DFRLab
Published in

DFRLab

#PutinAtWar: WADA Hack Shows Kremlin Full-Spectrum Approach

How the Russian government hacked and abused the World Anti-Doping Agency

Archive of the “Fancy Bears’ Hack Team” Twitter account, and footage of four accused GRU hackers arriving in the Netherlands in April 2018. (Source: Twitter, via archive.is, archived on August 10, 2018; Dutch Ministry of Defense)

Hackers On Tour

Translated from Dutch: “Schematic representation.” Image of the hacking equipment in the suspects’ car (left) and diagram of the layout (right). (Source: Dutch Ministry of Defense)
Table of earlier logins on the suspects’ laptop, with the Lausanne logins highlighted. (Source: Dutch Ministry of Defense)
The image on the suspects’ laptop, dated to August 14, 2016. (Source: Dutch Ministry of Defense)

The WADA Case

Headline of the WADA statement, published on July 18, 2016. (Source: WADA)

Hackers Who Leak

The seized site. (Source: fancybear.net)
Screenshot of a partial snapshot of the fancybear.net home page, dated September 13, 2016, and archived the following day. The archive did not show the full page. (Source: archive.is via fancybear.net)
Tweets by @FancyBears, saved on the Wayback archive machine, September 12, 2016. Note the reference to the Williams sisters as “doping addicts.” (Source: web.archive.org via Twitter / @FancyBears)
Screenshot of BBC video detailing the hacks, September 20, 2016. (Source: BBC)

Many Voices, One Chorus

News-Front article of September 13, 2016. The highlighted passage reads, translated from Russian, “WADA kept silent about the facts themselves, not giving way to scandals.” (Source: news-front.info)
Screenshot of the Sputnik article and headline. Note the results of the search for the word “hypocrisy,” top right, showing that the only mention was in the headline. (Source: Sputnik)
Archived on October 9, 2018. (Source: Twitter / @RussianEmbassy)
Archived on October 9, 2018. (Source: Twitter / @EmbassyofRussia)
List of troll farm accounts provided to the U.S. Congress by Twitter, showing @nataturn. (Source: House Democrats)
Result of entering the shortened link into the search bar. (Source: @DFRLab)
Results of the search. (Source: Google)
The article tweeted by @nataturn and attributed to Jenna Abrams. Note the byline, the attack on WADA in the second paragraph (“corrupted bastards”), and the claim of “rules violation” (highlighted). Archived on October 18, 2017. (Source: archive.is, from bullshit.ist)
RT articles in November and December, 2016. (Source: RT)
Left: Tweet by @FancyBears, archived on August 10, 2018. Right: Sputnik article on the leak. (Source: archive.is, from Twitter / @FancyBears/ Sputnik)
(Source: RT)

Conclusions

--

--

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
@DFRLab

@AtlanticCouncil's Digital Forensic Research Lab. Catalyzing a global network of digital forensic researchers, following conflicts in real time.