Could it be that Guccifer 2.0 isn't a lone Romanian hacker but rather a persona for propagandists or public relations workers with ties to Russia who are leaking Democratic National Committee (DNC) files to journalists?Despite the hacker's claims of independence, a digital trail traced by the ThreatConnect Research Team led to an Elite VPN service based in Russia being used to pass documents to the media."This discovery strengthens our ongoing assessment that Guccifer 2.0 is a Russian propaganda effort and not an independent actor," researchers said in a blog post.In earlier research ThreatConnect noted the inconsistencies, both technical and non-technical, in the tale spun by Guccifer 2.0, who claimed sole responsibility for hacking the DNC, as well as what researchers called "French connections" in the hacker's media interactions that overlapped with Fancy Bear's infrastructure. Those findings led them to believe that Guccifer 2.0 might be using French infrastructure for those communications.By analyzing the hacking persona's interactions with Vocativ and TheSmokingGun via email and Twitter, ThreatConnect found that the "hacker" was leveraging a French AOL account, which "stands out from a technical perspective," researchers said. "Very few hackers with Guccifer 2.0's self-acclaimed skills would use a free webmail service that would give away a useful indicator like the originating IP address "because an experienced pro would know which email providers are more inclined inclined to work with law enforcement as well as how much user metadata a provider would reveal."Taken together with inconsistencies in Guccifer 2.0's remarks that make his technical claims sound implausible, this detail makes us think the individual(s) operating the AOL account are not really hackers or even that technically savvy," the blog post said. "Instead, propagandist or public relations individuals who are interacting with journalists."Finding secure shell (SSH) and point-to-point tunneling protocol services on the host, "strongly suggest(s) a VPN and/or a proxy, both of which would allow the Guccifer 2.0 persona to put distance between his originating network and those with whom he is communicating," the researcher team wrote.The investigation uncovered six additional IP addresses that shared the same SSH fingerprint and while researchers noted it wouldn't be unusual for a hacker to use a proxy service they found no evidence that any of the IP addresses were part of the Tor infrastructure.One of the IP addresses had hosted the domain fr1.vpn-service[.]us since February 2015 and uses a naming convention "consistent with our working hypothesis that Guccifer 2.0 is leveraging French-based VPN infrastructure to communicate with journalists," the researchers said.The name on the domain's current registration matches the name on a 2004 registration operated under VPN Services Inc. and including an email address using mail.ru, the free Russian webmail service.Ultimately, the researchers wrote, "the domain vpn-service[.]com leads to the Elite VPN website and is hosted on the same IP as vpn-service[.]us, but was most recently registered using a privacy protection service."
Compliance Management, Privacy, Threat Management
ThreatConnect: Guccifer 2.0 likely persona for Russian-linked propagandists, PR operatives leaking info to media
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
