A Russian tech entrepreneur accused in the Trump-Russia scandal two years ago may end up regretting the defamation suit he filed against a U.S. media outlet.
Thousands of pages about his company's operations and finances were released to the public last week by the federal magistrate overseeing the case–effectively turning the suit into a WikiLeaks-sized data dump that's raise new a matter of his dealings with computer criminals.
Aleksej Gubarev came to notoriety in 2017 over a single paragraph in the so-called Steele dossier compiled by former U.K. intelligence officer Christopher Steele. The controversial dossier is a 35 -page compilation of anonymously sourced tips-off and anecdotes about Donald Trump's ties to Russia, a mixed bag of claims ranging from the lurid to the prosaic. Some of the reporting has since been broadly substantiated, much of it has not, and there are parts that have been all but proven false.
The dossier's claims about Gubarev fall in the latter category.
Gubarev runs a multinational internet hosting company called XBT that boastings subsidiaries in Europe, the United State, and Asia. Shortly after the 2016 election, one of Steele's sources thumbed Gubarev and his businesses as” significant players” in the Kremlin's election-hacking, claiming Russia's domestic snoop bureau the FSB had pressured Gubarev and his companies to use” botnets and porn traffic to transmit viruses, plant glitches, steal data and conduct' altering operations' against the Democratic Party leadership .”
When BuzzFeed published a leaked copy of the dossier in January 2017, Gubarev vehemently denied any role on the Kremlin's hack and filed a defamation lawsuit against the media company. Over the years, that litigation has produced a mountain of documents and hour upon hour of videotaped depositions, nearly all of which was kept under seal. A federal judge threw out Gubarev's lawsuit last Decemberon the grounds that BuzzFeed, being a news outlet, was within its rights to publish a document that top FBI agents had cited in surveillance court affidavits, and that two U.S. chairpeople had received personal briefings about.
Gubarev is appealing that ruling. In the meantime, on Thursday, the same judge unsealed the majority of members of the documents in the case at the urge of separate petitions by BuzzFeed and The New York Times .
In a twisting that must be maddening to Gubarev, the media coverage of the document dump is giving fresh oxygen to the dossier's claims about Gubarev and his business.
Much of the coverage focuses on a report prepared by one of BuzzFeed's expert witness, Anthony Ferrante of FTI Consulting, a former FBI agent retained to investigate Steele's claims. Ferrante's report found that Gubarev's hosting company” was utilized by Russian civilian and military intelligence services to compromise and exploit networks .”
” Additionally, evidence suggests that Cozy Bear and Fancy Bear, the Russian government affiliated APT groups responsible for hacking the Democratic Party leadership, have use XBT infrastructure to support other malicious activity ,” Ferrante wrote.
Prior to Thursday, the dossier's narrative of Gubarev use porn to hack Democrat had been banished to the fringes of the Russiagate narratives–buried under far more credible reporting from U.S. intelligence agencies, congressional examiners, and the detailed tick-tock of the election hackers presented in Robert Mueller's indictment against GRU officers. None of those accounts named Gubarev, or even left space for him in the tale. He was essentially vindicated.
Now, the Times notes,” the report's suggestions of a link between Mr. Gubarev and Russian hacking is likely to spur new demands for renewed investigations .”
Trump-Russia watchers are always interested when new proof emerges to support the Steele dossier. But in this case there's much less than gratifies the eye.
Ferrante's chore in the report was to sniff out links between XBT and the Russian government hackers–known as “Fancy Bear” in the security world–who carried out the election interference intrusions. He and his team did that work with vigor.” The report is well crafted, and although there are some small technological errors it's obviously been exhaustively researched ,” security expert Robert Lee, CEO of Dragos, told The Daily Beast.
The outcome, though, was essentially preordained. That's because XBT is a hosting company that offer inexpensive, turnkey internet servers on demand. And Fancy Bear is a ravenous customer of turnkey hosting services around the world.
The GRU hackers need servers to “drop” malware onto a fresh victim computer, to host the fake login forms for their phishing operations, to serve as command-and-control hubs for their long term surveillance implants. They rent the servers utilizing fake names and disposable email accounts, and pay in bitcoin when they can. According to Mueller's indictment, the GRU has an entire department, headed by Aleksey Aleksandrovich Potemkin,” responsible for the administration of computer infrastructure used in cyber operations .”
So when Ferrante went looking for Fancy Bear's paw publishes at XBT, it's no surprise he found them. But a fair read of his findings indicates the Kremlin's hackers have no particular affinity for XBT over other server farms. If anything, it's among their least favorite options.
Consider one of the tendrils supposedly connecting XBT to the election hackers by way of a December 2016 DHS report. Called” Grizzly Steppe ,” the report lists 876 internet IP address that have been used by Russian hackers over the years, according to DHS. Ferrante reports that some of those address belonged to XBT. To be more specific, 12 of them.
Four of the 12 are part of the Tor anonymization network, a free public system open to anyone in need of additional privacy. Assuming all of the remaining eight were indeed XBT servers rented by Russian spies, that's 1 percent of the list–not exactly a ringing endorsement of Gubarev x27; s business by Putin's hackers.
It's worth noting that none of those eight addresses have been linked specifically to the election hacking operation. Others, operated by different companies, ought to have.
Ferrante also examined a batch of 42 IP addresses connected to the GRU hackers by a website certificate used in a number of their hack attacks, including the 2014 intrusion at German Parliament and the 2016 DNC breach. Ferrante reports that one of the 42 addresses belongs to XBT. That particular address is not known to have been used in the election hackers. The other 41 addresses, including one that did play a role in the DNC breach, trace back to entirely different hosting companies scattered throughout Europe.
” Without more intelligence indicating that Gubarev's subsidiaries were directly involved with and aware of the malicious activity leveraging their infrastructure … it seems to be an analytic leaping to imply implication in those connects ,” said Kyle Ehmke, an analyst at ThreatConnect, which has tracked the GRU's hacking infrastructure closer than most.
Another set of 41 IP addresses comes from logs at the URL-shortener Bit.ly, which the Russians used in their months-long email phishing campaign against Hillary Clinton's staff and thousands of other political targets. Between October 2015 and and June 2016, a GRU officer set up 11,139 shortened connects leading to fake webmail login pages. It was one of those connects that tricked Clinton campaign chief John Podesta into devoting the Russians full access to his inbox.
Ferrante found that one of the 41 servers the GRU used to connect to Bit.ly and construct the links was at XBT. Presumably the other 40 were rented from other firms.
” Is it your opinion that the owners of all 40 of the other IP addresses are also culpable for the hacker of the DNC ?” Gubarev's lawyer asked during a deposition.
“No,” Ferrante replied.” It x27; s my opinion that XBT and its infrastructure … is linked to a pattern of significant malicious activity .”
Even a small overlap between the election hackers and the man named in the Steele dossier as their tech guy might be interesting if the Russians were the only hackers who use XBT's services. But the company's past client base also includes the spy services of completely different governments at the same or greater adoption rate.
This is even noted in the Ferrante report, but it's easy to miss since the report sticks with the generic security industry monikers for the non-Russian hacking operations. Ferrante takes aches to observe that Fancy Bear and Cozy Duke have been linked to the Russian government, but neglects to report that “DarkHotel,” ” Nitro ,” and “Careto” — who've also used XBT IP addresses–have been tied to the governments of North Korea, China, and Spain, respectively.
If the Ferrante report fails as vindication of the Steele dossier, it makes a more compelling case for XBT being an equal-opportunity host to all manner of cyber wrongdoing. And on that point the other unsealed documents contain plenty of proof to back it up.
The documents is demonstrating that XBT hosted a rogues' gallery of traditional for-profit cyber crooks over the years, including the professional bank heist crew known as the Carbanak Gang, crooks stealing from consumers and small businesses with the Zeus malware, and the brains behind a sophisticated long-con known as ” Methbot” that build an infrastructure twice the size of Facebook to fleece advertisers of millions.
Does that mean the company is more lax in patrolling its servers for offenders than other hosting firms? Ferrante thinks so, but the report doesn't offer an industrywide comparison. Independent security experts interviewed for this story say it's hard to tell.
” Not assured that I could really qualify a level of badness for purposes of comparison across infrastructure resellers, but based on what I read in that report, it doesn x27; t seem particularly anomalous ,” said ThreatConnect's Ehmke.” We've seen similar concentrations of malicious activity on infrastructure procured from resellers like Njalla and ITitch, which offer services that these sorts of performers probably look for, such as anonymity and payment via BitCoin .”
Kimberly Zenz, a veteran menace analyst specializing in Russian cybercrime, told The Daily Beast that XBT's reputation is” on the wrong side of the line for things like abuse responses, repercussions for terms-of-service violations, and illegal behaviour .” She said:” They react slower and less aggressively and less often than they are able to. They do respond sometimes, or in some way, though. They're not like an old-school, 100 percent-crime service .”
The unsealed documents are at their most revelatory when it comes to Gubarev's relationship with one of his allegedly criminal clients, Aleksandr Zhukov. The 38 -year-old native of St. Petersburg, Russia, is in a federal detention center in Brooklyn awaiting trial on four countings of wire fraud and money laundering, in part for allegedly masterminding the Methbot operation. For a hour he was XBT's biggest customer.
Methbot was an enterprising scam that used a fake internet ad agency called MediaMethane to sell millions of dollars worth of video ad spots on premium content sites.
Instead of running the ads on sites like The New York Times and Fox, the crew use rented hosting in Dallas to operate its own private network of fake sites simulating the real ones–and then operate the ads there. The audience for the ads were thousands of ” customers ” who were actually sophisticated bots happy to watch 300 million video ads a day.
To make the bots seem real to advertisers, the perpetrators leased over 800,000 IP addresses and then filed bogus information with internet registries to build them look like residential broadband providers in demographically desirable American neighborhoods.
A sizable section of those fake Comcast, AT& T, and Cox Cable address were leased from XBT. The company says it thought they were being used for an advertising metrics business.
According to attorneys, the Methbot scheme conned the thousands of brands and advertisers out of$ 7 million before it was exposed by a New York security company in December 2016. The unsealed documents indicate XBT was paid millions. In the scam's final month alone, XBT was paid $400,000, according to internal financial reports, accounting for 7 percentage of the company's earnings that month.
The unsealed documents is demonstrating that when Methbot was uncovered, XBT was worried it would be swept into a press cyclone at a time when Russian hackers were getting a lot of attention. Gubarev hired an American PR crisis manager who boasted of once repping accused mega-pirate Kim DotCom. In a series of emails, his chief operating office, Nick Dvas, urged the PR consultant to handle reporters with care.
” Please, be very careful with Mr. Krebs ,” Dvas wrote in one email, referring to independent security journalist Brian Krebs.” He has been performing lots of research in connection with cybercrime originating from Russia, and he might jump to some sort of unnecessary conclusions .”
In another message to the PR consultant, Gubarev admitted to direct copes with Zhukov.” We know him personally many years ,” he wrote.” We was[ sic] under impression that it is a big data analytics system for ad networks as per his explain .”
Despite the close and lucrative relationship, XBT evidently maintained scant documentation were related to its biggest client, according to a filing by BuzzFeed's lawyers.” Their internal records consist of a credit card check with a' tolerance threshold' of $1,000 and notations regarding multiple Russian names and e-mail addresses they are unable to identify ,” read the filing.” And though he was supposedly a client for more than a year who personally visited them several times, they have not made a single actual e-mail, message or other communication from Zhukov .”
In the end, the evidence knocked loose by Gubarev's lawsuit doesn't tie-in him in any meaningful route to Russiagate. But it does show that his company, perhaps innocently, was paid a lot of money as part of an epic Russian cybercrime caper that's now headed toward a federal trial in New York. That's the kind of advertising that fund can't buy.
Read more: www.thedailybeast.com