In Ukraine, a Malware Expert Who Could Blow the Whistle on Russian Hacking – New York Times
There is no evidence that Profexer worked, at least knowingly, for Russias intelligence services, but his malware apparently did.
That a hacking operation that Washington is convinced was orchestrated by Moscow would obtain malware from a source in Ukraine perhaps the Kremlins most bitter enemy sheds considerable light on the Russian security services modus operandi in what Western intelligence agencies say is their clandestine cyberwar against the United States and Europe.
It does not suggest a compact team of government employees who write all their own code and carry out attacks during office hours in Moscow or St. Petersburg, but rather a far looser enterprise that draws on talent and hacking tools wherever they can be found.
Also emerging from Ukraine is a sharper picture of what the United States believes is a Russian government hacking group known as Advanced Persistent Threat 28 or Fancy Bear. It is this group, which American intelligence agencies believe is operated by Russian military intelligence, that has been blamed, along with a second Russian outfit known as Cozy Bear, for the D.N.C. intrusion.
Rather than training, arming and deploying hackers to carry out a specific mission like just another military unit, Fancy Bear and its twin Cozy Bear have operated more as centers for organization and financing; much of the hard work like coding is outsourced to private and often crime-tainted vendors.
In more than a decade of tracking suspected Russian-directed cyberattacks against a host of targets in the West and in former Soviet territories NATO, electrical grids, research groups, journalists critical of Russia and political parties, to name a few security services around the world have identified only a handful of people who are directly involved in either carrying out such attacks or providing the cyberweapons that were used.
This absence of reliable witnesses has left ample room for President Trump and others to raise doubts about whether Russia really was involved in the D.N.C. hack.
There is not now and never has been a single piece of technical evidence produced that connects the malware used in the D.N.C. attack to the G.R.U., F.S.B. or any agency of the Russian government, said Jeffrey Carr, the author of a book on cyberwarfare. The G.R.U. is Russias military intelligence agency, and the F.S.B. its federal security service.
United States intelligence agencies, however, have been unequivocal in pointing a finger at Russia.
Seeking a path out of this fog, cybersecurity researchers and Western law enforcement officers have turned to Ukraine, a country that Russia has used for years as a laboratory for a range of politicized operations that later cropped up elsewhere, including electoral hacking in the United States.
In several instances, certain types of computer intrusions, like the use of malware to knock out crucial infrastructure or to pilfer email messages later released to tilt public opinion, occurred in Ukraine first. Only later were the same techniques used in Western Europe and the United States.
So, not surprisingly, those studying cyberwar in Ukraine are now turning up clues in the investigation of the D.N.C. hack, including the discovery of a rare witness.
Security experts were initially left scratching their heads when the Department of Homeland Security on Dec. 29 released technical evidence of Russian hacking that seemed to point not to Russia, but rather to Ukraine.
In this initial report, the department released only one sample of malware said to be an indicator of Russian state-sponsored hacking, though outside experts said a variety of malicious programs were used in Russian electoral hacking.
The sample pointed to a malware program, called the P.A.S. web shell, a hacking tool advertised on Russian-language Dark Web forums and used by cybercriminals throughout the former Soviet Union. The author, Profexer, is a well-regarded technical expert among hackers, spoken about with awe and respect in Kiev.
He had made it available to download, free, from a website that asked only for donations, ranging from $3 to $250. The real money was made by selling customized versions and by guiding his hacker clients in its effective use. It remains unclear how extensively he interacted with the Russian hacking team.
After the Department of Homeland Security identified his creation, he quickly shut down his website and posted on a closed forum for hackers, called Exploit, that Im not interested in excessive attention to me personally.
Soon, a hint of panic appeared, and he posted a note saying that, six days on, he was still alive.
Another hacker, with the nickname Zloi Santa, or Bad Santa, suggested the Americans would certainly find him, and place him under arrest, perhaps during a layover at an airport.
It could be, or it could not be, it depends only on politics, Profexer responded. If U.S. law enforcement wants to take me down, they will not wait for me in some countrys airport. Relations between our countries are so tight I would be arrested in my kitchen, at the first request.
In fact, Serhiy Demediuk, chief of the Ukrainian Cyber Police, said in an interview that Profexer went to the authorities himself. As the cooperation began, Profexer went dark on hacker forums. He last posted online on Jan. 9. Mr. Demediuk said he had made the witness available to the F.B.I., which has posted a full-time cybersecurity expert in Kiev as one of four bureau agents stationed at the United States Embassy there. The F.B.I. declined to comment.
Profexer was not arrested because his activities fell in a legal gray zone, as an author but not a user of malware, the Ukrainian police say. But he did know the users, at least by their online handles. He told us he didnt create it to be used in the way it was, Mr. Demediuk said.
A member of Ukraines Parliament with close ties to the security services, Anton Gerashchenko, said that the interaction was online or by phone and that the Ukrainian programmer had been paid to write customized malware without knowing its purpose, only later learning it was used in the D.N.C. hack.
Mr. Gerashchenko described the author only in broad strokes, to protect his safety, as a young man from a provincial Ukrainian city. He confirmed that the author turned himself in to the police and was cooperating as a witness in the D.N.C. investigation. He was a freelancer and now he is a valuable witness, Mr. Gerashchenko said.
While it is not known what Profexer has told Ukrainian investigators and the F.B.I. about Russias hacking efforts, evidence emanating from Ukraine has again provided some of the clearest pictures yet about Fancy Bear, or Advanced Persistent Threat 28, which is run by the G.R.U.
Fancy Bear has been identified mostly by what it does, not by who does it. One of its recurring features has been the theft of emails and its close collaboration with the Russian state news media.
Tracking the bear to its lair, however, has so far proved impossible, not least because many experts believe that no such single place exists.
Even for a sophisticated tech company like Microsoft, singling out individuals in the digital miasma has proved just about impossible. To curtail the damage to clients operating systems, the company filed a complaint against Fancy Bear last year with the United States District Court for the Eastern District of Virginia but found itself boxing with shadows.
As Microsoft lawyers reported to the court, because defendants used fake contact information, anonymous Bitcoin and prepaid credit cards and false identities, and sophisticated technical means to conceal their identities, when setting up and using the relevant internet domains, defendants true identities remain unknown.
Nevertheless, Ukrainian officials, though wary of upsetting the Trump administration, have been quietly cooperating with American investigators to try to figure out who stands behind all the disguises.
Included in this sharing of information were copies of the server hard drives of Ukraines Central Election Commission, which were targeted during a presidential election in May 2014. That the F.B.I. had obtained evidence of this earlier, Russian-linked electoral hack has not been previously reported.
Traces of the same malicious code, this time a program called Sofacy, were seen in the 2014 attack in Ukraine and later in the D.N.C. intrusion in the United States.
Intriguingly, in the cyberattack during the Ukrainian election, what appears to have been a bungle by Channel 1, a Russian state television station, inadvertently implicated the government authorities in Moscow.
Hackers had loaded onto a Ukrainian election commission server a graphic mimicking the page for displaying results. This phony page showed a shocker of an outcome: an election win for a fiercely anti-Russian, ultraright candidate, Dmytro Yarosh. Mr. Yarosh in reality received less than 1 percent of the vote.
The false result would have played into a Russian propaganda narrative that Ukraine today is ruled by hard-right, even fascist, figures.
The fake image was programmed to display when polls closed, at 8 p.m., but a Ukrainian cybersecurity company, InfoSafe, discovered it just minutes earlier and unplugged the server.
State television in Russia nevertheless reported that Mr. Yarosh had won and broadcast the fake graphic, citing the election commissions website, even though the image had never appeared there. The hacker had clearly provided Channel 1 with the same image in advance, but the reporters had failed to check that the hack actually worked.
For me, this is an obvious link between the hackers and Russian officials, said Victor Zhora, director of InfoSafe, the cybersecurity company that first found the fake graphic.
A Ukrainian government researcher who studied the hack, Nikolai Koval, published his findings in a 2015 book, Cyberwar in Perspective, and identified the Sofacy malware on the server.
The mirror of the hard drive went to the F.B.I., which had this forensic sample when the cybersecurity company CrowdStrike identified the same malware two years later, on the D.N.C. servers.
It was the first strike, Mr. Zhora said of the earlier hack of Ukraines electoral computers. Ukraines Cyber Police have also provided the F.B.I. with copies of server hard drives showing the possible origins of some phishing emails targeting the Democratic Party during the election.
In 2016, two years after the election hack in Ukraine, hackers using some of the same techniques plundered the email system of the World Anti-Doping Agency, or WADA, which had accused Russian athletes of systematic drug use.
That raid, too, seems to have been closely coordinated with Russian state television, which began airing well-prepared reports about WADAs hacked emails just minutes after they were made public. The emails appeared on a website that announced that WADA had been hacked by a group calling itself the Fancy Bears Hack Team.
It was the first time Fancy Bear had broken cover.
Fancy Bear remains extraordinarily elusive, however. To throw investigators off its scent, the group has undergone various makeovers, restocking its arsenal of malware and sometimes hiding under different guises. One of its alter egos, cyberexperts believe, is Cyber Berkut, an outfit supposedly set up in Ukraine by supporters of the countrys pro-Russian president, Viktor F. Yanukovych, who was ousted in 2014.
After lying dormant for many months, Cyber Berkut jumped back into action this summer just as multiple investigations in Washington into whether the Trump campaign colluded with Moscow shifted into high gear. Cyber Berkut released stolen emails that it and Russian state news media said had exposed the real story: Hillary Clinton had colluded with Ukraine.
Continued here:
In Ukraine, a Malware Expert Who Could Blow the Whistle on Russian Hacking - New York Times
- EU poised to agree on using frozen Russian assets to help Ukraine in war - Al Jazeera - October 26th, 2025 [October 26th, 2025]
- Trump's U-turns on Russia and Ukraine, and the significance of new sanctions: ANALYSIS - ABC News - Breaking News, Latest News and Videos - October 26th, 2025 [October 26th, 2025]
- Ukraine war: Trump hopes China will help bring end to Russia war - BBC - October 26th, 2025 [October 26th, 2025]
- Donald Tusk: Ukraine is ready to fight on for three more years - The Times - October 26th, 2025 [October 26th, 2025]
- Zelenskyy said Ukraine prepared to fight for three more years Polish PM - - October 26th, 2025 [October 26th, 2025]
- Ukraine ready to fight for the next three years, says Polands PM Tusk - The Independent - October 26th, 2025 [October 26th, 2025]
- Polish PM says Ukraine ready to keep fighting for at least another two or three years - TVP World - October 26th, 2025 [October 26th, 2025]
- Ukraine war briefing: US reportedly mulling further sanctions on Russia that could hit banking sector - The Guardian - October 26th, 2025 [October 26th, 2025]
- US could hit Russia with more sanctions over Ukraine war, but also wants Europe to increase pressure - Reuters - October 26th, 2025 [October 26th, 2025]
- Ukraine war live: Trump says no Putin meeting until peace deal is within reach - The Independent - October 26th, 2025 [October 26th, 2025]
- How the U.S.'s new sanctions on Russia could impact the war in Ukraine - NPR - October 26th, 2025 [October 26th, 2025]
- At least four killed in Russian strikes overnight on Ukraine - The Guardian - October 26th, 2025 [October 26th, 2025]
- Slovakia will not be part of EU scheme for Ukraine's military needs, PM Fico says - Reuters - October 26th, 2025 [October 26th, 2025]
- Polish prime minister says Ukraine ready to fight Russia for 'two to three more years' - Anadolu Ajans - October 26th, 2025 [October 26th, 2025]
- Russia Unleashed More Than 5,000 Suicide Drones on Ukraine in September - The National Interest - October 26th, 2025 [October 26th, 2025]
- Serbian foreign minister proposes hosting Ukraine-Russia peace negotiations amid ongoing conflict - Fox News - October 26th, 2025 [October 26th, 2025]
- Trump says he will not meet with Putin until he thinks there is a deal on Ukraine - Reuters - October 26th, 2025 [October 26th, 2025]
- Ukraine ready to fight for the next three years, says Polands PM Tusk - Yahoo News New Zealand - October 26th, 2025 [October 26th, 2025]
- How Ukraine and Russia are playing out a deadly cat and mouse drone war from underground bunkers - The Independent - October 26th, 2025 [October 26th, 2025]
- AI drones in Ukraine this is where we're at - The Kyiv Independent - October 26th, 2025 [October 26th, 2025]
- The wild card' weapon that will decide Ukraine's fate - but could spark WW3... - The US Sun - October 26th, 2025 [October 26th, 2025]
- What is the reparations loan for Ukraine and why is the EU stuck with the plan? - Euronews.com - October 26th, 2025 [October 26th, 2025]
- US reportedly readies new sanctions as Russia stalls on Ukraine peace talks - The Kyiv Independent - October 26th, 2025 [October 26th, 2025]
- MrBeast Just Flew Three Lions Out of Ukraine. Heres Why - UNITED24 Media - October 26th, 2025 [October 26th, 2025]
- Europes Persistence in Supporting Ukraine Is Bearing Fruit - The New York Times - October 24th, 2025 [October 24th, 2025]
- Why Trump Reached a Breaking Point With Putin Over Russia-Ukraine War - WSJ - The Wall Street Journal - October 24th, 2025 [October 24th, 2025]
- Kyiv's allies say frozen Russian assets should be quickly used to aid Ukraine - Reuters - October 24th, 2025 [October 24th, 2025]
- US sanctions on Russia over Ukraine add pressure on Putin to end war - CNN - October 24th, 2025 [October 24th, 2025]
- Russian Envoy Says US, Russia, And Ukraine Are Close To A 'Diplomatic Solution' To War In Ukraine - Radio Free Europe/Radio Liberty - October 24th, 2025 [October 24th, 2025]
- Ukraine picked the Gripen. Heres why and where there may be challenges - Breaking Defense - October 24th, 2025 [October 24th, 2025]
- Ukraine allies determined to to go further than ever to pressure Putin - Al Jazeera - October 24th, 2025 [October 24th, 2025]
- Russias human safari in southern Ukraine is a warning to the world - Atlantic Council - October 24th, 2025 [October 24th, 2025]
- A youth orchestra in Ukraine creates an overture with the sounds of war - NPR - October 24th, 2025 [October 24th, 2025]
- Ukraine war briefing: Zelenskyy urges US to expand Russia oil sanctions - The Guardian - October 24th, 2025 [October 24th, 2025]
- Rand Paul: Trump could see all hell break loose with further involvement in Ukraine, Venezuela - The Hill - October 24th, 2025 [October 24th, 2025]
- EU leaders delay decision on using frozen Russian funds to aid Ukraine - Al Jazeera - October 24th, 2025 [October 24th, 2025]
- Sanctions alone won't force Putin to end Ukraine war - Sky News - October 24th, 2025 [October 24th, 2025]
- Rosenberg: Trump abandons carrot and wields stick over Putin in Ukraine talks - BBC - October 24th, 2025 [October 24th, 2025]
- At least three killed in hand grenade attack at northern Ukraine train station - Euronews.com - October 24th, 2025 [October 24th, 2025]
- Opinion | How to arm Ukraine and disarm Hamas - The Washington Post - October 24th, 2025 [October 24th, 2025]
- From illusion to real peace: Trumps test in Gaza and Ukraine - Al Jazeera - October 24th, 2025 [October 24th, 2025]
- Putin envoy Dmitriev says US, Ukraine and Russia close to 'diplomatic solution' on war - Reuters - October 24th, 2025 [October 24th, 2025]
- The Ark Review: Ukraine-Set Doc Puts a Hopeful Spin on a Young Familys Wartime Pivot - The Hollywood Reporter - October 24th, 2025 [October 24th, 2025]
- Whats Next for US-Russia Relations and the War in Ukraine? - Chicago Council on Global Affairs - October 24th, 2025 [October 24th, 2025]
- Sen. Paul says Trump's base is irritated by continued involvement in Ukraine, Venezuela - The National Desk - October 24th, 2025 [October 24th, 2025]
- Ukraine will have to find a way to produce air defences, Zelenskiy says - Reuters - October 24th, 2025 [October 24th, 2025]
- What a Soaring Ruble Says About the Russia-Ukraine War, and How to Trade It Now - Yahoo Finance - October 24th, 2025 [October 24th, 2025]
- Ukraine Has 49 New M1A1 Abrams Tanks and America Isnt Happy One Bit - National Security Journal - October 24th, 2025 [October 24th, 2025]
- North Korea to build museum glorifying its troops fighting against Ukraine - politico.eu - October 24th, 2025 [October 24th, 2025]
- US imposes sanctions on Russian oil over Putins refusal to end war in Ukraine - The Guardian - October 23rd, 2025 [October 23rd, 2025]
- Ukraine war latest: Trump declares 'it was time' as US hits Russia's biggest oil firms with sanctions - Sky News - October 23rd, 2025 [October 23rd, 2025]
- How Europe Is Trying to Turn Frozen Russian Assets Into Cash for Ukraine - The New York Times - October 23rd, 2025 [October 23rd, 2025]
- What Are Gripen Fighter Jets and Why Does Ukraine Want Them From Sweden? - The New York Times - October 23rd, 2025 [October 23rd, 2025]
- Ukraine unveils upgraded sea drone it says can strike anywhere in the Black Sea - AP News - October 23rd, 2025 [October 23rd, 2025]
- Why planned Trump-Putin talks collapsed, and what it means for Ukraine - Al Jazeera - October 23rd, 2025 [October 23rd, 2025]
- As the US flip-flops on the path to peace, Europes coalition of the willing rallies round Ukraine - The Guardian - October 23rd, 2025 [October 23rd, 2025]
- Russia unleashes fresh wave of deadly strikes on Ukraine after Trump's summit with Putin called off - CBS News - October 23rd, 2025 [October 23rd, 2025]
- Mixed Signals from Washington Cost Lives in Ukraine - The Bulwark - October 23rd, 2025 [October 23rd, 2025]
- EU split over whether to let Ukraine use 140B loan to buy US weapons - politico.eu - October 23rd, 2025 [October 23rd, 2025]
- Ukraine moves to buy scores of Saab Gripen fighters from Sweden - Breaking Defense - October 23rd, 2025 [October 23rd, 2025]
- Swarms of Russian drones plunge parts of Ukraine into darkness, as Zelensky turns to Europe again - CNN - October 23rd, 2025 [October 23rd, 2025]
- Huge Gripen Fighter Order Letter Of Intent Signed By Ukraine - The War Zone - October 23rd, 2025 [October 23rd, 2025]
- Trump drops Ukraine missile restrictions (or not) and hits 'dishonest' Putin with oil sanctions - Euractiv - October 23rd, 2025 [October 23rd, 2025]
- What are the Gripen fighter jets Ukraine wants to buy from Sweden? - Reuters - October 23rd, 2025 [October 23rd, 2025]
- Wildfires have consumed vast chunks of Ukraine. Is Russia deliberately fuelling the flames? - The Guardian - October 23rd, 2025 [October 23rd, 2025]
- Ukraine's 'sea baby' drones are growing up with longer range, bigger payload - Reuters - October 23rd, 2025 [October 23rd, 2025]
- EU summit aims for new Russia sanctions and a plan to use Moscow's assets to help Ukraine - AP News - October 23rd, 2025 [October 23rd, 2025]
- Trump denies that US approved Ukraine's use of long-range missiles in Russia - Anadolu Ajans - October 23rd, 2025 [October 23rd, 2025]
- Russia is refusing to negotiate around Ukraine. So Kyiv wants allies to dial up the pressure. - CBC - October 23rd, 2025 [October 23rd, 2025]
- Explosions reported near military base in southern Russia, blasts allegedly rock ammunition plant 1,700 km from Ukraine - The Kyiv Independent - October 23rd, 2025 [October 23rd, 2025]
- Ukraine Aid Groups Targeted Through Fake Zoom Meetings and Weaponized PDF Files - The Hacker News - October 23rd, 2025 [October 23rd, 2025]
- Tracking the kidnapped children of Ukraine - CNN - October 23rd, 2025 [October 23rd, 2025]
- Children among at least 6 killed in Russian drone and missile attacks on Ukraine, officials say - CBC - October 23rd, 2025 [October 23rd, 2025]
- Reality catches up with Trumps Ukraine peace drive and threatens his Mideast push - CNN - October 23rd, 2025 [October 23rd, 2025]
- Trump says he doesn't think Ukraine will win war - NBC News - October 21st, 2025 [October 21st, 2025]
- Trump Says Efforts To Reach Peace Deal Ongoing As Ukraine, EU Make Their Own Diplomatic Moves - Radio Free Europe/Radio Liberty - October 21st, 2025 [October 21st, 2025]
- How European leaders are responding as Trump urges Ukraine to cede territory to Russia - PBS - October 21st, 2025 [October 21st, 2025]
- Trump calls for Ukraine war to halt with Russia in control of occupied territory: "Leave it the way it is" - CBS News - October 21st, 2025 [October 21st, 2025]
- How Trump can apply his Middle East success to ending Russias war in Ukraine - Atlantic Council - October 21st, 2025 [October 21st, 2025]
- EU pushes back on Trumps demand Ukraine cede territory to Putin - politico.eu - October 21st, 2025 [October 21st, 2025]