- Now THIS is a really interesting development in #DncHack: @Gawker has & is publishing the DNC's Trump oppo research http://gawker.com/this-looks-like-the-dncs-hacked-trump-oppo-file-1782040426 …
https://twitter.com/pwnallthethings/status/743179750064037888
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 20:33:54 - This is a big development, because it means whoever did #DncHack to get Trump oppo file was doing it (bear with me) in *support* of Trump.
https://twitter.com/pwnallthethings/status/743180111038472192
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 20:35:20 - How does this help Trump, you ask? It's a full dump. Trump gets lots of bad news today, but DNC loses ability to use contents strategically.
https://twitter.com/pwnallthethings/status/743180624731717636
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 20:37:23 - A few observations about this op 1) Another data point in Russian SIGINT strategically leaking stolen data to push a particular narrative.
https://twitter.com/pwnallthethings/status/743183682530324480
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 20:49:32
2) This para. V. bad for DNC if those are classification markings (but could be campaign "doc is sensitive" bluster) pic.twitter.com/aaHiQhdaAMhttps://twitter.com/pwnallthethings/status/743184280008916992
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 20:51:54
3) Gosh, I wonder what outlet Russian intelligence is going to use to launder these stolen documents. pic.twitter.com/4zjF7tXySLhttps://twitter.com/pwnallthethings/status/743184776547340288
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 20:53:53- 4) If you want to peruse the Trump oppo research directly, here's the PDF: https://assets.documentcloud.org/documents/2861555/1.pdf …
https://twitter.com/pwnallthethings/status/743184953546924033
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 20:54:35
5) Site apparently set up by the group that hacked DNC https://guccifer2.wordpress.com/ pic.twitter.com/8jUqw9tLnMhttps://twitter.com/pwnallthethings/status/743191210718797824
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 21:19:27- 6) This is all of the text from the hacker's post, in case website gets taken down. Check out the broken English. pic.twitter.com/gW6ZK2Ox8e
https://twitter.com/pwnallthethings/status/743191996437770241
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 21:22:34
7) Uh oh. This is an unfortunate document for Russia to stolen from under the noses of the DNC. pic.twitter.com/ilrBQBNPXEhttps://twitter.com/pwnallthethings/status/743194146752565248
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 21:31:07https://twitter.com/pwnallthethings/status/743197064843104257
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 21:42:42
9) Better #opsec in the "NatSec & Foreign Policy" doc. Attackers using VMs to open some (but clearly not all) docs pic.twitter.com/WgOeom0Rj7https://twitter.com/pwnallthethings/status/743199185596465152
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 21:51:08
10) Files from Russian Intelligence Agencies can contain viruses. It's safer to stay in Protected View pic.twitter.com/ZNjMZ6LYqrhttps://twitter.com/pwnallthethings/status/743200699975086083
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 21:57:09
11) Document #5 leaks via tracked changes (thx @TheCyberSecExp) but it's not very interesting, and likely not hacker pic.twitter.com/jhg4I00pxGhttps://twitter.com/pwnallthethings/status/743201610235514880
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 22:00:46- 12) To clarify: leak is the RU-lang settings, not name (cover name references "Iron Felix" https://en.wikipedia.org/wiki/Felix_Dzerzhinsky …) https://twitter.com/alcebaid/status/743202087601844225 …
https://twitter.com/pwnallthethings/status/743203462683496448
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 22:08:08 - 13) Another #opsec fail. (This happened because they did an Export as PDF, and then later saved, w/ lang set to RU) https://twitter.com/daviottenheimer/status/743199165459529728 …
https://twitter.com/pwnallthethings/status/743208737469509632
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 22:29:05 - 14) Tldr: this "lone hacker" uses many VMs, speaks Russian; username is founder of USSR secret police & likes laundering docs via Wikileaks.
https://twitter.com/pwnallthethings/status/743209989217587200
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 22:34:04 - 15) Spot the difference: Left: doc sent to Gawker (page 210). On right, same page in https://guccifer2.wordpress.com/ pic.twitter.com/0Wogj3TXuS
https://twitter.com/pwnallthethings/status/743211918995951616
— Pwn All The Things (@pwnallthethings)Wed, Jun 15 2016 22:41:44
