Sign up for our daily briefing

Make your busy days simpler with Axios AM/PM. Catch up on what's new and why it matters in just 5 minutes.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Catch up on the day's biggest business stories

Subscribe to Axios Closer for insights into the day’s business news and trends and why they matter

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Stay on top of the latest market trends

Subscribe to Axios Markets for the latest market trends and economic insights. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Sports news worthy of your time

Binge on the stats and stories that drive the sports world with Axios Sports. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Tech news worthy of your time

Get our smart take on technology from the Valley and D.C. with Axios Login. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Get the inside stories

Get an insider's guide to the new White House with Axios Sneak Peek. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Denver news?

Get a daily digest of the most important stories affecting your hometown with Axios Denver

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Des Moines news?

Get a daily digest of the most important stories affecting your hometown with Axios Des Moines

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Twin Cities news?

Get a daily digest of the most important stories affecting your hometown with Axios Twin Cities

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Tampa Bay news?

Get a daily digest of the most important stories affecting your hometown with Axios Tampa Bay

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Charlotte news?

Get a daily digest of the most important stories affecting your hometown with Axios Charlotte

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Photo: Mikhail Svetlov/Getty Images

We knew that Russians previously targeted more than 20 states' voter registration databases, and likely targeted all 50. Now we know the complexity behind how 12 Russian military officers interfered in the U.S. elections thanks to a federal grand jury indictment released Friday.

The big picture: The information in this indictment will be vastly important for those trying to bolster election security and monitoring, and learning what to train for in basic cyber hygiene practices — which is especially important since we know Russia is likely to try interfering again.

By the numbers
  • The Russian military intelligence officers targeted over 300 people associated with the DCCC, DNC, and Hillary Clinton's campaign, monitored dozens of DCCC and DNC employees, and implanted hundreds of files with malware to steal emails and other documents.
  • In 2015 the Russians collected emails from individuals affiliated with the Republican Party in other spearphishing operations.
  • Starting in June 2016, they eventually disseminated over 50,000 documents using fake online personas, including DCLeaks and Guccifer 2.0, and through a web site, likely WikiLeaks. They worked through November 2016.
  • 11 Russian military intelligence officers are charged with conspiracy to commit computer crimes, 8 counts of aggravated identity theft, conspiracy to launder money, and 2 are charged with separate conspiracy to commit computer crimes.
How they did it

The Russian intelligence officers used spearphishing to steal victims’ passwords or access their computers.

  • For example, they allegedly spoofed email accounts to make it appear as if they came from Google, and once created an email account just one letter off from an email of a known member of the Clinton Campaign.

The Russians researched the computer networks of the DCCC (and DNC), including internet protocol configurations to identify connected devices.

  • They stole a DCCC employee’s credentials via a spearphishing email to access the network, and installed different kinds of malware on at least 10 computers to spy on and steal data using keylogs and screenshots. The Russians gained screenshots of an employee looking at the DCCC's online banking information.
  • They malware transferred information to a GRU-leased server in Arizona and established a middle server overseas to obscure the connection between the Arizona server and the DCCC.

The Russians hacked into the DNC via their access to the DCCC network through an employee who was authorized to access the DNC network. This employee’s computer was monitored with keylogs and screenshots, which is how the Russians stole those credentials.

  • The Russians gained access to 33 computers at the DNC and again installed different kinds of malware, which sent keylogs and screenshots back to the Arizona server.
  • The Russians hacked the Microsoft Exchange Server and stole thousands of emails from DNC work emails.
Efforts to conceal

The Russians covered their tracks by deleting logs and computer files related to the DCCC and DNC hacking. They also tried deleting traces of their work on DCCC computers with a program, CCleaner.

  • The conspirators laundered the equivalent of $95,000 through transactions meant to conceal their identities, including to purchase a virtual private network (VPN) account and to lease a server in Malaysia to host some dissemination web sites. Many of the companies processing these transactions were located in the U.S.
    • They also paid for their infrastructure by mining bitcoin, obtaining bitcoin from peer-to-peer exchanges, and using pre-paid cards.
  • They further masked their identities by purchasing infrastructure to use hundreds of different email accounts, sometimes using a new account for each purchase, and made false statements about their identities and used fake personas online to disseminate information.
Election meddling
  • They hacked the web site of a state board of elections and stole information of approximately 500,000 voters, including names, addresses, partial social security numbers, birthdays, and driver’s license numbers.
  • The Russians hacked into computers of a U.S. vendor that supplied software to verify voter registration information.
  • They designed an email account to look like the vendor’s email addresses and sent over 100 spearphishing emails containing malware to organizations and personnel involved in administrating elections in counties in Florida.
  • They targeted state and county offices that administered the 2016 U.S. elections, including accessing the web sites of counties in Georgia, Iowa, and Florida to identify vulnerabilities.
Fake personas

These names have been used as aliases for the Russian intelligence officers to encourage the dissemination of stolen information and to exchange bitcoin to fund their activity.

  • Mike Long
  • Ward DeClaur
  • Daniel Farrell
  • Jason Scott
  • Richard Gingrey
  • Alice Donovan
  • Den Katenberg
  • Yuliana Martynova
  • Karen W. Millen
  • James McMorgans
  • Kate S. Milton
  • @BaltimoreIsWhr
  • @dcleaks_
  • Guccifer 2.0
  • dirbinsaabol@mail.com
  • hi.mymail@yandex.com

Editor's Note: Get more stories like this by signing up for our daily morning newsletter, Axios AM. 

Go deeper

Updated 3 hours ago - World

Skripal poisoning suspects linked to Czech blast, as country expels 18 Russians

Combined images released by British police in 2018 of Alexander Petrov (L) and Ruslan Boshirov, who are suspected of carrying out an attack in the in the southern English city of Salisbury using Novichok, a military-grade nerve agent, and also the2014 Czech depot explosion. Photo: Metropolitan Police via Getty Images

Czech police on Saturday connected two Russian men suspected of carrying out a poisoning attack in Salisbury, England, with a deadly ammunition depot explosion southeast of the capital, Prague, per Reuters.

Driving the news: Czech officials announced Saturday they're expelling 18 Russian diplomats they accuse of being involved in the blast in Vrbětice, AP notes. Czech police said later they're searching for two men carrying several passports — including two with the names Alexander Petrov and Ruslan Boshirov.

Indianapolis mass shooting suspect legally bought 2 guns, police say

Marion County Forensic Services vehicles are parked at the site of a mass shooting at a FedEx facility in Indianapolis, Indiana, on Friday. Photo: Jeff Dean/AFP via Getty Images

The suspected gunman in this week's mass shooting at a FedEx facility in Indianapolis legally purchased two "assault rifles" believed to have been used in the attack, police said late Saturday.

Of note: The Indianapolis Metropolitan Police Department's statement that Brandon Scott Hole, 19, bought the rifles last July and September comes a day after the FBI told news outlets that a "shotgun was seized" from the suspect in March 2020 after his mother raised concerns about his mental health.

U.S. and China agree to take joint climate action

US Special Presidential Envoy for Climate John Kerry waves as he arrives at the Elysee Presidential Palace on March 10, 2021 in Paris. Photo: Chesnot/Getty Images

Despite an increasingly tense relationship, the U.S. and China agreed Saturday to work together to tackle global climate change, including by "raising ambition" for emissions cuts during the 2020s — a key goal of the Biden administration.

Why it matters: The joint communique released Saturday evening commits the world's two largest emitters of greenhouse gases to work together to keep the most ambitious temperature target contained in the Paris Climate Agreement viable by potentially taking additional emissions cuts prior to 2030.