In Ukraine, a Malware Expert Who Could Blow the Whistle on Russian Hacking – New York Times
There is no evidence that Profexer worked, at least knowingly, for Russias intelligence services, but his malware apparently did.
That a hacking operation that Washington is convinced was orchestrated by Moscow would obtain malware from a source in Ukraine perhaps the Kremlins most bitter enemy sheds considerable light on the Russian security services modus operandi in what Western intelligence agencies say is their clandestine cyberwar against the United States and Europe.
It does not suggest a compact team of government employees who write all their own code and carry out attacks during office hours in Moscow or St. Petersburg, but rather a far looser enterprise that draws on talent and hacking tools wherever they can be found.
Also emerging from Ukraine is a sharper picture of what the United States believes is a Russian government hacking group known as Advanced Persistent Threat 28 or Fancy Bear. It is this group, which American intelligence agencies believe is operated by Russian military intelligence, that has been blamed, along with a second Russian outfit known as Cozy Bear, for the D.N.C. intrusion.
Rather than training, arming and deploying hackers to carry out a specific mission like just another military unit, Fancy Bear and its twin Cozy Bear have operated more as centers for organization and financing; much of the hard work like coding is outsourced to private and often crime-tainted vendors.
In more than a decade of tracking suspected Russian-directed cyberattacks against a host of targets in the West and in former Soviet territories NATO, electrical grids, research groups, journalists critical of Russia and political parties, to name a few security services around the world have identified only a handful of people who are directly involved in either carrying out such attacks or providing the cyberweapons that were used.
This absence of reliable witnesses has left ample room for President Trump and others to raise doubts about whether Russia really was involved in the D.N.C. hack.
There is not now and never has been a single piece of technical evidence produced that connects the malware used in the D.N.C. attack to the G.R.U., F.S.B. or any agency of the Russian government, said Jeffrey Carr, the author of a book on cyberwarfare. The G.R.U. is Russias military intelligence agency, and the F.S.B. its federal security service.
United States intelligence agencies, however, have been unequivocal in pointing a finger at Russia.
Seeking a path out of this fog, cybersecurity researchers and Western law enforcement officers have turned to Ukraine, a country that Russia has used for years as a laboratory for a range of politicized operations that later cropped up elsewhere, including electoral hacking in the United States.
In several instances, certain types of computer intrusions, like the use of malware to knock out crucial infrastructure or to pilfer email messages later released to tilt public opinion, occurred in Ukraine first. Only later were the same techniques used in Western Europe and the United States.
So, not surprisingly, those studying cyberwar in Ukraine are now turning up clues in the investigation of the D.N.C. hack, including the discovery of a rare witness.
Security experts were initially left scratching their heads when the Department of Homeland Security on Dec. 29 released technical evidence of Russian hacking that seemed to point not to Russia, but rather to Ukraine.
In this initial report, the department released only one sample of malware said to be an indicator of Russian state-sponsored hacking, though outside experts said a variety of malicious programs were used in Russian electoral hacking.
The sample pointed to a malware program, called the P.A.S. web shell, a hacking tool advertised on Russian-language Dark Web forums and used by cybercriminals throughout the former Soviet Union. The author, Profexer, is a well-regarded technical expert among hackers, spoken about with awe and respect in Kiev.
He had made it available to download, free, from a website that asked only for donations, ranging from $3 to $250. The real money was made by selling customized versions and by guiding his hacker clients in its effective use. It remains unclear how extensively he interacted with the Russian hacking team.
After the Department of Homeland Security identified his creation, he quickly shut down his website and posted on a closed forum for hackers, called Exploit, that Im not interested in excessive attention to me personally.
Soon, a hint of panic appeared, and he posted a note saying that, six days on, he was still alive.
Another hacker, with the nickname Zloi Santa, or Bad Santa, suggested the Americans would certainly find him, and place him under arrest, perhaps during a layover at an airport.
It could be, or it could not be, it depends only on politics, Profexer responded. If U.S. law enforcement wants to take me down, they will not wait for me in some countrys airport. Relations between our countries are so tight I would be arrested in my kitchen, at the first request.
In fact, Serhiy Demediuk, chief of the Ukrainian Cyber Police, said in an interview that Profexer went to the authorities himself. As the cooperation began, Profexer went dark on hacker forums. He last posted online on Jan. 9. Mr. Demediuk said he had made the witness available to the F.B.I., which has posted a full-time cybersecurity expert in Kiev as one of four bureau agents stationed at the United States Embassy there. The F.B.I. declined to comment.
Profexer was not arrested because his activities fell in a legal gray zone, as an author but not a user of malware, the Ukrainian police say. But he did know the users, at least by their online handles. He told us he didnt create it to be used in the way it was, Mr. Demediuk said.
A member of Ukraines Parliament with close ties to the security services, Anton Gerashchenko, said that the interaction was online or by phone and that the Ukrainian programmer had been paid to write customized malware without knowing its purpose, only later learning it was used in the D.N.C. hack.
Mr. Gerashchenko described the author only in broad strokes, to protect his safety, as a young man from a provincial Ukrainian city. He confirmed that the author turned himself in to the police and was cooperating as a witness in the D.N.C. investigation. He was a freelancer and now he is a valuable witness, Mr. Gerashchenko said.
While it is not known what Profexer has told Ukrainian investigators and the F.B.I. about Russias hacking efforts, evidence emanating from Ukraine has again provided some of the clearest pictures yet about Fancy Bear, or Advanced Persistent Threat 28, which is run by the G.R.U.
Fancy Bear has been identified mostly by what it does, not by who does it. One of its recurring features has been the theft of emails and its close collaboration with the Russian state news media.
Tracking the bear to its lair, however, has so far proved impossible, not least because many experts believe that no such single place exists.
Even for a sophisticated tech company like Microsoft, singling out individuals in the digital miasma has proved just about impossible. To curtail the damage to clients operating systems, the company filed a complaint against Fancy Bear last year with the United States District Court for the Eastern District of Virginia but found itself boxing with shadows.
As Microsoft lawyers reported to the court, because defendants used fake contact information, anonymous Bitcoin and prepaid credit cards and false identities, and sophisticated technical means to conceal their identities, when setting up and using the relevant internet domains, defendants true identities remain unknown.
Nevertheless, Ukrainian officials, though wary of upsetting the Trump administration, have been quietly cooperating with American investigators to try to figure out who stands behind all the disguises.
Included in this sharing of information were copies of the server hard drives of Ukraines Central Election Commission, which were targeted during a presidential election in May 2014. That the F.B.I. had obtained evidence of this earlier, Russian-linked electoral hack has not been previously reported.
Traces of the same malicious code, this time a program called Sofacy, were seen in the 2014 attack in Ukraine and later in the D.N.C. intrusion in the United States.
Intriguingly, in the cyberattack during the Ukrainian election, what appears to have been a bungle by Channel 1, a Russian state television station, inadvertently implicated the government authorities in Moscow.
Hackers had loaded onto a Ukrainian election commission server a graphic mimicking the page for displaying results. This phony page showed a shocker of an outcome: an election win for a fiercely anti-Russian, ultraright candidate, Dmytro Yarosh. Mr. Yarosh in reality received less than 1 percent of the vote.
The false result would have played into a Russian propaganda narrative that Ukraine today is ruled by hard-right, even fascist, figures.
The fake image was programmed to display when polls closed, at 8 p.m., but a Ukrainian cybersecurity company, InfoSafe, discovered it just minutes earlier and unplugged the server.
State television in Russia nevertheless reported that Mr. Yarosh had won and broadcast the fake graphic, citing the election commissions website, even though the image had never appeared there. The hacker had clearly provided Channel 1 with the same image in advance, but the reporters had failed to check that the hack actually worked.
For me, this is an obvious link between the hackers and Russian officials, said Victor Zhora, director of InfoSafe, the cybersecurity company that first found the fake graphic.
A Ukrainian government researcher who studied the hack, Nikolai Koval, published his findings in a 2015 book, Cyberwar in Perspective, and identified the Sofacy malware on the server.
The mirror of the hard drive went to the F.B.I., which had this forensic sample when the cybersecurity company CrowdStrike identified the same malware two years later, on the D.N.C. servers.
It was the first strike, Mr. Zhora said of the earlier hack of Ukraines electoral computers. Ukraines Cyber Police have also provided the F.B.I. with copies of server hard drives showing the possible origins of some phishing emails targeting the Democratic Party during the election.
In 2016, two years after the election hack in Ukraine, hackers using some of the same techniques plundered the email system of the World Anti-Doping Agency, or WADA, which had accused Russian athletes of systematic drug use.
That raid, too, seems to have been closely coordinated with Russian state television, which began airing well-prepared reports about WADAs hacked emails just minutes after they were made public. The emails appeared on a website that announced that WADA had been hacked by a group calling itself the Fancy Bears Hack Team.
It was the first time Fancy Bear had broken cover.
Fancy Bear remains extraordinarily elusive, however. To throw investigators off its scent, the group has undergone various makeovers, restocking its arsenal of malware and sometimes hiding under different guises. One of its alter egos, cyberexperts believe, is Cyber Berkut, an outfit supposedly set up in Ukraine by supporters of the countrys pro-Russian president, Viktor F. Yanukovych, who was ousted in 2014.
After lying dormant for many months, Cyber Berkut jumped back into action this summer just as multiple investigations in Washington into whether the Trump campaign colluded with Moscow shifted into high gear. Cyber Berkut released stolen emails that it and Russian state news media said had exposed the real story: Hillary Clinton had colluded with Ukraine.
Continued here:
In Ukraine, a Malware Expert Who Could Blow the Whistle on Russian Hacking - New York Times
- Russia issues school textbook saying it was 'forced' to march into Ukraine - Reuters - January 27th, 2025 [January 27th, 2025]
- Russia introduces history textbook that redefines war against Ukraine as justified defense. - Kyiv Independent - January 27th, 2025 [January 27th, 2025]
- Bad Things Happened: Trump Still Doesnt Understand the Ukraine War - The Bulwark - January 27th, 2025 [January 27th, 2025]
- Russia says its troops have captured a strategic town in eastern Ukraine - The Associated Press - January 27th, 2025 [January 27th, 2025]
- NATO chief: Cost of Russian victory in Ukraine would be trillions not billions - Atlantic Council - January 27th, 2025 [January 27th, 2025]
- For Russian Forces In Ukraine, Its Now Normal To Ride Into Battle In A Compact Car - Forbes - January 27th, 2025 [January 27th, 2025]
- Opinion: Trump promised to end the Ukraine war, but neither side is ready - Los Angeles Times - January 27th, 2025 [January 27th, 2025]
- Putin echoes Trump's claim that conflict in Ukraine could have been avoided had he been in office - The Associated Press - January 27th, 2025 [January 27th, 2025]
- Russia says it sees no signs that Ukraine and the West are ready for peace talks despite all statements - Reuters - January 27th, 2025 [January 27th, 2025]
- Zelenskiy says Trump could end Ukraine war only if Kyiv included in talks - Reuters - January 27th, 2025 [January 27th, 2025]
- War in Ukraine: EU to Agree to Extend Russia Sanctions, Hungary to Back Down - Bloomberg - January 27th, 2025 [January 27th, 2025]
- Letters: Stop the fireworks; angry about McCoy story; end war in Ukraine - VC Star - January 27th, 2025 [January 27th, 2025]
- Zelenskiy Says Ukraine Ready to Transit Gas From Azerbaijan - Bloomberg - January 27th, 2025 [January 27th, 2025]
- Why peace talks between Ukraine and Russia are not as simple as Trump makes out - The Independent - January 27th, 2025 [January 27th, 2025]
- Trump tells Putin to end 'ridiculous war' in Ukraine or face new sanctions - BBC.com - January 26th, 2025 [January 26th, 2025]
- Ukraine-Russia latest: Putin ready for Trump negotiations as Kyiv sets oil refinery ablaze with drone strike - The Independent - January 26th, 2025 [January 26th, 2025]
- Ukraine is reforming its recruitment efforts to attract younger soldiers and boost forces - The Associated Press - January 26th, 2025 [January 26th, 2025]
- Europe considers sending troops to Ukraine if theres a ceasefire. But would Russia accept? - The Associated Press - January 26th, 2025 [January 26th, 2025]
- Opinion: I spent Trumps inauguration in Ukraine. This is what I saw. - Salt Lake Tribune - January 26th, 2025 [January 26th, 2025]
- Putin claims Ukraine crisis may have been averted if Trump was president - CNN - January 26th, 2025 [January 26th, 2025]
- Did Ukraine Kill Its Own by Downing a Russian Plane? A Year Later, It Hasnt Said. - The New York Times - January 26th, 2025 [January 26th, 2025]
- Russia claims its troops are in the last stages of taking another eastern Ukraine town - The Associated Press - January 26th, 2025 [January 26th, 2025]
- Ukraine Is Losing Fewer Soldiers Than Russia but Its Still Losing the War - The New York Times - January 26th, 2025 [January 26th, 2025]
- Does Putin know why Ukraine fights on? Because we prize freedom above stability and wealth | Andrey Kurkov - The Guardian - January 26th, 2025 [January 26th, 2025]
- Russia rejects idea of NATO peacekeepers in Ukraine, warning of "uncontrollable escalation" - Reuters - January 26th, 2025 [January 26th, 2025]
- Trump's threat against Moscow on Ukraine seen as an insulting false start by some in Russia - NBC News - January 26th, 2025 [January 26th, 2025]
- UKs 100-year partnership with Ukraine is a meaningless political stunt - Al Jazeera English - January 26th, 2025 [January 26th, 2025]
- Putin says he and Trump should meet to discuss Ukraine and energy prices - Reuters - January 26th, 2025 [January 26th, 2025]
- Putin ready for negotiations with Trump on Ukraine war - The Guardian - January 26th, 2025 [January 26th, 2025]
- US arms exports hit record in 2024 on Ukraine-related demand - Reuters - January 26th, 2025 [January 26th, 2025]
- This Ones Mine. Ukraine Says Russia Is Executing More POWs and Capturing It on Video. - The Wall Street Journal - January 26th, 2025 [January 26th, 2025]
- Russia Brushes Off Trumps Threats on Ukraine - The Wall Street Journal - January 26th, 2025 [January 26th, 2025]
- Russia: Nothing new in Trump threats on Moscows war on Ukraine - VOA Asia - January 26th, 2025 [January 26th, 2025]
- Video: The Kremlin responds to Trump calling on Putin to make a deal with Ukraine - CNN - January 26th, 2025 [January 26th, 2025]
- To end the Russia-Ukraine war, Trump will need to get leverage - The Hill - January 26th, 2025 [January 26th, 2025]
- Ukraine's Kursk invasion was a risky play, but it might have nailed the timing - Business Insider - January 26th, 2025 [January 26th, 2025]
- Trump leans in on targeting Russian oil revenue as he tries to fulfill pledge to end Ukraine war - The Associated Press - January 26th, 2025 [January 26th, 2025]
- 'He shouldn't have done that': Donald Trump criticizes Ukraine president over war - USA TODAY - January 26th, 2025 [January 26th, 2025]
- Putin open for talks with Trump over Ukraine war and calls for leaders to meet - The Independent - January 26th, 2025 [January 26th, 2025]
- Business elites truly believe Trump could be on the verge of solving one of the world's most difficult problems: The Ukraine War - New York Post - January 26th, 2025 [January 26th, 2025]
- Kyiv investigates another case of Russian soldiers executing Ukraine POWs - POLITICO Europe - January 26th, 2025 [January 26th, 2025]
- Ukrainian winemaker and US veterans team up to show the best of Ukraine, a glass at a time - The Associated Press - January 26th, 2025 [January 26th, 2025]
- Is Trump changing tack on ending the war in Ukraine? - The Conversation Indonesia - January 26th, 2025 [January 26th, 2025]
- Shared Challenges: Israel Considers Sending Russian Weapons Seized From Hezbollah to Ukraine - Foundation for Defense of Democracies - January 26th, 2025 [January 26th, 2025]
- Ukrainian troops say inexperienced North Koreans are making easy targets - The Washington Post - December 16th, 2024 [December 16th, 2024]
- Ukraine says it has laser weapon able to down targets flying at over 2km - Yahoo! Voices - December 16th, 2024 [December 16th, 2024]
- Berlin eyes role in Ukraine peace deal but says too early for decisions - Reuters - December 16th, 2024 [December 16th, 2024]
- Keep Ukraine Out of Talks to End Its War - Foreign Policy - December 16th, 2024 [December 16th, 2024]
- Ukraine and US say some North Korean troops have been killed fighting alongside Russian forces - The Associated Press - December 16th, 2024 [December 16th, 2024]
- Russia aims to win the war in Ukraine in 2025, top official says - Semafor - December 16th, 2024 [December 16th, 2024]
- Trump suggests reversing permission for Ukraine to use US missiles in Russia - The Telegraph - December 16th, 2024 [December 16th, 2024]
- Trump to Europe: Overseeing a Ukraine Cease-Fire Would Be Your Job - The Wall Street Journal - December 16th, 2024 [December 16th, 2024]
- The Price of Russian Victory: Why Letting Putin Win Would Cost America More Than Supporting Ukraine - Foreign Affairs Magazine - December 16th, 2024 [December 16th, 2024]
- They said we were American spies: Priests describe Russias crackdown on Evangelicals in occupied Ukraine - CNN - December 16th, 2024 [December 16th, 2024]
- Trump says it was 'stupid' for Biden to let Ukraine use US weapons to strike deeper into Russia - The Associated Press - December 16th, 2024 [December 16th, 2024]
- Cajole, Plead and Flatter: Ukraine Makes Its Case to Trump - The New York Times - December 16th, 2024 [December 16th, 2024]
- Ukraine-Russia war map: Where Putins forces are making gains in eastern Ukraine - The Independent - December 16th, 2024 [December 16th, 2024]
- Europe Needs to Swiftly Fulfil Its Aid Pledges to Ukraine - Bloomberg - December 16th, 2024 [December 16th, 2024]
- Ukraine says it has laser weapon able to down targets flying at over 2km - Reuters - December 16th, 2024 [December 16th, 2024]
- Trump says deal needed to stop Ukraine war, will talk to Putin and Zelenskiy - Reuters - December 16th, 2024 [December 16th, 2024]
- Were 750,000 additional lives wasted in Ukraine for less than nothing? - The Hill - December 16th, 2024 [December 16th, 2024]
- Ukraine war: US gives $20bn to Kyiv funded by seized Russian assets - BBC.com - December 10th, 2024 [December 10th, 2024]
- Trump calls for immediate ceasefire in Ukraine and says a US withdrawal from NATO is possible - The Associated Press - December 10th, 2024 [December 10th, 2024]
- How Trump Can Win the Peace in Ukraine - The Atlantic - December 10th, 2024 [December 10th, 2024]
- Ukraine-Russia latest: Zelensky wont sacrifice young troops to Putins forces for more weapons from West - The Independent - December 10th, 2024 [December 10th, 2024]
- Biden is rushing aid to Ukraine. Both sides are digging in. And everyone is bracing for Trump - The Associated Press - December 10th, 2024 [December 10th, 2024]
- Russian prison boss killed in car blast in occupied Ukraine - BBC.com - December 10th, 2024 [December 10th, 2024]
- Kremlin says Ukraine war will go on until Putin's goals are met on battlefield or by negotiation - Reuters - December 10th, 2024 [December 10th, 2024]
- Russia targets Ukraine's energy grid as winter sets in. Here's how one plant copes - NPR - December 10th, 2024 [December 10th, 2024]
- Deadly Russian strike kills at least three in Ukraine's Zaporizhzhia - Euronews - December 10th, 2024 [December 10th, 2024]
- How Trump Could End the War in Ukraine - The Atlantic - December 10th, 2024 [December 10th, 2024]
- War in Ukraine: The woman turning amputees into 'superhumans' - BBC.com - December 10th, 2024 [December 10th, 2024]
- Zelensky salutes Trump's 'strong resolve' to end war in Ukraine - FRANCE 24 English - December 10th, 2024 [December 10th, 2024]
- US announces nearly $1 billion more in longer-term weapons support for Ukraine - The Associated Press - December 10th, 2024 [December 10th, 2024]
- Amid U.S. pressure, Ukraine starts thinking about drafting 18-year-olds - The Washington Post - December 10th, 2024 [December 10th, 2024]
- Zelenskyy open to Western troops providing security for end to war in Ukraine - The Associated Press - December 10th, 2024 [December 10th, 2024]
- Ukraine to raise NATO invite, security guarantees at meeting with European allies - Reuters - December 10th, 2024 [December 10th, 2024]
- Kyiv reveals total Ukraine casualties in Putins war for first time - POLITICO Europe - December 10th, 2024 [December 10th, 2024]
- Bill Browder on saving Ukraine, NATO, and the threat of Vladimir Putin - the1a.org - December 10th, 2024 [December 10th, 2024]
- Biden is rushing aid to Ukraine as everyone braces for Trump - FOX 5 DC - December 10th, 2024 [December 10th, 2024]