
Hackers from the Fancy Bear group fabricated documents that they then “merged” on behalf of the Khaker group “Cyberberkut” as evidence of the connection of independent media, including the Republic, and the opposition of Alexei Navalny with the US authorities. This is stated in the report of the research and human rights organization Citizen Lab, published on May 25. Citizen Lab provides information support for Financial Times.
Read more about the Citizen Lab report in the REPULIC material.
According to Citizen Lab, the basis for falsification was the data obtained as a result of hacking the American journalist David Satter , who has been working in Moscow for Radio Liberty since 2013. Prior to the publication of this information, the hackers made updates there, in particular, adding information about Navalny's anti-corruption investigations (for example, about the country of Prime Minister of the Russian Federation Dmitry Medvedev in Ples) and articles “Criticism of the Kremlin” and Russian officials in RBC , “ Vedomosti ” , Slon (Republic) .
The "drain" of the constructed documents in which the Satter appeared took place in October 2016. The data obtained by the Cyberbank and published, for example, in the Rossiyskaya Gazeta and on the REN-TV website , allegedly testified that by order of the Satter, the campaign is held in the Russian media, aimed at “shaking” the political situation and the preparation of the “color revolution” following the example of the coup in Ukraine. Satter, according to hackers, became an intermediary between the opposition media of the Russian Federation, the National Fund for Democracy of the United States and Radio Liberty-by ordering in independent mass media, publications that discredit Russian high-ranking officials appeared.
Citizen Lab notes that the hacking of Satter, carried out using phishing messing in e-mail, became only part of a large-scale attack conducted by hackers. It follows from the report that more than 200 people in 39 countries, including NATO and the UN, military personnel from the USA, Latvia, Montenegro, Ukraine, Turkey, Sweden, as well as politicians and officials from Russia, Ukraine, Armenia, Uzbekistan, Austria and other states, were the goal of the attack.
Researchers also compared the phishing link sent by Setter with dubious letters received by the Bellingcat investigation group. Threatconnect, which specializes in cybersecurity, considered that the responsibility for them lies on the group of hackers "APT 28" (or "FANCY Bear"). The latter is considered to be related to the GRU and responsible, for example, for attacks on US servers during the presidential election.