Report on the Investigation into Russian Interference in the 2016 Presidential Election · 2019
RUSSIAN HACKING AND DUMPING OPERATIONS
RUSSIAN HACKING AND DUMPING OPERATIONS
¶Beginning in March 2016, units of the Russian Federation's Main Intelligence Directorate of the General Staff (GRU) hacked the computers and email accounts of organizations, employees, and volunteers supporting the Clinton Campaign, including the email account of campaign chairman John Podesta. Starting in April 2016, the GRU hacked into the computer networks of the Democratic Congressional Campaign Committee (DCCC) and the Democratic National Committee (DNC). The GRU targeted hundreds of email accounts used by Clinton Campaign employees, advisors, and volunteers. In total, the GRU stole hundreds of thousands of documents from the compromised email accounts and networks.109 As discussed in Section V below, our Office charged 12 GRU officers for crimes arising from the hacking of these computers, principally with conspiring to commit computer intrusions, in violation of 18 U.S.C. §§1030 and 371. See Volume I, Section V.B, infra; Indictment, United States v. Netyksho, No. 1:18-cr-215 (D.D.C. July 13, 2018), Doc. 1 ("Netyksho Indictment"). The GRU later released stolen Clinton Campaign and DNC documents through online personas, "DCLeaks" and "Guccifer 2.0," and later through the organization WikiLeaks. The release of the documents was designed and timed to interfere with the 2016 U.S. presidential election and undermine the Clinton Campaign.
¶The Trump Campaign showed interest in the WikiLeaks releases and, in the summer and fall of 2016, Roger Stone tried to connect with WikiLeaks founder Julian Assange through intermediaries. Stone boasted to senior Campaign officials about his access to Assange. After Stone's prediction of WikiLeaks's first Clinton-related release proved true, the Trump Campaign stayed in contact with Stone about WikiLeaks's activities. The investigation was unable to resolve whether Stone played a role in WikiLeaks's release of the stolen Podesta emails on October 7, 2016, the same day a video from years earlier was published of Trump using graphic language about women.
GRU Hacking Directed at the Clinton Campaign
GRU Units Target the Clinton Campaign
¶Two military units of the GRU carried out the computer intrusions into the Clinton Campaign, DNC, and DCCC: Military Units 26165 and 74455.110 Netyksho Indictment ¶ 1. Military Unit 26165 is a GRU cyber unit dedicated to targeting military, political, governmental, and non-governmental organizations outside of Russia, including in the United States.111 Separate from this Office's indictment of GRU officers, in October 2018 a grand jury sitting in the Western District of Pennsylvania returned an indictment charging certain members of Unit 26165 with hacking the U.S. Anti-Doping Agency, the World Anti-Doping Agency, and other international sport associations. United States v. Aleksei Sergeyevich Morenets, No. 18-263 (W.D. Pa.). The unit was sub-divided into departments with different specialties. One department, for example, developed specialized malicious software ("malware"), while another department conducted large-scale spearphishing campaigns.112 A spearphishing email is designed to appear as though it originates from a trusted source, and solicits information to enable the sender to gain access to an account or network, or causes the recipient to [Redacted: (b) (7)(A), (b) (7)(E)] a bitcoin mining operation to secure bitcoins used to purchase computer infrastm cture used in hacking operations. 113
37¶Beginning in mid-March 2016, Unit 26165 had prima1y responsibility for hacking the DCCC an d DNC, as well as email accounts of individuals affiliated with the Clinton Campaign: 115
-
¶
- Unit 26165 used [Redacted: (b) (7)(A), (b) (7)(E)] to learn about [Redacted: (b) (7)(A), (b) (7)(E)]
• • •
, . [Redacted: (b) (7)(A), (b) (7)(E)] • • • •• •• I I I I I I •
began before the GRU had obtained any credentials or gained access to t ese networ s, m 1cating that the later DCCC and DNC intmsions were not crimes of oppo1iunity but rather the result of targeting. 116
-
¶
- GRU officers also sent hundreds of speai-phishing emails to the work and personal email
accounts of Clinton Campaign employees and volunteers. Between Mai·ch 10, 2016 and Mai·ch 15, 2016, Unit 26165 appears to have sent approximately 90 speai-phishing emails to email accounts at hillaiyclinton.com. Sta1iing on March 15, 2016, the GRU began tai·geting Google email accounts used by Clinton Campaign employees, along with a smaller number of dnc.org email accounts.117
¶The GRU speai-phishing operation enabled it to gain access to numerous email accounts of Clinton Campaign employees and volunteers, including campaign chaiim an John Podesta, junior volunteers assigned to the Clinton Campaign 's advance team, info1mal Clinton Campaign advisors, an d a DNC employee.11 8 GRU officers stole tens of thousan ds of emails from speai-phishing victims, including vai·ious Clinton Campaign-related collllllunications.
¶download malware that enables the sender to gain access to an account or network. Netyksho Indictment ,i 10.
¶. Bitcoin mining consists of unlocking new bitcoins by solving computational problems. - illllll kept its newly mined coins in an account on the bitcoin exchange platfo1m CEX.io. To i : ~ ases, the GRU routed funds into other accounts through transactions designed to obscure the source of funds . Netyksho Indictment ,i 62.
¶Netyksho Indictment ,i 69.
Netyksho Indictment ,i 9. See SM-2589105, se1ials 144 & 495 .
¶118 [Redacted: (b) (7)(A), (b) (7)(E)]
38