CASE DOSSIER fugitive

U.S. v. Elena Alekseevna Khusyaynova (Project Lakhta)

Docket: 1:18-mj-00464 Court: U.S. District Court for the Eastern District of Virginia Opened: 2018-09-28 Sector: Electoral Systems, Social Media, Public Institutions

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$35.0 million
Managed an operating budget exceeding $35 million for covert information warfare activities.
Techniques
1
Verified mappings
Defendants
1
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the Eastern District of Virginia.
  • Primary Target Sector: Electoral Systems, Social Media, Public Institutions.
  • Documented Financial Loss: $35.0 million.
  • 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Russian chief accountant charged with managing the financial administration of Project Lakhta, a massive state-funded covert influence and cyber operation designed to sow political discord in U.S. elections.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against Electoral Systems, Social Media, Public Institutions networks. Russian chief accountant charged with managing the financial administration of Project Lakhta, a massive state-funded covert influence and cyber operation designed to sow political discord in U.S. elections.

Operational & Financial Fallout

Managed an operating budget exceeding $35 million for covert information warfare activities. Impacted Electoral Systems, Social Media, Public Institutions infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: FUGITIVE
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against Electoral Systems, Social Media, Public Institutions networks. Russian chief accountant charged with managing the financial administration of Project Lakhta, a massive state-funded covert influence and cyber operation designed to sow political discord in U.S. elections.

Adversary Kill Chain Flow

2 Documented Phases
1
Phase 1: Infiltration Perimeter Ingress
MITRE ATT&CK T1190 →

Operatives secured access to victim infrastructure within the Electoral Systems, Social Media, Public Institutions sector.

Artifacts & Tooling: Network perimeter logs
2
Phase 2: Execution Payload Deployment
MITRE ATT&CK T1486 →

Russian chief accountant charged with managing the financial administration of Project Lakhta, a massive state-funded covert influence and cyber operation designed to sow political discord in U.S. elections.

Artifacts & Tooling: Malicious payload
Real-World Blast Radius & Operational Fallout

Managed an operating budget exceeding $35 million for covert information warfare activities. Impacted Electoral Systems, Social Media, Public Institutions infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2018-09-28 indictment

Criminal complaint filed charging Khusyaynova with conspiracy to defraud the United States.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Elena Alekseevna Khusyaynova Russian Federation fugitive Pending None Chief financial accountant for Project Lakhta information warfare operation.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1584 Compromise Infrastructure
Resource Development
"Operatives purchased thousands of virtual private servers and compromised proxy networks in the United States to disguise Russian origins." Criminal Complaint ¶ 24, Page 12 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Elena Alekseevna Khusyaynova (Project Lakhta), No. 1:18-mj-00464 (U.S. District Court for the Eastern District of Virginia 2018), https://cybercaselibrary.com/cases/us-v-khusyaynova-project-lakhta/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-khusyaynova-project-lakhta" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>