Log in

Mueller report says Russian hacking once went through Arizona server

Posted 4/22/19

By Austen Bundy

Cronkite News

PHOENIX – The road from Washington to St. Petersburg apparently passes through Arizona – at least the cyber-road does.

That’s according to the …

You must be a member to read this story.

Join our family of readers for as little as $5 per month and support local, unbiased journalism.


Already have an account? Log in to continue.

Current print subscribers can create a free account by clicking here

Otherwise, follow the link below to join.

To Our Valued Readers –

Visitors to our website will be limited to five stories per month unless they opt to subscribe. The five stories do not include our exclusive content written by our journalists.

For $6.99, less than 20 cents a day, digital subscribers will receive unlimited access to YourValley.net, including exclusive content from our newsroom and access to our Daily Independent e-edition.

Our commitment to balanced, fair reporting and local coverage provides insight and perspective not found anywhere else.

Your financial commitment will help to preserve the kind of honest journalism produced by our reporters and editors. We trust you agree that independent journalism is an essential component of our democracy. Please click here to subscribe.

Sincerely,
Charlene Bisson, Publisher, Independent Newsmedia

Please log in to continue

Log in
I am anchor

Mueller report says Russian hacking once went through Arizona server

Posted

By Austen Bundy

Cronkite News

PHOENIX – The road from Washington to St. Petersburg apparently passes through Arizona – at least the cyber-road does.

That’s according to the long-awaited Mueller report on the two-year investigation into possible Russian meddling in the 2016 presidential election.

Buried in the 448-page report is a little more than a page that said Russian intelligence officers used a “leased computer” in Arizona to help funnel information that was stolen from hacked Democratic Party computers.

About half of the page on the Arizona server is redacted because the information relates to an “investigative technique” – one of the areas blacked out from the report, along with information about grand jury testimony, ongoing investigation and privacy concerns.

The unredacted portions do not reveal where in Arizona the leased computer was located or which company might have leased it.

But the report echoes information that was cited in a June indictment filed by Special Counsel Robert Mueller’s office against 12 officers of the GRU, the Russian intelligence directorate.It said the 12 conspired to “gain unauthorized access (to ‘hack’) into the computers of U.S. persons and entities involved in the 2016 U.S. presidential election, steal documents from those computers, and stage releases of the stolen documents to interfere with the 2016 U.S. presidential election.”

The indictment said the GRU officers installed malware called “X-Agent” on 10 computers of the Democratic National Committee and the Democratic Congressional Campaign Committee in April 2016. The malware “transmitted information from the victims’ computers to a GRU-leased server located in Arizona” that the Russians checked for information – keystroke logs and information on fundraising and voter outreach, for example.

The bulk of the information stolen using the Arizona-based computer “included passwords, internal communications between employees, banking information, and sensitive personal information” and occurred between April and June 2016, according to the Special Counsel’s report.

The Arizona computer “served as a nerve center,” the report said, allowing the Russian hackers to control the malware that broke in and stored the stolen Democratic data. In addition to X-agent, the Russians used “X-Tunnel” that gave the hackers the capability to view screenshots of Democratic employees’ computers.

Stolen data first went to a group of “middle servers” that communicated with the Arizona server, which the Russians would then access, according to the report. It said the Arizona server held “thousands of files” for the GRU officers for their operations in 2016.

Calls to cybersecurity experts and academics seeking comment on the Russians’ reported methods were not immediately returned Friday.