
All 12 accused are employees of the General Intelligence Directorate of Russia in different military ranks (senior and junior lieutenants, lieutenant colonels; in most cases are simply indicated as “military personnel”). All of them, except Alexander Osadchuk and Alexei Potemkin, served in Part 26165, located on Komsomolsky Prospekt in Moscow (it is known for the fact that cryptographs, creators of algorithms for decryption and other specialists of this kind are in it). Osadchuk and Potemkin served in Part 74455, allegedly located at Kirov Street, house 22, in Khimki; This place in the indictment is also called the "tower".
Update. The “Tower” GRU in Khimki is the Novator business center, built by the company of State Duma deputy Dmitry Sablin and the sold Ministry of Defense .
The 2015 judicial documents say that the specified part is located in Moscow on Svoboda Street, d. 21 (Vikimapia denotes this house as the “177th Separate Center for Management of Technology Development”, but another military unit).
Employees are interconnected - so, Boris Antonov and Dmitry Badin carried out general supervision of the activities of several military from the list (for example, Ivan Ermakov, Alexei Lukashev and others).
Little is said about the activities of the GRU employees. It is known that Sergey Morgachev, Nikolai Kozachek, Pavel Ershov and Alexander Osadchuk developed, tested and applied the malicious X-Agent program ( it is believed that it was developed by the hacker group Fansy Bear; the latter was always associated with Russia).
In the case of several military personnel, it is indicated what nickels they used, performing actions of which the US government accuses them. So, Nikolai Kozachek is mentioned as “Kazak” and “Blablabla1234565”. Lukashev created users “Den Katenberg” and “Juliana Martynov”, Ivan Ermakov - “Kate S. Milton”, “James McMorganes”, “Karen W. Millen”. Alexander Osadchuk and Alexei Potemkin managed users under the pseudonyms of DC Leks and Guccifer 2.0; Through them, documents stolen from the headquarters of Hillary Clinton and the National Committee of the Democratic Party of the United States were distributed.

According to investigators, the GRU employees attacked computers of more than 300 people related to the National Committee of the US Democratic Party, the Party Committee for Elections to Congress and the presidential campaign Hillary Clinton. They sent letters on behalf of Google, allegedly containing a notification of security settings. Inside was a link that led to the site created by the GRU. To disguise it, the URL reduction service was used. In March 2016, the post of head of the election headquarters of Clinton John Podesta was hacked in this way. There were more than 50 thousand letters in his box.
In April 2016, the accused brought a mailbox, the address of which was different from the address of one of the participants in the Clinton campaign. They sent from him phishing letters more than 30 employees of the presidential candidate. The letters allegedly contained a link to the XLSX document with Clinton ratings. In fact, she led to the site created by the GRU.
At the same time, Russian intelligence officers attacked computer systems of the Committee of the Democratic Party for Elections to Congress. Access was obtained using a physical letter sent by one of the employees of the committee. She went through the link sent to her and entered the password. In April-June 2016, the accused installed the X-Agent spy program at least 10 computers connected to the party committee network. The program wrote down what keys the user pressed, and took pictures of the screen of his computer, and then transmitted the stolen data to the server that the GRU rented in Arizona.
With the help of X-Agent, in particular, the passwords of the employee of the Congress election committee, who also had access to the network of the National Committee of the Democratic Party. Thus, at least 33 computers connected to this network were hacked.
On hackneyed computers, the accused, in particular, searched for documents with the mention of Hillary Clinton, Donald Trump and presidential candidate from Republicans Ted Cruise. They also downloaded folders with information about the investigation of the fighters attack on the US Embassy in Benghazi in 2012 (Hillary Clinton at that time served as US Secretary of State, she testified in this case at a hearing in Congress). In addition, Russian intelligence officers gained access to financial documents, in particular to plans to collect donations for Clinton's campaign.
To distribute these documents, GRU employees, according to investigators, pretended to be a Romanian hacker under the pseudonym Guccifer 2.0. As stated in the document, in June 2016, when Guccifer 2.0 was accused of using this name as a cover for representatives of Russian special services, search queries about some English phrases were received from one of the servers of the military unit (for example, the translation of the phrase “well -known word Illuminati). After two and a little hour, all these phrases appeared in the Guccifer 2.0 statement, where the Hacker categorically denied the connection with Russia.
Then, in June 2016, the accused launched the DCLAKS website, on which they laid out part of the stolen correspondence. For its promotion, Facebook accounts and other social networks were created. In addition, they transmitted the stolen data to the third party, which is indicated in the indictment as Organization 1. Most likely, this is the WikiLeaks project.
Osadchuk and Kovalev are also accused of that in the summer of 2016 they hacked the site of the election commission of one of the American states and stole personal data about half a million voters. They also hacked the company's website that issued software for verifying these voters. A little later, the FBI found out about this hacking and established some of its circumstances; At this moment, according to the prosecution, Kovalev and his accomplices removed the accounts used for this operation.
Alexander Polivanov, Dmitry Tomilov