Page_0019

US. Department of Justice
AfiemethoflePreduet // May-Gontam—Matefiai—Preteeted—U-nder-Fed—IFGHm—P—éfeé

IH. RUSSIAN HACKING AND DUMPING OPERATIONS

Beginning in March 2016, units of the Russian Federation’s Main Intelligence Directorate
of the General Staff (GRU) hacked the computers and email accounts of organizations, employees,
and volunteers supporting the Clinton Campaign, including the email account of campaign
chairman John Podesta. Starting in April 2016, the GRU hacked into the computer networks of the
Democratic Congressional Campaign Committee (DCCC) and the Democratic National
Committee (DNC). The GRU targeted hundreds of email accounts used by Clinton Campaign
employees, advisors, and volunteers. In total, the GRU stole hundreds of thousands of documents
from the compromised email accounts and networks.109 The GRU later released stolen Clinton
Campaign and DNC documents through online personas, “DCLeaks” and “Guccifer 2.0,” and later
through the organization WikiLeaks. The release of the documents was designed and timed to
interfere with the 2016 US. presidential election and undermine the Clinton Campaign.

The Trum Camai_n showed interest in the WikiLeaks releases and, in the summer and
fall of 2016, Harm to Ongoing Matter







WikiLeaks’s first Clinton-related release HOM , the Trump Campaign
sta ed in contac about WikiLeaks’s activities. The investigation was unable to resolve
Harm to Ongoing Matter WikiLeaks’s release of the stolen Podesta emails on October 7,
2016, the same day a Video from years earlier was published of Trump using graphic language
about women.

A. GRU Hacking Directed at the Clinton Campaign
1. GRU Units Target the Clinton Campaign

Two military units of the GRU carried out the computer intrusions into the Clinton
Campaign, DNC, and DCCC: Military Units 26165 and 74455.110 Military Unit 26165 is a GRU
cyber unit dedicated to targeting military, political, governmental, and non-governmental
organizations outside of Russia, including in the United States.111 The unit was sub-divided into
departments with different specialties. One department, for example, developed specialized

malicious software “malware” , while another de artment conducted large-scale spearphishing
campaigns.HZ a bitcoin mining operation to

my As discussed in Section V below, our Office charged 12 GRU officers for crimes arising from
the hacking of these computers, principally with conspiring to commit computer intrusions, in violation of
18 U.S.C. §§1030 and 371. See Volume 1, Section V.B, infia; Indictment, United States v. Netyksho, No.
1:18-cr—215 (D.D.C. July 13, 2018), Doc. 1 (“Netyksho Indictment”).

”0 Netyksho Indictment 11 1.

“1 Separate from this Office’s indictment of GRU officers, in October 2018 a grand jury sitting in
the Western District of Pennsylvania returned an indictment charging certain members of Unit 26165 with
hacking the US. Anti-Doping Agency, the World Anti-Doping Agency, and other international sport
associations, United States v. Aleksez' Sergeyevich Morenels, No. 18-263 (W.D. Pat).

“2 A spearphishing email is designed to appear as though it originates from a trusted source, and
solicits information to enable the sender to gain access to an account or network, or causes the recipient to

36


Next Page_0020
pages_list