Stringwall 🇺🇸🇺🇸 Profile picture
Less noise. More clarity.

Sep 30, 2021, 146 tweets

September 2020

The Trump-Alfa Bank Server Mystery Resurfaces

justsecurity.org/72262/the-trum…

The recent release of the final volume of the Senate Intelligence Committee report on Russian 2016 election interference and two new lawsuits by Russia’s Alfa Bank have brought back into the spotlight the puzzling lack of an explanation…

…for the mysterious communications between the bank and the Trump Organization during the last presidential campaign.

It has been almost four years since a group of computer scientists disclosed, on the basis of DNS (Domain Name System) logs, that two internet servers belonging to Alfa Bank had looked up the address of the Trump Organization server 2,820 times between May and September 2016.

Yet the long-awaited Senate report provides only this paltry, ambiguous conclusion:

“Based on the FBI’s assessment, the Committee did not find the DNS activity reflected the existence of covert communication between Alfa Bank and Trump Organization personnel. However…

…the Committee also could not positively determine an intent or purpose that would explain the unusual activity.” ⬅️⬅️

*Side Note: I know what would explain the unusual activity. I also know why no one wants to look beneath these stones.

As stated on page 24 of the Senate report, the committee was not able to see the underlying records that the FBI used in its briefings to members.

So, although committee members have high-level security clearances, they appear to remain in the dark about the reasons for the server communications.

Was the committee told what kind of technical diligence the FBI carried out, or whether the FBI used the talent of cyber experts such as those at Carnegie Mellon University, the CIA and NSA?

Amazingly, the committee may have interviewed only one source–Jae Cho, the IT director for the Trump Organization…

…who “did not recall conducting a system-wide review of the Trump Organization network to determine if there were any connections from the Trump Organization side with any of the Alfa Bank servers.” ⬅️⬅️

*Side Note: Of course he didn’t. 🙄🙄

According to the report, Cho “inferred” that Alfa Bank’s servers were configured in a way that they could not have been used to transmit emails to the Trump server. But it was not just a question of emails.

🎯🎯 Writing in the New Yorker in 2018, Dexter Filkins noted that computer scientists who examined the data theorized that the look-ups could have represented other forms of communication, such as data transfers or a technique called foldering (a digital form of “dead dropping”).

*Side Note: Gee, what data might they have been dead-dropping? Prepaid gift card/payment card account numbers from Heartland Payment Systems, Alfa Bank, and Amway perhaps?

Brad Parscale, the digital media director for Trump’s 2016 campaign, was even less helpful when questioned by the House Intelligence Committee in October 2017.

*Side Note: You can read that full interview here…

d3i6fh83elv35t.cloudfront.net/static/2020/05…

Claiming that he forgot the name of the bank involved, Parscale dismissed the server incident with a nonsensical  statement:

“Trump Org had done something on a server that for some service Cendyn was the provider of…And this other organization [Alfa Bank] also used the same company for something else and they just happened to have the same DNS entry, which is very common.”

🎯🎯➡️➡️ The DNS queries were from dedicated IP addresses owned by Alfa Bank, not by a hosting company sharing IP addresses. It has never been suggested that Alfa Bank and the Trump Organization shared domain names.

The FBI has been obfuscating about the Trump/Alfa server links ever since a lawyer for the Democratic National Committee (DNC), Michael Sussmann, told FBI General Counsel James Baker in mid-September 2016 about the findings of the computer scientists who had examined the data…

…and intelligence officials reportedly began briefing Congress about the mysterious connections around the same time.

According to Filkins, later that month the agency persuaded the New York Times’ Eric Lichtblau to back off a story the paper planned to publish on the case because it would jeopardize the agency’s ongoing investigation.

But an FBI official subsequently told Lichtblau “that there could be an innocuous explanation for the computer traffic.” 🤔🤔

So when his story finally appeared on Oct. 31, the message was that Trump and Alfa Bank had been exonerated, and the server mystery disappeared from the public’s radar.

Contrary to what many expected, the Mueller Report did not even mention the server allegations, and when asked about the case during his July 2019 testimony to the House Intelligence Committee, Mueller was foggy in his response:

“Do not know whether it’s true…It may well have been investigated, although it’s my belief at this point, it’s not true.”

*So was it or was it not investigated? And what exactly does Mueller believe not to be true; that the servers were communicating or that data was being exchanged for nefarious purposes?
You can read the full exchange here:

nbcnews.com/politics/congr…

Given the enormous implications of the allegations, Mueller surely could have said more to put the story to rest.

Was he constrained in his investigation or what he could say by Attorney General William Barr or Deputy Attorney General Rod Rosenstein, or had his team for other reasons decided not to reach, whether privately or publicly, a more decisive conclusion?

The only other information on the case from the Department of Justice appeared in the December 2019 Inspector General’s report about the origins of the Russia investigation.

A footnote on page 119 reads: “The FBI investigated whether there were cyber links between the Trump Organization and Alfa Bank, but concluded by early February 2017 that there were no such links.”

*Side Note: You can read that IG report here…

justice.gov/storage/120919…

*Also Side Note: We’re getting to the part where Alfa Bank goes to court to argue that the data links do in fact exist, but that they were engineered without their cooperation by malevolent third party actors.

Though terse, those words could have helped put the issue to rest. But, the FBI’s investigation apparently did not end in early February 2017. In March 2017, a source close to the investigation told CNN that the probe was ongoing and there was more work for the FBI to do.

And on April 1, 2017, a Kirkland & Ellis attorney representing Alfa Bank, Viet Dinh, met with the Justice Department and FBI in Chicago to discuss the server communications and “pledged full cooperation with government authorities,”…

…according to a letter Dinh sent to the Senate Judiciary Committee.

That said, Dinh described the meeting as Alfa Bank proactively reaching out to the government due to suspicious activity in 2017 involving unidentified third parties repeatedly querying the bank’s servers for an invalid host name related to Trump.

Dinh wrote that his meeting in April 2017 was part of the federal authorities “continu[ing] to examine whether Alfa Bank has been the victim of illegal conduct.”

*Side Note: Yeah sorry, but this “we’re the victim” act is comical.

So what has actually happened with the FBI investigation?

According to one source with high-level national security connections, the FBI could have decided not to pursue a criminal probe…

…(including, one might think, into allegations raised by Dinh) because of concerns about compromising “sources and methods” involving the sophisticated techniques of DNS analysis:

“protection of sources and methods is always paramount, even when it means justice loses out.”

A recent example is the DOJ’s decision last March to drop charges against Concord Management in the Internet Research Agency case…

…allegedly because of concerns that U.S.national security would be compromised by the government’s revelation of that kind of information during the trial process.

Retired senior CIA officer John Sipher has also written persuasively about these tradeoffs in Just Security. Another possibility, my source suggested, is that the probe is part of a much broader counterintelligence investigation that is ongoing.

But it could also be, as Congressman Adam Schiff told the Washington Post last year, that there are disagreements between intelligence professionals on the one hand and Attorney General Barr and the White House on the other…

…about what exactly can be shared with Congress in the general domain of topics involving Trump-Russia.

🎯🎯🎯 Schiff observed: “I think the FBI is willing to be more forthcoming. I think the FBI and intelligence community are mindful of their statutory obligations, and they’re caught between a rock and a hard place with the combative posture that Bill Barr has taken.”

Whatever the reasons for the inconclusive and odd accounts emanating from the DOJ and the FBI, Alfa Bank may now be capitalizing on the confusion.

On June 11, the bank filed lawsuits in Palm Beach County, Florida and  Lancaster, Pennsylvania, where the companies that owned and administered the Trump server are located.

The two similar complaints allege a criminal conspiracy by unidentified defendants (John Doe), who ostensibly forged emails by manipulating DNS data to make it appear that the bank was communicating with the Trump Organization.

🔥🔥🔥➡️➡️ Oddly, Alfa Bank’s new theory of the case is inconsistent with the company’s own prior statements.

Dinh wrote in 2017 that the company hired Mandiant and that “Mandiant’s hypothesis was that any server-related activity between Alfa Bank and the Trump Organization was the result of an automated email-based campaign to market Trump properties to Alfa Bank employees.”

*Side Note: Except, the Trump server wasn’t actually configured to act as a marketing mail server. And it wasn’t flagged in any spam filter logs, as you would expect to see in a real server that was actually being used to send out bulk marketing mail. So this explanation is 🐂💩.

So which is it? That innocuous account that Alfa Bank put forth earlier or the new nefarious one? 🤔🤔

Demanding jury trials in the two swing states, Alfa Bank’s lawyers from Skadden Arps have issued aggressive subpoenas in the Florida case to computer scientists and DNS records custodians…

…as well as to Glenn Simpson, Peter Fritch and their firm Fusion GPS, which commissioned the Steele dossier, and former DNC lawyer Sussmann.

It is noteworthy that Skadden formerly employed Alex van der Zwaan, who was convicted in 2018 of lying to Mueller’s prosecutors about his communications with Paul Manafort, Rick Gates & Russian military intelligence (GRU) spy Konstantin Kilimnik during the 2016 election campaign.

*Side Note: You remember Alex and Konstantin having their special conversations over encrypted apps…in Russian. 😘😘

Van der Zwaan’s father-in-law is one of Alfa Bank’s co-owners, German Khan, and the law firm has represented Alfa Bank in numerous litigations over the years.

*Side Note: Golly it’s a small world, because Paul Manafort’s daughter also worked at Skadden Arps between 2012 and October 2016. 🤔🤔

🔥🔥 Alfa Bank’s complaint makes the erroneous claim that in October 2016 the FBI was granted a FISA warrant to wiretap the Trump server, citing two sources:

Louise Mensch, a known purveyor of conspiracy theories, and the December IG report, which discusses only warrants granted in relation to Carter Page.

As evidence for its conspiracy allegations, the complaint cites an April 2020 study by the cybersecurity firm Ankura. According to the 41-page analysis, a “likely scenario” is that third parties artificially created the activity to make it appear as though a connection existed.

But computer scientist L. Jean Camp, one of those who first studied the server data, gave me her assessment of the analysis just after it was posted on the Internet by the conservative website Just the News: “It confuses the issue by adding remote possibilities.” 🎯🎯🎯

*Side Note: Maybe it was aliens? 🤷‍♂️

One question is why the FBI did not discover this criminal conspiracy during its investigation of the server allegations – or at least we have no public indication of such a discovery, and it does not appear in the Senate report either.

When I asked Jeffrey Birnbaum, whose public relations firm, BGR, represents Alfa Bank, if the bank took its new evidence from the Ankura study to the FBI for criminal prosecution…

…he responded in an email that Alfa Bank could not comment on any ongoing discussion with U.S. law enforcement.

🔥🔥🔥➡️➡️ Significantly, the Ankura study was commissioned for the bank by Kirkland & Ellis, where Barr and the recently retired Assistant Attorney General Brian Benczkowski had been partners before they took up their respective positions at Trump’s Department of Justice.

*Side Note: Maybe now is a good time to remind you that the growth of Kirkland and Ellis was fueled by private equity…

…which the FBI says is a vehicle for criminal money laundering. 🤔🤔

(White House Counsel Pat Cippolone is another Kirkland & Ellis alumnus.)

While still at Kirkland & Ellis in 2017, Benczkowski represented Alfa Bank in its efforts to clear its name from allegations of collusion with the Trump campaign.

He commissioned a computer forensics study by Stroz Friedberg that identified suspicious queries to Alfa Bank servers in 2017, a finding that suggested something similar could have occurred in 2016.

Benczkowski also advised Alfa Bank in its lawsuit against BuzzFeed for publishing the Steele dossier, which alleged that two of Alfa Bank’s owners, Mikhail Fridman and Petr Aven, were conduits of information to Putin about the U.S. election.

*Side Note: Aven told Mueller that he meets with Putin on a quarterly basis, at which time he receives “implicit directives”.

*Side Note: Let us also please recall that the Kremlin is able to persuade dependent oligarchs to assist with foreign policy undertakings.

(Fridman, Aven and Khan also initiated defamation lawsuits in the United States against Christopher Steele and Fusion GPS. In June, the D.C. Court of Appeals upheld the August 2018 dismissal of the Steele case by the D.C. Superior Court.)

While Benczkowski was still at the firm, Kirkland & Ellis began sending threatening letters to computer scientist Camp, who had posted the suspicious DNS logs on her website. Camp is among those who have recently been subpoenaed by Alfa Bank.

🔥🔥🔥 Benczkowski has said he thought it was appropriate to represent the litigious Russian bankers, who for years have been dogged by allegations of corruption, money-laundering and drug-trafficking.

*Side Note: Alfa Bank also sued the Center for Public Integrity for reporting on their criminal activity. You can read that suit here…

govinfo.gov/content/pkg/US…

During the July 2017 Senate Judiciary Committee hearing on his nomination to head the DOJ Criminal Division, Benczkowski said that he had been “comfortable accepting the representation” of Alfa Bank because…

…a November 2016 report on the server issued by the cybersecurity firm Mandiant “looked at the 2016 allegations and found them to be inaccurate, and there to be nothing to it.” But…

🎯🎯🎯 In fact, the Mandiant study–commissioned by Skadden–was only a draft, and did not provide a conclusive explanation for the server communications. ⬅️⬅️

*Side Note: Ok now pay attention! While this entire article has been informative & enlightening, this next part is the fundamental reason that I started this thread! Are you ready?? ⬇️⬇️

🔥🔥🔥 What’s more, as stated in the study, Mandiant based some of its findings on an earlier analysis done for Alfa Bank by the Russian cybersecurity firm Group-1B, which works closely with the KGB successor agency the FSB.

➡️➡️ The FSB gave Group-1B a special clearance to handle top secret documents, and its CEO, Ilya Sachkov, who was honored as an innovator by Putin in the Kremlin last year, lectures at the FSB Academy. 🔥🔥🔥

*Side Note: Did you catch that? ⬆️⬆️ 1. Mandiant never actually got access to any of Alfa Bank’s DNS data. They based their report on the findings from the FSB-linked firm, Group-1B. And this FSB spin is what Benczkowski used as justification for his work for Alfa Bank. 🔥🔥

*Side Note: 2. Do you recognize those names, “Group-1B” and “Ilya Sachkov”? You should, because they were in the news again yesterday, when the FSB raided the Group-1B offices and arrested Sachkov on treason charges! 🔥🔥🔥

bbc.com/news/world-eur…

*Side Note: I don’t know what this looks like to you, but to me, it looks like Putin is tying up loose ends and burying evidence.

Benczkowski’s work for Alfa Bank was a key reason for the opposition to his nomination by Democrats on the Senate Judiciary Committee.

In a May 9, 2018 letter to President Trump, they expressed concerns that his refusal to recuse himself from Russia-related matters would adversely affect investigations involving Russia.

*Side Note: You can read that letter here…

durbin.senate.gov/newsroom/press…

Indeed, on Aug. 21, 2018, just five weeks after Benczkowski took up his DOJ job, he received an ethics waiver authorizing him to participate in a legal matter involving a “former client.”

After repeated requests from Senate Democrats, the Justice Department provided the senators with only heavily redacted information about Benczkowski’s authorization.

On Dec. 16, 2019, Benczkowski received a waiver to take part in a “confidential criminal matter involving his former employer” (presumably Kirkland & Ellis).

This prompted the watchdog agency American Oversight, citing Benczkowski’s past work for Alfa Bank, to make a Freedom of Information request to the Justice Department’s Criminal Division for records relating to the waiver. There has been no response.

American Oversight Executive Director Austin Evers told me in an email: “In the Trump administration, officials have been given waivers to work on matters involving their former clients so long as they toe the administration’s line…

Benczkowski may be abandoning ship [in leaving the DOJ], but the public needs to understand the full scope of his loyal conduct and should not allow him to escape accountability.”

*Side Note: Remember when Congressman Adam Schiff suggested that Billy Barr was sabotaging the investigations?

*Side Note: This isn’t really speculation, because we’ve seen him bring in specific individuals to sabotage other investigations. Like when he appointed Timothy Shea (formerly with the 2016 Russian Law Firm of the Year, Morgan Lewis & Bockius) to sabotage the Stone & Flynn cases.

*Side Note: So is there any reason not to expect that Benczkowski used his secret waiver to scuttle the server investigation?

In its complaint Alfa Bank says that the lawsuits are intended to clear its name of the false charges that it communicated secretly with the Trump campaign in 2016 and restore “its global reputation as the leading private bank in Russia.”

But the server scandal has long since disappeared from the media, so why open up this can of worms? And why expose the bank to risks of revealing its own internal information in the discovery process, that is, if the cases were to proceed to the point where defendants are named?

Whether intentional or not, Alfa Bank’s lawsuits may soon be used by others to try to cast a shadow over the 2020 election by stirring up bogus conspiracies and discrediting the probes that proved Russia’s interference in the2016 U.S. elections on Trump’s behalf.

*Side Note: Remember that this article was published on Sept 02, 2020, two months before the election and four months before the violent insurrection on Jan 6. I’d say that’s prescient.

Alfa Bank spokesman Birnbaum told me that the alleged criminal conspiracy of the bank’s connections to Trump “was not just an attack on Alfa Bank, one of the few remaining privately owned banks in Russia, but on the integrity of the U.S. political process.”

*Side Note: Oh please with the 🐂💩 already.

This is likely music to the ears of Barr. Ever since he assumed his post in February 2019, Barr has worked feverishly to discredit, even criminalize, the FBI’s investigation into Russia’s election interference and potential ties to Trump campaign associates.

The upcoming report on the Russia investigation by Barr’s own appointed prosecutor, John Durham, could include references to the new Alfa Bank lawsuits and its allegations.

*Side Note: Golly, it’s like @just_security could see the future!

For its own purposes, the bank may have been better off leaving well enough alone with the impressions created by the Inspector General’s report that the FBI had wrapped up its investigation and found nothing.

But the lawsuits can also be used by the Kremlin to help counter the claims by top U.S. intelligence officials that Russia has returned for a repeat performance in the 2020 campaign.

🎯🎯➡️➡️ And by issuing subpoenas for the records of the computer scientists and research firms, Alfa Bank might gain information that can be used by Russia’s intelligence services for their cyber assaults against the West. 🔥🔥

*Side Note: Say it with me, “the Kremlin appears able to persuade dependent oligarchs to assist in its foreign policy undertakings.”

Putin seeks to stir political controversy in the United States, particularly when it comes to elections. And,Alfa Bank’s owners have an interest in remaining on Putin’s good side.

🔥🔥🔥 As Petr Aven told the Mueller team during an August 2018 interview, there would be “consequences” if he did not follow through with Putin’s directives.

*Side Note: For example, A Russian oligarch, nicknamed The Sausage King, has been murdered with a crossbow, investigators say.

bbc.com/news/world-eur…

🔥🔥🔥 And the Senate Intelligence Committee report highlights Aven’s participation in Putin’s group of oligarchs who take implicit and explicit “directives” from the Russian president.

Michigan-based Spectrum Health, whose board chairman in 2016 was Richard DeVos, husband of Trump’s education secretary, Betsy DeVos, is mentioned in the Ankura study as another possible victim of the conspiracy.

Spectrum Health looked up the Trump server 714 times during that same May-September 2016 time period. (Together Alfa Bank and Spectrum Health accounted for 99 percent of the DNS look-ups.)

🎯The DeVos family had more in common with Alfa Bank than a desire to get Trump elected, although its members contributed generously to Trump’s campaign. A direct marketing company co-owned by the family, Amway, had a large presence in Russia, with 2016 sales around $270 million.

Amway also had ties with Alfa Bank. In 2014, Amway partnered with Alfa Bank to establish a joint credit card. And a year later, Alfastrakhovanie, an insurance arm of the bank’s parent company, Alfa Group, became the insurer for hundreds of Amway employees in Russia.

*Side Note: This Alfa card wasn’t just a “credit” card, it was a prepaid payment card that could be loaded with a cash balance!

…which is EXACTLY what Andy Khawaja alleges is used in the scheme that he taught George Nader how to create in order to funnel Saudi money into the Trump campaign via small donations beneath the $200 reporting threshold! ⬇️⬇️

*Side Note: Since we’re on the topic, remember how the previously-broke Trump campaign was miraculously saved by a sudden rush of record-setting small donations between June-Sept of 2016?

…Well golly, that corresponds almost perfectly with the mysterious data transfers that all occurred between May-Sept 2016. Do you see it yet?

Along with Alfa Bank, Amway doubtless welcomed Trump’s suggestions during the 2016 campaign that he would lift economic sanctions imposed on Russia after the 2014 annexation of Ukraine’s Crimean Peninsula.

➡️➡️ In a 2015 interview with the Russian business daily Vedomosti, Amway CEO Doug DeVos (brother-in-law of Betsy DeVos) complained that economic sanctions against Russia were taking its toll on Amway’s business there.

🎯🎯 A possible explanation for the server communications is that they represented movement of data, which computer scientist Camp suggested to Filkins.

🎯🎯🎯➡️➡️ Separately, a computer researcher who called himself Tea Pain reported a pattern of database replication between servers—a process whereby different versions of the same database are kept “in sync” so that new information or changes make their way to others.

According to Tea Pain, Russia might have created a voter-targeting database, laundered through Alfa Bank, and Spectrum Health added value to the data through its extensive databases of email addresses and phone numbers:

“Once back in the hands of Russian Intelligence, this massaged data could be programmatically matched up with social media handles to create a micro-targeted ‘hit list’ for the thousand Russian trolls employed by Putin.”

*Side Note: It’s possible that these data transfers were voter data for psyop targeting. Certainly we know that this targeting occurred. However, there are a few problems this theory:

1. They didn’t need to establish a direct server connection to exchange voter data, because as @VickerySec discovered, the data was already openly exposed by a conservative data firm called Deep Root Analytics. The Russians could download it whenever.

m.dw.com/en/deep-root-a…

2. Aside from the Trump Org, all of the other 3 entities exchanging data were related to the prepaid gift card industry: Alfa Bank, Heartland Payment Systems, and Amway (which could have been communicating through Spectrum servers).

3. The timing of the data transfers matches up almost perfectly with the surge of small donations to the Trump campaign between June and September of 2016.

4. Andy Khawaja told us that this operation was happening.

Evidence to support the database replication hypothesis includes a strange ping (seen on DNS logs posted by Camp) to the Trump server on July 26, 2016, from an IP address (79.134.218.130) belonging to a Russian internet provider in St. Petersburg, called OBIT.

OBIT’s Russian website advertises that it has a large facility especially designed for data storage, and it includes among its many clients Concord Catering, which…

…along with its sister company Concord Management, sponsored the massive pro-Trump “information warfare” campaign carried out by the Internet Research Agency.

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling