Guy Jordan Profile picture

Sep 22, 2020, 23 tweets

@paulsperry_ The claim in the Mueller indictment was that the GRU hackers of "Fancy Bear" were so freaking stupid that they keylogged their own keystrokes to a server they leased inside the US, which the FBI seized. That is, supposedly, plus reports from Dutch Intelligence, their evidence.

@paulsperry_ Where I have trouble with the whole story is:

1. Why would Putin send GRU into the DNC network in March 2016 when Putin already had the SVR team, "Cozy Bear," inside the DNC network since JULY 2015? "Cozy Bear" had access to about everything on the network.

@paulsperry_ FBI told Yared Tamene, one of the DNC's security consultants, who found no evidence of any hackers on teh DNC network, that Cozy Bear transmitted data to Moscow in November 2015. DNC people couldn't find any hackers to remove, and the FBI refused to force entry into the..

@paulsperry_ ..DNC network, so the Russians were able to caper and prance around in there for an entire year unmolested. Comey was not alarmed at all that Russian spies were camping out in the network of a major political party.

@paulsperry_ 2. Comey's lack of concern is weird for two reasons:

A. In May 2014, John Brennan presented alleged intelligence to President Obama that Russia planned to interfere in the elections of other nations, including the US. Obama told Putin not to interfere in the UKRAINIAN...

@paulsperry_ ...election of 2014, but apparently was unconcerned that Russians were lounging around in the network of his own party. The 2014 report by Brennan made the presence of Russian spies in that network a NATIONAL SECURITY MATTER. No one in the Obama Administration did...

@paulsperry_ ...anything of substance to expel the "Cozy Bear" SVR hackers.

2. For years leading up to the 2015-2016 "Cozy Bear" hack of the DNC, Comey became controversial for his use of NATIONAL SECURITY LETTERS (NSL) rather than using search warrants that required a judge's signature.

@paulsperry_ Comey issued thousands of NSLs over his tenure. If someone's cat got stuck up a tree, it might warrant an NSL to drag the cat out of the tree, but, for some reason, Comey passed on doing that, or anything else, about "Cozy Bear."

@paulsperry_ So, you're Vladimir Putin, the real life "Dr. Evil," and you have a hacking group so skilled they are, in reality, USERS OF THE DNC NETWORK AND MOST OF ITS ASSETS. At least one of the Cozy Bear boys has some kind of Administrative Privileges.

No one in DC cares...

@paulsperry_ ...so what do you, Putin, do now?

You put the B team into the DNC network, GRU's bunch that gets caught most of the time they do anything like this.

Try to hack the Anti-Doping organization of the Olympics? They get caught. They also get photographed at the airport.

@paulsperry_ Try to hack the OPCW, the UN body investigating use of chemical weapons in Syria at their headquarters in The Hague?

They get caught in an automobile crammed with electronics by Dutch intelligence. They are photographed again.

@paulsperry_ Yes, after Putin has a hacking group on the DNC network for an entire year, with the run of the place, and no evidence anyone knows the hackers are in there, your first instinct is to send another hacking group in there that behaves this way, in the words of Donna Brazile:

@paulsperry_ "Fancy Bear (the GRU team) showed up in April 2016. Fancy Bear, the one our IT Department detected, was loud and did not seem concerned about being found out...Fancy Bear smashed in the front window and raged around grabbing whatever was at hand..." (Brazile, Donna:HACKS, Pg.138

@paulsperry_ The more is discovered about this story, the stupider it gets. On top of all of this, Fancy Bear didn't steal the emails as alleged until May 23 and May 25, after two months of letting everyone know their presence on the network. Crowdstrike was hired on May 5, 2016 to stop...

@paulsperry_ ...the alleged Russian hacks. The only way to do this was disconnect from the Internet under the guise of upgrading the system. Crowdstrike was not allowed to do this. As related by Donna Brazile in her book HACKS:

@paulsperry_ "In May, when Crowdstrike recommended that we take down our system and rebuild it, the DNC told them to wait a month, because the state primaries for the presidential election were still underway."

The emails were exfiltrated on May 23 and May 25, 2016. Now, I used to think...

@paulsperry_ ...Crowdstrike could see the emails being stolen, because that was what was reported at the time. Shawn Henry, in charge of the Incident Response for Crowdstrike told Congress in classified testimony that Crowdstrike could not see documents being exfiltrated. That month cost...

@paulsperry_ ...the DNC 44,000 stolen emails. No one is sure what all Cozy Bear stole while operating as users of the DNC network, but there was at least one transmission to Moscow in 2015, according to the FBI.

@paulsperry_ Dutch Intelligence operations Re-Fancy Bear

volkskrant.nl/wetenschap/dut…

@paulsperry_ CBS News in Re--Dutch Intelligence operations.

cbsnews.com/news/dutch-int…

@paulsperry_ Comey and National Security Letters Controversy:

lawfareblog.com/jim-comey-and-…

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling