In Ukraine, a Malware Expert Who Could Blow the Whistle on Russian Hacking – New York Times
There is no evidence that Profexer worked, at least knowingly, for Russias intelligence services, but his malware apparently did.
That a hacking operation that Washington is convinced was orchestrated by Moscow would obtain malware from a source in Ukraine perhaps the Kremlins most bitter enemy sheds considerable light on the Russian security services modus operandi in what Western intelligence agencies say is their clandestine cyberwar against the United States and Europe.
It does not suggest a compact team of government employees who write all their own code and carry out attacks during office hours in Moscow or St. Petersburg, but rather a far looser enterprise that draws on talent and hacking tools wherever they can be found.
Also emerging from Ukraine is a sharper picture of what the United States believes is a Russian government hacking group known as Advanced Persistent Threat 28 or Fancy Bear. It is this group, which American intelligence agencies believe is operated by Russian military intelligence, that has been blamed, along with a second Russian outfit known as Cozy Bear, for the D.N.C. intrusion.
Rather than training, arming and deploying hackers to carry out a specific mission like just another military unit, Fancy Bear and its twin Cozy Bear have operated more as centers for organization and financing; much of the hard work like coding is outsourced to private and often crime-tainted vendors.
In more than a decade of tracking suspected Russian-directed cyberattacks against a host of targets in the West and in former Soviet territories NATO, electrical grids, research groups, journalists critical of Russia and political parties, to name a few security services around the world have identified only a handful of people who are directly involved in either carrying out such attacks or providing the cyberweapons that were used.
This absence of reliable witnesses has left ample room for President Trump and others to raise doubts about whether Russia really was involved in the D.N.C. hack.
There is not now and never has been a single piece of technical evidence produced that connects the malware used in the D.N.C. attack to the G.R.U., F.S.B. or any agency of the Russian government, said Jeffrey Carr, the author of a book on cyberwarfare. The G.R.U. is Russias military intelligence agency, and the F.S.B. its federal security service.
United States intelligence agencies, however, have been unequivocal in pointing a finger at Russia.
Seeking a path out of this fog, cybersecurity researchers and Western law enforcement officers have turned to Ukraine, a country that Russia has used for years as a laboratory for a range of politicized operations that later cropped up elsewhere, including electoral hacking in the United States.
In several instances, certain types of computer intrusions, like the use of malware to knock out crucial infrastructure or to pilfer email messages later released to tilt public opinion, occurred in Ukraine first. Only later were the same techniques used in Western Europe and the United States.
So, not surprisingly, those studying cyberwar in Ukraine are now turning up clues in the investigation of the D.N.C. hack, including the discovery of a rare witness.
Security experts were initially left scratching their heads when the Department of Homeland Security on Dec. 29 released technical evidence of Russian hacking that seemed to point not to Russia, but rather to Ukraine.
In this initial report, the department released only one sample of malware said to be an indicator of Russian state-sponsored hacking, though outside experts said a variety of malicious programs were used in Russian electoral hacking.
The sample pointed to a malware program, called the P.A.S. web shell, a hacking tool advertised on Russian-language Dark Web forums and used by cybercriminals throughout the former Soviet Union. The author, Profexer, is a well-regarded technical expert among hackers, spoken about with awe and respect in Kiev.
He had made it available to download, free, from a website that asked only for donations, ranging from $3 to $250. The real money was made by selling customized versions and by guiding his hacker clients in its effective use. It remains unclear how extensively he interacted with the Russian hacking team.
After the Department of Homeland Security identified his creation, he quickly shut down his website and posted on a closed forum for hackers, called Exploit, that Im not interested in excessive attention to me personally.
Soon, a hint of panic appeared, and he posted a note saying that, six days on, he was still alive.
Another hacker, with the nickname Zloi Santa, or Bad Santa, suggested the Americans would certainly find him, and place him under arrest, perhaps during a layover at an airport.
It could be, or it could not be, it depends only on politics, Profexer responded. If U.S. law enforcement wants to take me down, they will not wait for me in some countrys airport. Relations between our countries are so tight I would be arrested in my kitchen, at the first request.
In fact, Serhiy Demediuk, chief of the Ukrainian Cyber Police, said in an interview that Profexer went to the authorities himself. As the cooperation began, Profexer went dark on hacker forums. He last posted online on Jan. 9. Mr. Demediuk said he had made the witness available to the F.B.I., which has posted a full-time cybersecurity expert in Kiev as one of four bureau agents stationed at the United States Embassy there. The F.B.I. declined to comment.
Profexer was not arrested because his activities fell in a legal gray zone, as an author but not a user of malware, the Ukrainian police say. But he did know the users, at least by their online handles. He told us he didnt create it to be used in the way it was, Mr. Demediuk said.
A member of Ukraines Parliament with close ties to the security services, Anton Gerashchenko, said that the interaction was online or by phone and that the Ukrainian programmer had been paid to write customized malware without knowing its purpose, only later learning it was used in the D.N.C. hack.
Mr. Gerashchenko described the author only in broad strokes, to protect his safety, as a young man from a provincial Ukrainian city. He confirmed that the author turned himself in to the police and was cooperating as a witness in the D.N.C. investigation. He was a freelancer and now he is a valuable witness, Mr. Gerashchenko said.
While it is not known what Profexer has told Ukrainian investigators and the F.B.I. about Russias hacking efforts, evidence emanating from Ukraine has again provided some of the clearest pictures yet about Fancy Bear, or Advanced Persistent Threat 28, which is run by the G.R.U.
Fancy Bear has been identified mostly by what it does, not by who does it. One of its recurring features has been the theft of emails and its close collaboration with the Russian state news media.
Tracking the bear to its lair, however, has so far proved impossible, not least because many experts believe that no such single place exists.
Even for a sophisticated tech company like Microsoft, singling out individuals in the digital miasma has proved just about impossible. To curtail the damage to clients operating systems, the company filed a complaint against Fancy Bear last year with the United States District Court for the Eastern District of Virginia but found itself boxing with shadows.
As Microsoft lawyers reported to the court, because defendants used fake contact information, anonymous Bitcoin and prepaid credit cards and false identities, and sophisticated technical means to conceal their identities, when setting up and using the relevant internet domains, defendants true identities remain unknown.
Nevertheless, Ukrainian officials, though wary of upsetting the Trump administration, have been quietly cooperating with American investigators to try to figure out who stands behind all the disguises.
Included in this sharing of information were copies of the server hard drives of Ukraines Central Election Commission, which were targeted during a presidential election in May 2014. That the F.B.I. had obtained evidence of this earlier, Russian-linked electoral hack has not been previously reported.
Traces of the same malicious code, this time a program called Sofacy, were seen in the 2014 attack in Ukraine and later in the D.N.C. intrusion in the United States.
Intriguingly, in the cyberattack during the Ukrainian election, what appears to have been a bungle by Channel 1, a Russian state television station, inadvertently implicated the government authorities in Moscow.
Hackers had loaded onto a Ukrainian election commission server a graphic mimicking the page for displaying results. This phony page showed a shocker of an outcome: an election win for a fiercely anti-Russian, ultraright candidate, Dmytro Yarosh. Mr. Yarosh in reality received less than 1 percent of the vote.
The false result would have played into a Russian propaganda narrative that Ukraine today is ruled by hard-right, even fascist, figures.
The fake image was programmed to display when polls closed, at 8 p.m., but a Ukrainian cybersecurity company, InfoSafe, discovered it just minutes earlier and unplugged the server.
State television in Russia nevertheless reported that Mr. Yarosh had won and broadcast the fake graphic, citing the election commissions website, even though the image had never appeared there. The hacker had clearly provided Channel 1 with the same image in advance, but the reporters had failed to check that the hack actually worked.
For me, this is an obvious link between the hackers and Russian officials, said Victor Zhora, director of InfoSafe, the cybersecurity company that first found the fake graphic.
A Ukrainian government researcher who studied the hack, Nikolai Koval, published his findings in a 2015 book, Cyberwar in Perspective, and identified the Sofacy malware on the server.
The mirror of the hard drive went to the F.B.I., which had this forensic sample when the cybersecurity company CrowdStrike identified the same malware two years later, on the D.N.C. servers.
It was the first strike, Mr. Zhora said of the earlier hack of Ukraines electoral computers. Ukraines Cyber Police have also provided the F.B.I. with copies of server hard drives showing the possible origins of some phishing emails targeting the Democratic Party during the election.
In 2016, two years after the election hack in Ukraine, hackers using some of the same techniques plundered the email system of the World Anti-Doping Agency, or WADA, which had accused Russian athletes of systematic drug use.
That raid, too, seems to have been closely coordinated with Russian state television, which began airing well-prepared reports about WADAs hacked emails just minutes after they were made public. The emails appeared on a website that announced that WADA had been hacked by a group calling itself the Fancy Bears Hack Team.
It was the first time Fancy Bear had broken cover.
Fancy Bear remains extraordinarily elusive, however. To throw investigators off its scent, the group has undergone various makeovers, restocking its arsenal of malware and sometimes hiding under different guises. One of its alter egos, cyberexperts believe, is Cyber Berkut, an outfit supposedly set up in Ukraine by supporters of the countrys pro-Russian president, Viktor F. Yanukovych, who was ousted in 2014.
After lying dormant for many months, Cyber Berkut jumped back into action this summer just as multiple investigations in Washington into whether the Trump campaign colluded with Moscow shifted into high gear. Cyber Berkut released stolen emails that it and Russian state news media said had exposed the real story: Hillary Clinton had colluded with Ukraine.
Continued here:
In Ukraine, a Malware Expert Who Could Blow the Whistle on Russian Hacking - New York Times
- Heres what Putin really wants from Trump and its not peace in Ukraine - CNN - August 14th, 2025 [August 14th, 2025]
- Why Putin Thinks Russia Has the Upper Hand Against Ukraine - The New York Times - August 14th, 2025 [August 14th, 2025]
- How a Call From Trump Ignited a Frantic Week of Diplomacy by Ukraine - The New York Times - August 14th, 2025 [August 14th, 2025]
- Putin to offer financial incentives to Trump at Ukraine summit - The Guardian - August 14th, 2025 [August 14th, 2025]
- Trump offers Putin 'narrow window' to end Ukraine war and more top headlines - Fox News - August 14th, 2025 [August 14th, 2025]
- Europe and Ukraine to hold Trump call ahead of Putin-Alaska meet - NBC News - August 14th, 2025 [August 14th, 2025]
- EU leaders sound upbeat after Ukraine call with Trump. They could be in for a rude awakening. - politico.eu - August 14th, 2025 [August 14th, 2025]
- Ceding land to Russia not only unpopular in Ukraine, but also illegal - PBS - August 14th, 2025 [August 14th, 2025]
- Ukraine live: Zelensky to meet Starmer ahead of Trump-Putin summit - The Independent - August 14th, 2025 [August 14th, 2025]
- Ukraine-Russia war live: Putin praises Trumps energetic and sincere peace efforts - The Telegraph - August 14th, 2025 [August 14th, 2025]
- Trump Agrees on Ukraine Red Lines With Europe Before Putin Summit - WSJ - The Wall Street Journal - August 14th, 2025 [August 14th, 2025]
- Report: US, Russia considering West Bank-style future for Ukraine occupation - The Times of Israel - August 14th, 2025 [August 14th, 2025]
- Zelenskiy says Ukraine has secured $1.5 billion from European allies for US weapons - Reuters - August 14th, 2025 [August 14th, 2025]
- Why Ukraine's ex-foreign minister believes Putin won't go for peace as Trump summit approaches - ABC News - August 14th, 2025 [August 14th, 2025]
- Ukraine Isnt the Model for Winning the Innovation War - War on the Rocks - August 14th, 2025 [August 14th, 2025]
- The enormity of the attacks on Ukraine is impossible to grasp. Let me show you the horror of a single day - The Guardian - August 14th, 2025 [August 14th, 2025]
- Russia has won war in Ukraine, Hungary's Orban says - Reuters - August 14th, 2025 [August 14th, 2025]
- Germany and allies to send major military aid package to Ukraine using new NATO supply line - AP News - August 14th, 2025 [August 14th, 2025]
- Looking back on key moments of the war in Ukraine - NBC News - August 14th, 2025 [August 14th, 2025]
- Trump's nod to Europe on a future peace force for Ukraine vastly improves its chances of success - AP News - August 14th, 2025 [August 14th, 2025]
- Ukraine Hits Another Key Russia Refinery in Flurry of Attacks - Bloomberg.com - August 14th, 2025 [August 14th, 2025]
- Trump agreed only Ukraine can negotiate territorial concessions, Macron says - politico.eu - August 14th, 2025 [August 14th, 2025]
- Panic in eastern Ukraine as Trump entertains idea of giving parts of it to Russia - CNN - August 12th, 2025 [August 12th, 2025]
- EU leaders say Ukraine should have freedom to decide its future ahead of Trump-Putin summit - The Guardian - August 12th, 2025 [August 12th, 2025]
- Trump says he will try to get back territory for Ukraine in talks with Putin - BBC - August 12th, 2025 [August 12th, 2025]
- Ukraine war latest: All EU nations bar one issue new statement ahead of Putin-Trump summit - Sky News - August 12th, 2025 [August 12th, 2025]
- Sidelined from Trump-Putin talks, Ukraine warns the world not to trust Russia - CNBC - August 12th, 2025 [August 12th, 2025]
- Ahead of Putin sitdown, Trump says he hopes to get 'prime territory' back for Ukraine - NBC News - August 12th, 2025 [August 12th, 2025]
- Trump says he will 'feel out' Putin in Alaska on ending the war in Ukraine - NPR - August 12th, 2025 [August 12th, 2025]
- Trump suggests hell know if Putin wants a peace deal with Ukraine soon into their meeting - AP News - August 12th, 2025 [August 12th, 2025]
- Europe to Trump: Stand up for Ukraine when you talk to Putin - politico.eu - August 12th, 2025 [August 12th, 2025]
- Trump says Ukraine, Russia will have to swap some land for peace - Reuters - August 12th, 2025 [August 12th, 2025]
- Trump says he'll know if Putin wants peace deal with Ukraine soon into their Alaska meeting - CBS News - August 12th, 2025 [August 12th, 2025]
- Ukraine war briefing: US ambassador to Nato says Zelenskyy could attend Alaska summit but decision is Trumps - The Guardian - August 12th, 2025 [August 12th, 2025]
- EU holds talks amid fear that Trump-Putin meeting will sideline Ukraine - Al Jazeera - August 12th, 2025 [August 12th, 2025]
- Ukraine invaded Russia, seizing land it hoped to trade. It couldnt hold on. - The Washington Post - August 12th, 2025 [August 12th, 2025]
- Why Europe is so worried about Ukraine being excluded from Trump-Putin talks - NBC News - August 12th, 2025 [August 12th, 2025]
- European leaders to meet virtually on Ukraine before call with Trump - Reuters - August 12th, 2025 [August 12th, 2025]
- Europe live: EU says Ukraine should be able to choose its own destiny ahead of Trump-Putin meeting - The Guardian - August 12th, 2025 [August 12th, 2025]
- European leaders urge for Ukraine to be included in Trump-Putin Alaska peace talks - NPR - August 12th, 2025 [August 12th, 2025]
- Ukraine makes small territorial gains in Sumy ahead of Trump-Putin summit - Reuters - August 12th, 2025 [August 12th, 2025]
- Trump pushes Ukraine to agree to 'land swap' with Russia ahead of Putin summit - USA Today - August 12th, 2025 [August 12th, 2025]
- Trump says he and Putin will discuss land swapping at Ukraine war summit - The Guardian - August 12th, 2025 [August 12th, 2025]
- For Ukraine, 'Losing Slowly' Might Be a Winning Strategy - Reason Magazine - August 12th, 2025 [August 12th, 2025]
- The brutal logic of the Ukraine war threatens to crush Trumps dreams of peace - The Telegraph - August 12th, 2025 [August 12th, 2025]
- In negotiations between Russia and Ukraine, Crimeas status is a red line that neither side will cross - The World from PRX - August 12th, 2025 [August 12th, 2025]
- Europe Casts Doubt on Trump-Putin Summit Without Ukraine - Time Magazine - August 12th, 2025 [August 12th, 2025]
- Trump and Putin to meet this week in bid to end Russia-Ukraine war - LiveNOW from FOX - August 12th, 2025 [August 12th, 2025]
- European leaders rally behind Ukraine ahead of Trump-Putin meeting - AP News - August 12th, 2025 [August 12th, 2025]
- Trump calls Putin summit a "feel out meeting," says Russia and Ukraine will need to swap territory - CBS News - August 12th, 2025 [August 12th, 2025]
- Trump says he hopes to get 'prime territory' back for Ukraine as he prepares for Putin summit - Sky News - August 12th, 2025 [August 12th, 2025]
- Summit with Putin set to top Trump's agenda this week as Ukraine war takes center stage - Fox News - August 12th, 2025 [August 12th, 2025]
- In a Trump-Putin Summit, Ukraine Fears Losing Say Over Its Future - The New York Times - August 12th, 2025 [August 12th, 2025]
- Vance says Ukraine peace deal unlikely to satisfy either side - Reuters - August 12th, 2025 [August 12th, 2025]
- Trump, Putin and the future of Ukraine - Financial Times - August 12th, 2025 [August 12th, 2025]
- Dmitri Kozak Was a Key Putin Aide. He Lost Power When He Balked at the Ukraine War. - The New York Times - August 12th, 2025 [August 12th, 2025]
- Trump says he will meet Putin next Friday in Alaska to discuss ending the Ukraine war - AP News - August 12th, 2025 [August 12th, 2025]
- On the front lines in eastern Ukraine, peace feels far away - AP News - August 12th, 2025 [August 12th, 2025]
- Trump says hell tell Putin to end Ukraine invasion, vows Zelensky will be in next meeting - New York Post - August 12th, 2025 [August 12th, 2025]
- Kallas says any deal between US and Russia must include Ukraine and EU - Reuters - August 12th, 2025 [August 12th, 2025]
- Ukraine prepared to cede territory held by Russia ahead of Trump-Putin meeting - The Telegraph - August 12th, 2025 [August 12th, 2025]
- The Russian Technocrat Who Helps Enable Putin and Manage the Ukraine War - The New York Times - August 12th, 2025 [August 12th, 2025]
- UK and Canada say peace must not be imposed on Ukraine - Reuters - August 12th, 2025 [August 12th, 2025]
- Zelenskyy says Trump-Putin summit will achieve nothing, vows Ukraine will not give up land - CBS News - August 9th, 2025 [August 9th, 2025]
- Europe and Ukraine press US ahead of Trump-Putin talks - Reuters - August 9th, 2025 [August 9th, 2025]
- Ukraine war briefing: European leaders stress protection of Ukrainian interests ahead of Trump-Putin talks - The Guardian - August 9th, 2025 [August 9th, 2025]
- Zelensky rejects Trumps suggestion that Ukraine cede territory to Russia - The Washington Post - August 9th, 2025 [August 9th, 2025]
- Zelenskyy rejects Trump's proposal that Ukraine could swap territories with Russia - NBC News - August 9th, 2025 [August 9th, 2025]
- Before Trump-Putin talks, Ukraine rules out gifting land to occupier - Al Jazeera - August 9th, 2025 [August 9th, 2025]
- With summit looming, Ukraine's Zelenskyy says he won't give land to Russia - NPR - August 9th, 2025 [August 9th, 2025]
- Live updates: Zelensky says Ukraine will not give up land, ahead of Trump-Putin summit in Alaska - CNN - August 9th, 2025 [August 9th, 2025]
- Trump and Putin to meet in Alaska for Ukraine talks next week - BBC - August 9th, 2025 [August 9th, 2025]
- WATCH: Trump suggests swapping Ukraine and Russia territories ahead of meeting with Putin - PBS - August 9th, 2025 [August 9th, 2025]
- Europe rallies behind Ukraine after defiant Zelensky rejects any peace plan that gives up land to Russia - The Independent - August 9th, 2025 [August 9th, 2025]
- Lammy and Vance hold meeting to discuss US-brokered Ukraine peace plan - The Guardian - August 9th, 2025 [August 9th, 2025]
- Zelenskiy Says Ukraine Wont Give Up Land to Russia for Peace - Bloomberg.com - August 9th, 2025 [August 9th, 2025]
- Russian Strikes Kill 3 in Ukraine, Which May Be Left Out of Peace Talks - The New York Times - August 9th, 2025 [August 9th, 2025]
- Trump, casting himself as peacemaker-in-chief, faces tests in Gaza and Ukraine - Los Angeles Times - August 9th, 2025 [August 9th, 2025]
- Trump says Ukraine will have to give up territory for a ceasefire, Zelenskyy says no - CBS News - August 9th, 2025 [August 9th, 2025]
- Trump will meet with Putin in Alaska for talks on ending Russias war in Ukraine - PBS - August 9th, 2025 [August 9th, 2025]