THREAD: 1/ @wikileaks stated in its #Vault7 release that "the archive appears to have been circulated among former [USG] hackers and contractors". Lately I've been compiling a list of potential subjects including: Hal Martin, Michael Adams, "Carlo", and of course, Joshua Schulte.
2/ For all intents and purposes I believe that this Vault7 group at minimum has some overlap with the @shadowbrokerss (TSB) membership, given Wikileaks claimed to possess the NSA cyberweapons and that Adam Waldman was a US intermediary in both leaks.
3/ Furthermore, Assange was aware of people like Nghia Pho being under investigation for the TSB "theft", even though his role wasn't public until October 2017. Notice he was charged in 2015, but the "theft" was discovered in 2016. wsj.com/articles/russi…nytimes.com/2017/12/01/us/…
4/ Given, the presumed membership overlap, I started looking into Schulte's potential involvement with TSB. Apparently, his first "wikileaks" google was on 8/4/16, but of main interest and just days after the Hal Martin arrest, he started repeatedly searching "what is a mole"...
5/ Schulte also was a free man throughout the entire posting period of TSB and even used the internet against a court order after his September 2017 indictment. This doesn't mean that he was the TSB "mouthpiece", but one cannot rule it out. courtlistener.com/recap/gov.usco…
6/ The Twitter account @LexingtonAl was widely considered to be a member of TSB, and I have surmised the name could be pay homage to FMC Lexington inmate and ShadowCrew member, Albert Gonzalez. Review Lex's Twitter history please 👇
7/ I initially ignored the possibility that Schulte could be Lex, because of his incarceration, but during Lex's brief Twitter career Schulte did have access to ≥3 cellphones, 2 of which were apparently confiscated by October 5, 2018. storage.courtlistener.com/recap/gov.usco…
8/ Schulte was moved to a secure housing unit on October 2 to restrict his access to phones, but he was still able to post potentially using @buffer. What isn't clear is when he left the SHU. storage.courtlistener.com/recap/gov.usco…
9/ What is clear is that the day Schulte was indicted for the third time, Lex reappeared, wished us a Happy Halloween, and then changed his profile pic to CCI.
10/ CCI refers to Center for Cyber Intelligence, where Schulte was an Operational Support officer coding Brutal Kangaroo. Now, there is no smoking gun that Schulte was involved with TSB, but there is a lot of ammo lying around...
11/ My instinct is that Wikileaks's "former U.S. government hackers and contractors" are Hal, Michael, Joshua, and potentially Maksym Popov, and one or more of them are TSB. Review my previous threads if it pleases thee...
Easter Egg: Schulte's Samsung phone had 2048 on it while he was in jail. This is 1 of the 24 "Fine Dining" potential decoy apps, was Schulte hacking while in prison? 🤭
EE2: Schulte having to wait until midnight to tweet because he was in prison is funny to me.
Monthly DOS Foia dump from @15poundstogo! 689 documents. Doesn’t look all too exciting but may be worth a skim by those stuck inside during a heatwave. Let’s take a glance. foia.state.gov/Search/Results…
Uh oh looks like all of @igordanch's "sources" have denied, under oath, providing him any information related to the contents of the dossier. Enjoy your perjury charge Iggy 👀 courtlistener.com/docket/6163126…
How did the FBI not know that Danchenko was Steele's PSS until December 2016, if they were asking Vorontsov about him in June 2016.
1/ @emptywheel claims that multiple people told her that these two personas used the same IP address. I'll assess other evidence that TSB and G2 could be linked and and surmise who is in the group besides "Phil".
2/ Marcy's first mistake is in thinking that "Phil" (Michael L. Adams) left the Icelanderia/G2 comment on her site, when in reality Adams refers to that individual as "the mouthpiece". Here we can assume that Adams and "the mouthpiece" could be associates. emptywheel.net/2020/10/26/par…