U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)
Key Facts
- Legal Status: FUGITIVE in U.S. District Court for the District of Columbia.
- Primary Target Sector: Political Organizations, Government.
- Documented Financial Loss: $10.0 million.
- 5 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Adversary breached the target network via Spearphishing Link. Conspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains.
Operational & Financial Fallout
Extensive campaign disruption and federal investigative expenditure. Impacted Political Organizations, Government infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Adversary breached the target network via Spearphishing Link. Conspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains.
Adversary Kill Chain Flow
3 Documented PhasesConspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains.
Defendants used custom X-Agent malware and executed PowerShell scripts to automate file collection across internal exchange servers.
Adversaries created WMI event filters to ensure backdoor persistence whenever Windows booted.
Extensive campaign disruption and federal investigative expenditure. Impacted Political Organizations, Government infrastructure and associated victim operations.
Procedural & Incident Timeline
Special Counsel Robert Mueller unseals 11-count indictment against 12 GRU military officers.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Dmitriy Sergeyevich Badin | Russian Federation | fugitive | Pending | None | GRU cyber operator indicted in D.D.C. and subject to German federal arrest warrant for the Bundestag intrusion. |
| Viktor Borisovich Netyksho | Russian Federation | fugitive | Pending | None | Commander of GRU Unit 26165 indicted for the 2016 DNC cyber intrusions. |
| Boris Alekseyevich Antonov | Russian Federation | fugitive | Pending | None | GRU Unit 26165 department head overseeing spearphishing operations. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1566.002 | Spearphishing Link Initial Access | "Conspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains." | Indictment ¶ 21, Page 8 | reviewed |
| T1059.001 | PowerShell Execution | "Defendants used custom X-Agent malware and executed PowerShell scripts to automate file collection across internal exchange servers." | Indictment ¶ 33, Page 14 | reviewed |
| T1583.001 | Domains Resource Development | "GRU officers registered misleading domain names such as dcleaks.com and actblues.com using cryptocurrency to stage leaks." | Indictment ¶ 28, Page 12 | reviewed |
| T1071.004 | DNS Tunneling Command and Control | "X-Agent malware used DNS tunneling over port 53 to transmit command output across restricted network perimeter firewalls." | Indictment ¶ 35, Page 16 | reviewed |
| T1546.003 | Windows Management Instrumentation Event Subscription Persistence | "Adversaries created WMI event filters to ensure backdoor persistence whenever Windows booted." | Indictment ¶ 38, Page 17 | reviewed |