCC and DNC networks. 121 Between April 18, 2016 and June 8, 2016, Unit 26165 compromised more than 30 computers on the DNC network, including the DNC mail server and shared file server. 122
Implantation of Malware on DCCC and DNC Networks
¶Unit 26165 implanted on the DCCC an d DNC networks two types of customized malware,123 "Malwai·e" is sho1t for malicious softwai·e, and here refers to softwai·e designed to allow a third paity to infiltrate a computer without the consent or knowledge of the computer's user or operator. known as "X-Agent" an d "X-Tunnel"; Mimikatz, a credential-harvesting tool; and rar .exe, a tool used in th ese intrnsions to compile and compress materials for exfilti·ation. X-Agent was a multi-function hacking tool that allowed Unit 26165 to log keysti-okes, take screenshots, and gather other data about the infected computers (e.g., file directories, operating systems).124 [Redacted: (b) (7)(A), (b) (7)(E)] X Tunnel was a hacking tool that created an enc1ypted connection between the victim DCCC/DNC computers and GRU-conti·olled computers outside the DCCC and DNC networks that was capable of large-scale data ti·ansfers.125 [Redacted: (b) (7)(A), (b) (7)(E)] GRU officers th en used X-Tunnel to exfilti-ate stolen data from the victim computers.
¶A VPN extends a private network, allowing users to send and receive data across public networks (such as the internet) as ifthe connecting computer was directly connected to the p1ivate network. The VPN in this case had been created to give a small number of DCCC employees access to ce1t ain databases housed on the DNC network. Therefore, while the DCCC employees were outside the DNC's private network, they could access paits of the DNC network from their DCCC computers.
39¶To operate X-Agent and X-Tunnel on the DCCC an d DNC networks, Unit 26165 officers set up a group of computers outside those networks to collllllunicate with the implanted malware. 126 The first set of GRU-controlled computers, known by the GRU as "middle servers," sent and received messages to and from malware on the DNC/DCCC networks. The middle
¶Panel[QJJNIIPJMJQlt:J uiw• servers, in turn, relayed messages to a second set of GRU-controlled cojfiuters, labeled internally by the GRU as an "AMS Panel." The AMS served as a nerve center through which GRU officers monitored and directed the m alwar e's operations on the DNC/DCCC networks.127 Netyksho Indictment ,i 25.
¶The AMS Panel used to conti·?l X~A ent ~uring the DCCC and DNC intiusions was housed on a leased com uter located near An zona. 128
40¶The Arizona-based AMS Pan el also stored thousands of files containing keylogging sessions captured through X-Agent. These sessions were captured as GRU officers monitored DCCC and DNC employees' work on infected computers regularly between April 2016 and June 2016. Data captured in these keylogging sessions included passwords, internal collllllunications between employees, banking info1mation, an d sensitive personal info1mation.
Theft of Documents from DNC and DCCC Networks
¶Officers from Unit 26165 stole thousands of documents from the DCCC an d DNC networks, including significant amounts of data pertaining to th e 2016 U.S. federal elections. Stolen documents included internal strategy documents, fundraising data, opposition research, and emails from the work inboxes of DNC employees. 130
¶The GRU began stealing DCCC data sho1ily after it gained access to the network. On April 14, 2016 (approximately three days aBer the initial intru sion) GRU officers downloaded rar.exe onto th e DCCC's document server. The following day, the GRU searched one comproinised DCCC computer for files containing search ten ns that included "Hilla1y ," "DNC," "Cmz," and "Tnnnp." 131 On April 25 , 2016, the GRU collected and compressed PDF and Microsoft documents from folders on the DCCC 's shared file server that pe1iained to the 2016 election.132 The GRU appears to have compressed an d exfilti·ated over 70 gigabytes of data from this file server. 133
¶The GRU also stole documents from the DNC network sho1ily after gaining access. On April 22, 2016, the GRU copied files from the DNC network to GRU-conti·olled computers. Stolen documents included the DNC's opposition research into can didate Tmmp.i 34 Between approximately May 25, 2016 and June 1, 2016, GRU officers accessed th e DNC 's mail server from a GRU-conti·olled computer leased inside the United States. 135 Dming these connections,
41¶Unit 26165 officers appear to have stolen thousan ds of emails and attachments, which were later released by WikiLeaks in July 2016.136
Dissemination of the Hacked Materials
¶The GRU's operations extended beyond stealing materials, an d included releasing documents stolen from th e Clinton Campaign and its supporters. The GRU can ied out the anonymous release through two fictitious online personas that it created-DCLeaks and Guccifer 2.0- and later through the organization WikiLeaks.