
On August 8, 2008, Hacker Leonid Stroykov - on the Internet, he most often signed as R0id - he sat at home, in his Khabarovsk apartment, drank beer and read Bashorg . At some point, his attention was attracted by the emergency release of news on TV-they reported that Georgian troops began to shell the capital of South Ossetia Tskhinvali.
Impressed by the experienced hacker Stroykov (in 2006, for example, he told in detail how to hack an online bank) began to study the sites of Georgian government organizations and the media-to look for holes in defense through which you can attack them. Soon several sites of Georgian media and state institutions were hacked; The attacks continued all the time that there was a conflict - and took place after it.
According to several Russian -speaking hackers, with whom Medusa spoke, it was the events in Georgia that became a catalyst that the Russian special services began to cooperate with patriotic hackers, drawing attention to their actions during the conflict. Since then, they are attracted to work regularly - sometimes voluntarily, sometimes forcibly: under the threat of criminal cases.
According to one of the Medusa interlocutors, the special services prefer not to keep many technical specialists in the staff, but to oversee freelance employees - they are found through criminal cases of hacks and carding or hired in underground specialized forums. Another hacker says that in the Ministry of Defense and the FSB “there is a common scheme to attract illegal hackers, their promotion, and create conditions for them to get the necessary information through them.” According to the interlocutor of Medusa, the special services even often hide hackers in conspiratorial apartments - so that they are not caught by the police officers investigating cybercrime from the K -"Ministry of Internal Affairs.
The former head of the Kaspersky Lab in the investigation department Ruslan Stoyanov, who collaborated on working with the FSB, openly warned that such cooperation was dangerous. “There is a huge temptation for“ people who make decisions to use the ready -made decisions of Russian cybercrime in order to influence geopolitics, ”wrote Stoyanov, who has been in the Lefortovo pre -trial detention center on charges of Gosman, in his open letter . - The most terrible scenario is to give cybercriminals immunity from retaliation for stealing money in other countries in exchange for intelligence. If this happens, a whole layer of “patriots thieves” will appear. Half-aliel “patriot groups” can much more openly invest stolen capital in the creation of more modern Trojan programs, and Russia will receive the most advanced cyber weapons. ”
In fact, as the Medusa interlocutors say, the services of such Patriot-Groups have been used in special services for at least ten years.
In August and September 1999, several residential buildings were blown up in Moscow and Volgodonsk; 307 people were killed, about 1700 were injured (explosives were laid in the basements of houses). The incident was accused of Chechen terrorists-in the same August of 1999, the militants' detachments led by Shamil Basayev began hostilities in Dagestan to free the region "from the occupation by infidels."
Soon, Russian troops blocked the borders of Chechnya, and on September 30 - a week after President Boris Yeltsin signed a decree on the “counter -terrorist operation” (KO), entered the territory of the republic. The “operation”, which was not called the war at the official level, lasted the next ten years: formally, the regime of who was canceled only in April 2009.
The second Chechen was the first conflict in which Russian hackers sided with the state and actually fought with the enemy. So far, after explosions in residential buildings in most Russian cities, people were on duty at their entrances, looking for suspicious strangers from the basements, several people decided to fight the enemy actively - without leaving their own houses.
Several students of the Tomsk Polytechnic University organized the Siberian Network Brigade. She conducted DDOS attacks on the sites of Chechen militants, where they published their news and interviews-moreover, cyber venists began to act even before the conflict turned into an active phase. On August 1, 1999, on the main page of the site kavkaz.org they posted a drawing - it depicted the poet Mikhail Lermontov in camouflage and with a Kalashnikov machine gun. “There was Misha here,” the signature in the colors of the Russian flag reported. “This site of terrorists and killers was closed at the numerous requests of Russians.”

Participants in the "brigade" also sent letters to the American hosting companies demanding no longer providing their services to terrorists. On November 17, 2001, the leader of the organization sent another appeal to the US media and the US State Department. “The events that occurred in your country on September 11, 2001 brought the positions of our states in matters of the fight against international terrorism,” he said. - Xo Communications, Inc. Provides hosting services to the Kavkaz-Center information agency, belonging to persons recognized by international terrorists, including in your country. This site is used not only to place materials that discredit the efforts of the world community to combat international terrorism, but also for recruiting new militants and collecting funds for terrorists. ” A month later, the resource was refused in hosting, and the Caucasus Center moved to the servers to Georgia (not the last time: after that the site had to move to Estonia, Latvia and Finland; where it is located now, it is unknown-the Cloudflare DDOS attacks are hiding the real addresses of the company servers).
In 2002, the breeders from the "brigade" again hacked the site of the "Caucasus Center", leaving the message on its main page. “We pulled out a sting from the smelly mouth of the“ Gavgav Center ”, and silence hung over the den of the Chechen terrorists. He choked with the bark of the Udugov ( so in the text - approx. "Medusa" ). The gangstock was silent in the mountains. The cunning Arab did not send Chechen mercenaries. The evil Talib in Afghanistan was sad. If you shut this mouth tomorrow, the world will become even calmer and even safer. ”
Participants in the “brigade” openly called on their colleagues to attack the resources of the militants: “The best reward is the admiration of the Brothers in Online Tershu and the happy sun, filled with the sun tomorrow.” After a couple of months, Russian-speaking hackers began to massively spread the Masyanya virus, named after the Internet-multfilm popular at that moment-it was harmless to users, but the infected computer became a participant in the DDOS attack on the Caucasus Center.
The head of the Caucasus Center Movladi Udugov was sure that the FSB was behind the actions of hackers. The Tomsk FSB publicly said that the “Siberian Network Brigade” does not violate the Russian legislation, and the actions of its participants “are an expression of their civil position, which is worthy of respect,” despite the fact that at that moment the 272nd article of the Criminal Code on the illegal access to computer information (the new department of the Ministry of the Interior then was then engaged in the new department of the Ministry of the Interior).
A few months later, on October 23, 2002, when the Chechen militants captured the Moscow Theater Center, where they showed the Nord-Ost musical, their sites were again attacked. Soon, however, the Siberian Network Brigade stopped holding its shares; What its participants did in subsequent years is unknown.
In 2005, a new era began in the history of hackers-patriots-it was then that calls began to unite on specialized forums to attack extremist resources.
More actively, the person called in these projects under the nickname Petr Severa, at that time - one of the most famous Russian -speaking hackers and spamers. Under this name, Peter Levashov from St. Petersburg was hidden-a man who in the 2000s created one of the world's largest Kelihos botnets , consisting of 100 thousand infected computers. In the United States, Levashov was called the "king of spam."
Several friends of Levashov told Medusa that he was one of the first among Russian hackers began to cooperate with special services. He later used his skills for political purposes - his botnet was accused of that in 2012, during the presidential campaign in Russia, he sent letters telling about the homosexuality of presidential candidate Mikhail Prokhorov. They placed links to material with a politician attributed by a quote "to everyone who know me for a long time, it is clear that I am a fagot." Levashov also stated that since 2007 he "worked for United Russia, collected various information about opposition parties and was engaged in bringing this information to the right people at the right time."
On April 1, 2013, Severa laid out on a hacker forum, apparently a comic post dedicated to the day of the fool. He talked about the fact that at the Center for Information Security of the FSB, a new department would be created to counteract the cyber -owneds of the United States and other countries. “I am instructed not only to lead, but also to create the main [personnel] composition,” wrote Levashov. - The presence of higher technical education is a plus, but it will not be mandatory, it is much more important that you really know how. The presence of a finished military department or an urgent service in the Armed Forces of the Russian Federation is also a plus. The Motherland raised us, gave us all education, now our time has come to serve Russia. ”
The acquaintance of the hacker told Medusa that Petr Severa invited his friends to serve Russia, helping the state on the Internet since the mid-2000s. First, he called for attacking the sites of the Chechen terrorists, then the Russian opposition. They did it for free. The journalists Andrei Soldatov and Irina Borogan, who investigated the activities of the Russian special services, wrote about this.
Levashov called on to join the Civil Anti-Terror-a community that some hackers-patriots created in the spring of 2005. They published a manifesto, proclaiming that the most important weapon in the 21st century is information. “Our goal is to block access to information resources that posted distorted information about terrorism and terrorists, promoting the correctness of their actions, whatever it is based,” hackers said. They acted in the same methods as predecessors-using DDOS attacks.
A month later, another similar project appeared - Internet undround community vs. Terrorism. His site was decorated in black and blue; The logo depicted the confrontation of the hacker and man in a Muslim scarf. The creators of the project indicated that they were looking for in a “close -knit team” collected throughout Russia and the CIS, DDOS specialists and denied communication with the Russian authorities and special services, stating that they themselves are people “on the other side of the law”. In the "Program" section, they laid out the provision for DDOS attacks; There was also a table, which indicated the successful actions of the organization.
After the fighters attack on Nalchik in October 2005, hackers attacked not only the Caucasus Center, but also the media, which, in their opinion, incorrectly spoke about the actions of the terrorists: “Echo of Moscow”, “New Newspaper”, “Radio Liberty”. A month later, they broke the website of the National-Bolshevik party (banned in Russia) Eduard Limonov-the day after this attack, the Supreme Court just eliminated the NBP interregional public group. After that, DDOS attacks on opposition sites and protest shares became more and more frequent. In the spring of 2007, when the Estonian authorities decided to transfer a monument to Soviet soldiers who died in the Second World War from the center of Tallinn, the patriots attacked Estonian state sites.
Around the same time, the St. Petersburg programmer Anton Moskal called. According to journalist Andrei Soldatov, who called he introduced himself as an employee of the National Anti -Terrorism Committee of the FSB. He asked if Moskal really owns the Civil Anti -Terror site. The site of Muscovite did not belong - he only made his mirror on his blog. The FSB officer "started talking about patriotism and the fight against terrorist sites with a programmer." Upon learning that he did not call that, he asked how to contact the hackers working on the project.
In the summer of 2008, DDOS attacks on Georgian government sites began two weeks before the start of the war-when constant shootings began on the border of Georgia and South Ossetia.
August 9 - the day after Russia entered its troops into the territory of Georgia - Russian -speaking hackers created the site Stopgeorgia.ru. There were tips on which Georgian sites to attack, links to the necessary programs, advice to beginners. There were about 30 permanent participants on the site forum - mainly hackers who earned with carding; The calls to participate in the project appeared on the forum of the Hacker magazine and other sites for communication programmers-Exploit.in, Zloy.org, Web- Hack.ru.
The creators of the site were represented by "representatives of the Russian Hak-Andigund." “We will not tolerate the provocations on the part of Georgia in any of its manifestations,” they said in their appeal. “We want to live in a free world, but to exist in the network space free of aggression and lies.” They promised to attack Georgian resources “until the situation changes” and called for help “everyone who is not indifferent to the lies of political Georgian sites”. On StopGeorgia, a list of “priority goals” for attacks appeared - after that the sites of the Georgian president, parliament, the Ministry of Internal Affairs, and the Ministry of Defense stopped working.
It happened in those days and cyber attacks on Russian resources: they attacked RIA Novosti and other Russian and Ossetian media; The Russia Today site as a result of a DDOS attack did not work for about an hour. Someone created a site with false news, looking like an Ossetian news agency.
Stopgeorgia continued to act after the war. When in December 2009 the Georgian authorities dismantled the Memorial of Military Glory in Kutaisi (on the site of the monument to Soviet soldiers, they were going to build a parliament building), the hackers again began to collapse Georgian state sites. “We will not tolerate the destruction of our historical heritage and attempts to push the peoples of the former USSR with foreheads,” they wrote in their appeal at one of the hacker forums. “We play for the peace and friendship of our peoples and will not allow inciting interethnic growth between people, whose story is forever fastened by the bonds of the brotherhood.”
The researchers later found that Stopgeorgia.ru was registered with the Naunet host, who refuses to issue data on the owners at the request of law enforcement agencies. The organization of Spamhaus has long brought this company in the blacklist - because it provides the site for spamers and cybercriminals. The building of Naunet is located near the Belorussian station in the center of Moscow - Khoster shares it with the Etalon Research Institute, which is close to the state, which is engaged in the production of information security systems. In 2015, “Etalon” became part of Rostec-a state-owned company, which has been interested in programs and equipment for DDOS attacks for many years.

The post and telephone indicated during the registration of the site Stopgeorgia.ru were repeatedly lit on the forums of the carders - they belonged to a certain Andrei angular, who sold the databases of stolen credit cards, as well as fake passports and driver’s licenses (most likely the name was fictitious).
The IP address Stopgeorgia.ru belonged to a small company Steadyhost, located on 88 Khoroshevskoye Shosse, in the Moscow area, where almost all buildings are connected with the GRU . In the neighboring building-in house 86-is the 6th Research Institute of the Ministry of Defense, the Center for Military-Technical Information and the study of the military potential of foreign states that previously subordinated to the GRU. Locals call this four-story building, built in 1930, the Pentagon-not because of the form, but because of secrecy; The NII employees were characterized as “the most informed people in the GRU”, and the leadership of the institute is part of the Russian Security Council.
Леонид Стройков — он же R0id — атаковал грузинские сайты сам, без поддержки коллег и хакерских организаций. Сначала он начал ломать местные СМИ и поисковик. «Ни одно крупномасштабное событие не обходится без участия СМИ, они активно используют интернет для передачи своего видения происходящего, публикуют исключительно то, что хотят, или то, что подсказали», — объяснял хакер позже. Потом он обратил внимание на государственные ресурсы. Вскоре на главной странице грузинского парламента появились фотографии грузинского президента Михаила Саакашвили, на которых он сравнивался с Гитлером. «И кончит он так же… — гласила подпись. — Hacked by South Ossetia Hack Crew».
О своей атаке на Грузию Стройков впоследствии рассказал журналу «Хакер», объяснив, что «кибервойны стали неотъемлемой частью реальных, кровопролитных событий». Чем он занимался после тех событий, неизвестно; судя по его нынешней странице во «ВКонтакте», Стройков любит камуфляжную одежду и ходит на охоту с ружьем. На вопросы «Медузы» он не ответил.
В социальной сети у хакера 36 друзей, большинство — из Хабаровска, где он по-прежнему живет. Исключение — Дмитрий Докучаев, сотрудник ФСБ, известный как хакер Forb. Как и Стройков, Докучаев писал для журнала «Хакер» (благодаря журналу многие хакеры познакомились между собой) — он даже был редактором рубрики «Взлом».
Несколько русскоязычных хакеров в разговоре с «Медузой» сказали, что именно Докучаев первым из хакеров перешел на постоянную работу в спецслужбы. Видимо, это произошло в 2005–2006 годах, когда им заинтересовались из-за кардинга; подозрения о новой работе Докучаева у многих его коллег по форумам появились, по их воспоминаниям, в 2008-м — после этого они стали внимательнее следить за тем, что пишут.
Именно Докучаев, возможно, курировал хакерские атаки на инфраструктуру Демократической партии США в 2016 году во время выборов в США. Он же привлекал хакеров на работу на спецслужбы.
В юности Дмитрий Докучаев, как и многие подростки, увлекался поэзией — иногда лирической, иногда про компьютеры и интернет. Он объяснял, что «даже самый „компьютерный“ человек изредка склонен к романтике и стихам :)». В 2001 году, он, например, написал такие строки (орфография и пунктуация сохранены):
Linux — Rules, Винда — маздай форева.
Так говорили мне друзья,
Проверить я решил, купив редхат нулевый,
Живя во грезах, диски форматя.
Вдруг непонятные экраны и таблицы:
Тут нужен своп , а здесь — резервный диск,
Смотрю я книги, листаю все страницы…
Как кто-то говорил: «Без бутыля не обойтись».
Уф… Разобрался. Идет формат разделов
Мне нужно выбрать компоненты для инсталла
Я уж не соображаю, башка вся запотела,
Весь выложился тут, а Linux`у все мало.
Проходит час-другой, Ура! luck!
Setup complete. со второй попытки.
Волнуясь, радуясь, я от счастья плачу,
No! Это не RedHat, а просто пытка…
Докучаев родился в Каменске-Уральском — бедном городе в часе езды от Екатеринбурга. Последний раз Каменск-Уральский попадал в новости в 2013 году — после того, как там появилась радикальная группировка, преследовавшая гомосексуалов (однажды они приехали с мужчиной на кладбище, заставили его вырвать надгробие, а потом преследовали его на джипе — такие операции активисты называли «сафари»). Сам хакер описывал родной город так: «Насчитывает 200 тысяч жителей, что совсем немного. В Каменске-Уральском очень много заводов, как правило по металлообработке, — трубный, металлургический, алюминиевый. Городу скоро стукнет 300 лет. Не такой и старый, но уже и немолодой. Немного о достопримечательностях: это, конечно, вам не Москва, но в Каменске есть краеведческий музей, очень много театров, библиотек, стадионов, спорткомплексов и интернет-кафе».
В последних Докучаев в юности и проводил большую часть своего времени — много играл в видеоигры: Worms Armageddon, Need for Speed, Quake 3. Свой первый взлом он совершил в городской сети, чтобы получить бесплатный доступ в интернет. «Я всегда считал, что информация должна быть свободной, поэтому платить провайдеру за предоставление доступа ужасно не хотелось», — вспоминал он.
После школы Докучаев поступил в политехнический институт в Екатеринбурге на факультет информационных систем в технике и технологиях; позже стал работать системным администратором на кафедре одного из екатеринбургских университетов. О себе он подробно рассказывал на своем сайте (сейчас удален), который назывался «Dmitryʼs homepage. The best…». В 2002 году он без стеснения писал, что «приобретает популярность в инете и не только ;) Сотрудничаю с редакцией журнала „Хакер“ и получаю приличный гонорар ;)». Свой ник — Forb — он образовал от английского слова forbidden, «запрещенный».
Кроме раздела с найденными программными уязвимостями на сайте Докучаева был и раздел с его фотографиями: «Я на диване (1997 год)» (подросток в клетчатой фланелевой рубашке и спортивных штанах сидит на диване), в МИФИ, в Крыму, на дискотеке у Черного моря.
В 2004 году Докучаев занимался кардингом и взламывал сайты по заказу — о том, как это делать, он подробно рассказывал на собственном сайте. Своим главным достижением хакер считал взлом одного из правительственных сайтов США. В 2006-м переехал в Москву и стал работать в журнале «Хакер».
Его знакомые вспоминали, что после переезда он женился на девушке, которую вскоре научил взламывать сайт русского Cosmopolitan. Докучаев с коллегами много веселились и выпивали вместе, иногда попадая в истории. «Беспредел доходил даже до криминала, клево было, все пати и встречи проходили беспокойно, но весело», — вспоминал один из них. Как-то во время очередной пьянки Докучаев подсадил его на трехметровую высоту, чтобы сломать камеру видеонаблюдения. После этого они убегали от полицейских — и наткнулись на сотрудника ФСБ, от которого хакер «получил в челюсть».

Вскоре Докучаев и сам стал сотрудничать с ФСБ — а потом и перешел туда на работу, став старшим оперуполномоченным 2-го отдела оперативного управления ЦИБ ФСБ, департамента, занимающегося киберзащитой государства и расследованием хакерских дел, связанных с угрозой безопасности страны. Там он трудился до 2016 года, когда его арестовали.
Докучаев был знаком не только со Стройковым, но и с другими хакерами. Один из них, как и Докучаев, тоже был родом из Каменска-Уральского. Как и земляк, Константин Козловский постоянно сидел на русскоязычных хакерских форумах — тогда, как рассказывает один из коллег Докучаева и Козловского, на них была «атмосфера, что нужно помогать России, защищать ее и атаковать банки США и европейских стран, — там деньги все равно застрахованы, а в России после 1990-х они нужнее». Через несколько лет Козловский создаст группировку Lurk, которая будет атаковать инфраструктуру уже российских банков («Медуза» подробно писала об этом деле), — а когда в 2017-м его арестуют, заявит, что Докучаев курировал его работу. Козловский утверждает , что именно он — по заданию Докучаева — взламывал Национальный комитет Демократической партии США и другие цели в Америке. Докучаев, который к моменту заявления Козловского также находился в СИЗО, отвергает эти обвинения.
Спецслужбы США считают , что Докучаев, будучи майором ФСБ, курировал хакеров, которые атаковали компьютерные сети американских государственных и коммерческих структур. В России его, видимо, обвиняют в том, что он работал двойным агентом и передавал американцам информацию о российских хакерах. Арестовали Докучаева вместе с одним из руководителей ЦИБ ФСБ Сергеем Михайловым (ему при задержании показательно надели на голову мешок) и Русланом Стояновым из «Лаборатории Касперского», который уже из СИЗО предостерегал государство от сотрудничества с хакерами; всех их обвиняют в госизмене. В апреле 2018 года РБК сообщал , что Докучаев подписал досудебное соглашение о частичном признании вины в передаче данных иностранным спецслужбам, — по информации издания, сотрудник ФСБ считал, что таким образом помогает бороться с киберпреступностью.
Президент России Владимир Путин впервые высказался о хакерах-патриотах в июне 2017 года. «Хакеры — свободные люди! — заявил он на Петербургском экономическом форуме. — Как художники. Настроение у них хорошее — они встали с утра и картины рисуют. Так же и хакеры: они проснулись сегодня, прочитали, что там что-то происходит в межгосударственных отношениях. Если они настроены патриотически, они начинают вносить свою лепту, как они считают правильным в борьбе с теми, кто плохо отзывается о России».
Российские спецслужбы, видимо, и сейчас продолжают вербовать хакеров в обмен на закрытие уголовного дела. В июле 2018 года в Белгороде суд прекратил уголовное дело в отношении местного жителя, который совершил 545 кибератак на официальный сайт ФСБ. Дело было прекращено по ходатайству следователя ФСБ.
Daniil Turovsky