Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

CousinIT

(9,239 posts)
Fri Dec 30, 2016, 05:04 PM Dec 2016

Released Report on "GRIZZLY STEPPE" didn't mention why it was determined to be Russian

However that information HAS appeared elsewhere:

The issue has come to the fore in the 2016 U.S. presidential election. The Department of Homeland Security and the Office of the Director of National Intelligence—a combined 17 intelligence agencies—issued a statement saying Russia was behind the election hacking.

It is pretty clear judging by the indicators of compromise [IOCs]. The binaries that were used to hack the DNC as well as Podesta’s email as well as some other Democratic campaign folks, those IOCs match binaries and also infrastructure that was used in attacks that were previously recorded by others as having Russian origin. That much we can confirm. So if you believe other people’s—primarily government’s—attribution that those previous attacks were Russian, then these attacks are definitely connected. We’re talking about the same binaries, the same tools, the same infrastructure.

I understand you and your firm have spent significant time analyzing the DNC and Podesta hacks. What groups are responsible, and how did you determine attribution?

We’ve analyzed the tools, the binaries, and the infrastructure that was used in the attack, and from that we can confirm that it’s connected to a group that has two names. One is Sofacy, or “Cozy Bear,” and The Dukes, which is also known as “Fancy Bear.” From the binary analysis point of view, I can tell you that the activities of these attackers have been during Russian working hours, either centered on UTC+3 or UTC+4; they don’t work Russian holidays; they work Monday to Friday; there are language identifiers inside that are Russian; when you look at all the victim profiles they would be in interest to the Russian nation-state. So all of that stuff fits the profile. Now, could all those things be false flags? Sure. Other government entities obviously have come out and said it is the Russian state, and the binary forensics would definitely match that
.

http://www.thedailybeast.com/articles/2016/11/05/cybersecurity-expert-proof-russia-behind-dnc-podesta-hacks.html

https://twitter.com/MarlowNYC/status/814926627524186116

2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Released Report on "GRIZZLY STEPPE" didn't mention why it was determined to be Russian (Original Post) CousinIT Dec 2016 OP
Cozy Bear and Fancy Bear HoneyBadger Dec 2016 #1
I see Putin as "Big Bear" Buns_of_Fire Dec 2016 #2

Buns_of_Fire

(17,174 posts)
2. I see Putin as "Big Bear"
Fri Dec 30, 2016, 05:55 PM
Dec 2016

But oddly enough, I don't see Trumpski as "Little Bear" -- or even "Gummy Bear" or "Scummy Bear".

I think he would be referred to as "Goldilocks." ("Someone's been sleeping in my bed and he left a hooker in there!&quot

Latest Discussions»General Discussion»Released Report on "GRIZZ...