CASE DOSSIER fugitive

U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)

Docket: 1:18-cr-00215 Court: U.S. District Court for the District of Columbia Opened: 2018-07-13 Sector: Political Organizations, Government

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$10.0 million
Extensive campaign disruption and federal investigative expenditure.
Techniques
5
Verified mappings
Defendants
3
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the District of Columbia.
  • Primary Target Sector: Political Organizations, Government.
  • Documented Financial Loss: $10.0 million.
  • 5 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Twelve Russian GRU military intelligence officers charged with hacking into the Democratic National Committee and Hillary Clinton presidential campaign servers, exfiltrating emails, and orchestrating strategic leaks via DCLeaks and Guccifer 2.0.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Adversary breached the target network via Spearphishing Link. Conspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains.

Operational & Financial Fallout

Extensive campaign disruption and federal investigative expenditure. Impacted Political Organizations, Government infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: FUGITIVE
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Adversary breached the target network via Spearphishing Link. Conspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains.

Adversary Kill Chain Flow

3 Documented Phases
1
Phase 1: Initial Access Initial Perimeter Infiltration
MITRE ATT&CK T1566.002 →

Conspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains.

Artifacts & Tooling: T1566.002 Spearphishing Link
2
Phase 2: Execution Host Execution & Payload Staging
MITRE ATT&CK T1059.001 →

Defendants used custom X-Agent malware and executed PowerShell scripts to automate file collection across internal exchange servers.

Artifacts & Tooling: T1059.001 PowerShell
3
Phase 3: Persistence Persistent Foothold Establishment
MITRE ATT&CK T1546.003 →

Adversaries created WMI event filters to ensure backdoor persistence whenever Windows booted.

Artifacts & Tooling: T1546.003 Windows Management Instrumentation Event Subscription
Real-World Blast Radius & Operational Fallout

Extensive campaign disruption and federal investigative expenditure. Impacted Political Organizations, Government infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2018-07-13 indictment

Special Counsel Robert Mueller unseals 11-count indictment against 12 GRU military officers.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Dmitriy Sergeyevich Badin Russian Federation fugitive Pending None GRU cyber operator indicted in D.D.C. and subject to German federal arrest warrant for the Bundestag intrusion.
Viktor Borisovich Netyksho Russian Federation fugitive Pending None Commander of GRU Unit 26165 indicted for the 2016 DNC cyber intrusions.
Boris Alekseyevich Antonov Russian Federation fugitive Pending None GRU Unit 26165 department head overseeing spearphishing operations.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1566.002 Spearphishing Link
Initial Access
"Conspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains." Indictment ¶ 21, Page 8 reviewed
T1059.001 PowerShell
Execution
"Defendants used custom X-Agent malware and executed PowerShell scripts to automate file collection across internal exchange servers." Indictment ¶ 33, Page 14 reviewed
T1583.001 Domains
Resource Development
"GRU officers registered misleading domain names such as dcleaks.com and actblues.com using cryptocurrency to stage leaks." Indictment ¶ 28, Page 12 reviewed
T1071.004 DNS Tunneling
Command and Control
"X-Agent malware used DNS tunneling over port 53 to transmit command output across restricted network perimeter firewalls." Indictment ¶ 35, Page 16 reviewed
T1546.003 Windows Management Instrumentation Event Subscription
Persistence
"Adversaries created WMI event filters to ensure backdoor persistence whenever Windows booted." Indictment ¶ 38, Page 17 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack), No. 1:18-cr-00215 (U.S. District Court for the District of Columbia 2018), https://cybercaselibrary.com/cases/us-v-netyksho-apt28-dnc/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-netyksho-apt28-dnc" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>