Dcleaks

Threat Actor updated 4 months ago (2024-05-04T19:18:52.610Z)
Download STIX
Preview STIX
DCLeaks, a threat actor, is suspected to be a part of a sophisticated information operation orchestrated by the Russian government, specifically by IRON TWILIGHT and Unit 74455. It was allegedly created alongside the Guccifer 2.0 persona to divert attention from the real source of leaked material. These entities are believed to have been involved in the dissemination of stolen data through the DCLeaks and Guccifer 2.0 websites. Notably, these groups also liaised with WikiLeaks to amplify their information operations and promoted leaks to journalists via GRU-controlled email and social media accounts. The members of Unit 74455, which included Ivan Sergeyevich Yermakov and Senior Lieutenant Aleksey Viktorovich Lukashev as per an indictment, were responsible for targeting the email accounts that were eventually exposed on the DCLeaks site prior to election operations. This group was also responsible for configuring the DCLeaks and Guccifer 2.0 blogs and social media accounts, which were later used to disseminate data stolen from the DNC, DCCC, and Clinton campaigns. The DCLeaks website also released internal DNC documents in a separate incident. Guccifer 2.0 claimed that DCLeaks was a subproject of WikiLeaks, although there's no public evidence supporting any formal or informal relationships between DCLeaks and WikiLeaks. Interestingly, in private communications with TSG, Guccifer 2.0 revealed prior knowledge of DCLeaks but has not publicly mentioned or promoted it. Researchers assess that DCLeaks is another Russian influence operation, possibly managed by the same actors behind the Guccifer 2.0 persona. It's noteworthy that the Guccifer 2.0 persona hosted content on DCLeaks and had privileged permissions to access and administer password-protected content. Despite this, Guccifer 2.0 asked TSG not to link or associate the DCLeaks content to the Guccifer 2.0 blog.
Description last updated: 2024-05-04T19:16:20.620Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Dcleaks Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago
IRON TWILIGHT Supports Active Measures
MITRE
2 years ago
How they did it (and will likely try again): GRU hackers vs. US elections
CERT-EU
a year ago
Does a BEAR Leak in the Woods? | ThreatConnect