131. How Russia Made Trump: Stealing Washington’s Secrets (Ep 2)

25 Feb 2026 · 49 min · 15 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

```markdown

Podcast Episode Notes

The Rest Is Classified

Episode Title

131. How Russia Made Trump: Stealing Washington’s Secrets (Ep 2)

Hosts

David McCloskey & Gordon Corera

Episode Summary In this episode, the hosts dive deep into the continued exploration of Russian interference in the 2016 U.S. presidential election, specifically focusing on the strategies employed by Russian intelligence, namely the GRU (Russian military intelligence). The episode discusses the active measures campaign involving hacking and leaking information to undermine the political landscape, primarily against Hillary Clinton and the Democratic National Committee (DNC).

---

Key Concepts

  • Active Measures:
  • Russian tactics to influence political events, historically used by the KGB, now adapted in the digital age.
  • Involves seeding misinformation and mixing real and fake content to manipulate public perception.
  • Hack and Leak:
  • A method where information is hacked from sources and subsequently leaked to the public to create chaos or influence opinions.
  • The GRU employed this tactic extensively during the 2016 election.
  • GRU:
  • The main military intelligence agency of Russia, known for aggressive operations, including cyber attacks and information warfare.
  • Historically involved in operations like the poisoning of Sergei Skripal and cyber sabotage in Ukraine.
  • Unit 26165:
  • A specific GRU unit responsible for offensive cyber operations, including hacking U.S. political systems.
  • Key personnel include Victor Netish (commander), Alexei Lukashev, and Ivan Yirmakov, who utilized various techniques to infiltrate political organizations.

---

Episode Breakdown

Introduction

  • Hosts recap the previous episode's discussion on Russian active measures, particularly under Vladimir Putin.
  • The importance of information as a weapon in modern espionage is highlighted.

Russian Hacking History

  • Russian hacking tactics date back to the 1980s.
  • The rise of state-sponsored hacking marked a shift from traditional espionage to cyber operations.

The GRU's Role

  • The GRU's aggressive nature and historical continuity from Soviet times are emphasized.
  • Their involvement in cyber operations against Ukraine serves as a precursor to the strategies used in the U.S. election.

U.S. Presidential Race Context (2015-2016)

  • Hillary Clinton's strong position in polls is discussed, alongside Donald Trump's unexpected rise as a candidate.
  • Russian intelligence is portrayed as keenly observing and adapting to the evolving political landscape.

Hacking of Political Campaigns

  • The GRU begins targeting both the DNC and Republican National Committee for information.
  • The distinction between espionage (data gathering) and active measures (influencing outcomes) is clarified.

Key Events Leading to the Leak

  • GRU's phishing campaigns successfully infiltrate the email accounts of Clinton campaign chairman John Podesta and DCCC staff.
  • The use of deceptive emails mimicking Google security alerts to harvest login credentials is a focal point.

The Significance of Hacking Operations

  • The GRU successfully infiltrates networks, obtaining sensitive information, including opposition research on candidates.
  • Their aggressive and loud approach contrasts with the quieter, more subtle tactics of the SVR.

Conclusion & Cliffhanger

  • The episode ends with a preview of how the GRU plans to not only steal information but also publicly leak it, setting the stage for subsequent events in the election.
  • Encouragement for listeners to join the Declassified Club for more in-depth content on the topic.

---

Key Takeaways

  • The GRU's methodologies showcase a blend of traditional espionage tactics with modern digital strategies.
  • The Russian interference in the 2016 U.S. election was marked by bold actions and a disregard for the norms of covert operations.
  • Understanding the history of Russian active measures is crucial for comprehending their tactics in contemporary geopolitics.

---

Additional Resources

  • Books Mentioned:
  • "Russian Roulette" by Michael Isikoff and David Korn.
  • "Active Measures" by Thomas Ridd.
  • "The Apprentice" by Greg Miller.
  • Further Exploration:
  • Join the Declassified Club at [The Rest Is Classified](https://therestisclassified.com) for exclusive content and deeper dives into espionage topics.

```

This markdown file provides a structured and detailed summary of the podcast episode, capturing key concepts, themes, and discussions while ensuring clarity and accessibility for readers.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Active Measures and Information Warfare

0:45 to 2:44

Discussion on Russia's history of using active measures and information warfare to influence politics.

“Last time, David, we looked at this concept of the active measure, something which goes back to KGB days.”

The Role of the GRU in Espionage

2:44 to 6:20

Exploration of the GRU's historical role and operations in espionage and information warfare.

“And this is going to be called a hack and leak.”

The History of Russian Hacking

8:42 to 14:02

An overview of the development of Russian hacking from the KGB to contemporary operations.

“Available at participating locations only.”

Understanding Russian Cyber Operations

14:02 to 21:46

Learn about the evolution of Russian cyber operations, including their use of active measures and the role of the GRU.

“was understood what was happening in Ukraine at the time by the West, but the idea that those tools, those active measures would be exported onto the states was something that was not grasped at the time.”

The 2016 U.S. Presidential Election Landscape

22:28 to 28:00

Examine how Putin's views on Hillary Clinton shape Russia's stance as Trump enters the race for the presidency.

“During that break, David, I did try and understand what bangs were, and I've learned that it's basically a fringe, which like Claudia Winkleman, do you know Claudia?”

Trump's 2016 Presidential Campaign and Russian Interest

28:00 to 28:40

Learn how the Russian intelligence community viewed the 2016 election.

“Now, the Trump organization blames kind of vaguely, quote unquote, business reasons for the deal collapsing.”

Russian Hacking Operations Against Political Targets

28:40 to 30:24

Discover the dual roles of GRU and SVR in targeting U.S. political systems.

“of 2016 is going to assume the contest will be clinton versus trump we were talking earlier about how the GRU had been going after political targets in the West and in the US in particular.”

Historical Context of Espionage Tactics

30:24 to 31:40

Explore the historical background of espionage tactics in political campaigns.

“There's a wonderful book called Active Measures by Thomas Ridd that also gets at this historical context of active measures going back to Tsarist times, Gordon, and the KGB years.”

Targeting Key Figures in the Clinton Campaign

31:40 to 34:20

Understand how the GRU targeted key figures in the Clinton campaign.

“At first, they think it might be a kind of fake call into them and kind of ends up with computer support, the DNC.”

Phishing Campaign Against John Podesta

34:20 to 36:42

Learn about the phishing campaign that led to the breach of John Podesta's emails.

“So this is kind of a volume game to some degree to see where you can get bytes.”
Show all 15 chapters

The Fallout from the Podesta Email Hack

36:42 to 40:12

Discover the consequences of the GRU's successful hack on Podesta's emails.

“That's very stereotypical of you, Gordon.”

Continued Targeting of Democratic Campaigns

40:34 to 42:00

Learn about the ongoing attacks against Democratic organizations by the GRU.

“So the GRU throughout March, they just keep going after the Democrats, right?”

Unpacking the DCCC Hack and X-Agent Kit

42:00 to 43:36

Learn about the GRU's DCCC hack and the capabilities of the X-Agent malware.

“But now with the DCCC hack, Unit 26165 is inside a major political organization.”

The GRU and SVR Competition for DNC Data

43:36 to 45:46

Explore the dynamic between GRU and SVR as they infiltrate the DNC.

“server out in Arizona that had been leased by GRU unit 26165.”

The Consequences of the GRU's Actions

45:46 to 46:58

Understand the implications of the GRU's data theft and planned leaks.

“And what I also think is great is that not only did the SVR already have access inside the DNC, but later on it'll leak out that the SVR guys thought that the GRU guys did a really crappy job with the hack.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:03Gordon:For exclusive interviews, bonus episodes, ad-free listening, early access to series, first look at live show tickets, a weekly newsletter, and discounted books, join the Declassified Club at therestisclassified.com.

0:24David:Donald Trump is gaining ground in the 2016 presidential race, But what does his rise mean for Russian hackers desperate to take down Hillary Clinton? Well, welcome to The Rest is Classified. I'm Gordon Carrera. And I'm David McCloskey. And this is the second part of our series looking at Russia interfering in the US 2016 election. Last time, David, we looked at this concept of the active measure, something which goes back to KGB days.

0:52Gordon:Or before, before, remember you edited out my deep historical context, Gordon.

0:58David:Let's just say it goes back a long way.

1:00Gordon:We're 20 seconds into the episode. I'm already angry again about your vicious editing.

1:06David:It's about the active measure. Back to the story. It's the desire to influence, to undermine, often using information as a weapon. And last time, we looked at how under Vladimir Putin, he, the Russian leader, came to view the West as weaponizing information against him, and he's determined to use his own methods to fight back. And one of these methods, David, will be something which is known as hack and leak.

1:34Gordon:Well, that's right, Gordon. Last time we looked at how often very real documents and fake material can be kind of swizzled together and then pushed at journalists who were always, Gordon, of course, as you know, just keen to report whatever comes into their hands. Subject to manipulation by malicious spies, you mean. That's right. But you seed that information, you take real things and you take some fake stuff and you mix it together and then you seed it to an unsuspecting or sort of gullible journalist as the KGB did throughout the Cold War. And we talked about Operation Denver, where the KGB promulgated the falsehood that the CIA was behind the creation of the AIDS virus.

2:19Gordon:And it took years after that story had been planted to really get out and spread. And we're going to see that as we approach 2016, some of these old methods of stealing information and then leaking it out, well, they're still here, but it's going to be a lot easier to get it out. It's going to be a lot quicker to get the message out thanks to the Internet. And this is going to be called a hack and leak. The hack is, of course, how you get this stuff. And then the leak is how you disseminate it. And this piece of the active measure in 2016 is going to be led by the GRU, the main directorate of the general staff of the armed forces of the Russian Federation, Gordon, also known as Russian military intelligence.

3:06Gordon:And, you know, I would say one of the more insane spy organizations operating today in the world.

3:12David:That's right. The GRU, it's technically known as the GU these days, but everyone still seems to call it the GRU. deep roots going back many decades unlike some of the other soviet spy services the kgb which get renamed and the kgb becomes the fsb domestically in the security service and the svr becomes the foreign bit of the kgb which is your classic spy service like cia or mi6 the gru are the tough guys of military intelligence. They are doing classic espionage, trying to get military secrets, but they also are engaged in things like sabotage, assassination, active measures in terms of information warfare, again with this continuity never disbanded from the days of the Soviet Union and then continuing.

4:04David:And they are the ones who can do some of the most aggressive operations against the West, you think about the poisoning of Sergei Skripal in Britain in 2018 with Novichok, a former GRU officer himself, but poisoned by the GRU. So they tend to have more military targets, but they are the, I think you're right, maybe one of the more sinister Russian intelligence services.

4:28Gordon:I would say exhibit A in the GRU's sinisterness is the seal of the GRU, which you can see there's a great picture that I've put into the notes here. I don't know if we could, you know, put it up somewhere on the video, but it shows President Putin on a visit to GRU headquarters at a building known as the Aquarium, walking across the seal of the GRU in the Bay Lobby. And the seal is a sinister looking black bat that is covering most of the globe. And it reminds me, Gordon, of the Mitchell and Webb sketch where they're wearing the Death's Head Skull SS uniforms and wondering if they're the baddies.

5:12Gordon:You have to wonder what the GRU guys think they're doing at an organization that has an evil-looking black bat with its wings covering the entire world.

5:22David:Very impressive knowledge of British Schumer, by the way, to cite Mitchell and Webb, David. We'll get into numberwang next time, maybe, if you don't know that. But back to the back.

5:32Gordon:Well, people who listened to our last series will know that I sampled Monster Munch for the first time whilst I was in London, Gordon. And, you know, it's gone to the brain. What can I say? Let's go back to the GRU. So Wild Place, you mentioned the poisoning of Sergei Skripal, the GRU behind kind of the initial invasion of Crimea, parcel bombings across Europe, the poisoning of Alexei Navalny, a campaign to provide money to Taliban linked militants in Afghanistan. going after foreign forces, a failed coup attempt in Montenegro in 2016, trying to topple the government of Montenegro, poisoning a Bulgarian arms dealer, among many other insane operations.

6:15Gordon:So I think it's safe to say, Gordon, that the GRU alone might keep our podcast in business for a very long time.

6:21David:Plenty of stories there. And one of the things they do is a lot of hacking.

6:30David:This episode is sponsored by HP. Most people are not counter-espionage experts, but that won't stop them getting targeted by cyber criminals seeking to extract their secrets.

6:42Gordon:HP understands that approximately 4 in 10 UK businesses have reported cyber breaches in the past 12 months alone. That's why HP business laptops, desktops, and workstations bought directly on HP Store are secure straight out of the box with their endpoint security.

6:58David:No more stressing about dodgy emails or unexplained pop-ups. HP's independently verified WolfPro Security works alongside your existing security tools to protect your business, users and reputation from malware and evolving cyber threats with your first click.

7:16Gordon:You don't need an alias or a secret hideout to stay safe. Just WolfPro Security working tirelessly to protect your hard work. It's security that's built in, not bolted on.

7:26David:Find out more about how HP can protect your business at hp.com forward slash classified. Podcast listeners benefit from a 10 % discount on all business PCs, printers and accessories using the code TRIC10. Terms and conditions apply.

7:45Gordon:Tax Act knows filing taxes can be confusing, so we have live experts on hand who can help answer any questions you may have. Questions like, can I claim my SUV is my home office? if I answer work emails in my car? If I adopted 12 dogs this year, can I list them as dependents? And am I doing this right or am I doing this very, very wrong? Our experts have the answers to those questions and many others. Tax Act. Let's get them over with. Thought sweetgreen was just salads? Think again. There's a new way to do sweetgreen. Wrapped and ready. These handheld wraps pack bold flavor and 40 plus grams of protein into something hearty, satisfying, and built for life on the go.

8:29Gordon:From craveable sauces to satisfying textures, they're designed to keep you going without slowing you down. So put that fork down. Try the new wraps today in app or at order.sweetgreen.com. Available at participating locations only.

8:50David:So Russian hacking has got a deep history. I mean, the first case I know of is in the 1980s, when the KGB hire some East German teenagers to hack into the early US research Internet. By the 1990s, Russian hackers are running a campaign called Moonlight Maze, which is the first real state-backed espionage campaign the US sees against its secrets. All of this is espionage, though. And I think it's important that we draw this distinction between different types of behavior, including in cyberspace. Classic espionage is stealing secrets. And that's what a lot of people thought cyber hacking was all about when it came to state intelligence agencies.

9:35David:They thought it was about hackers often working for the state or employed by the state, covertly breaking into maybe military research networks, maybe defense networks, stealing the secrets, doing what spies have always done. But it is also worth saying that there is an element which is going to grow of active measures of influence operations and even of sabotage, which is going to be taking place in cyberspace. And the GRU's hackers are at the leading edge of that. We start to see some of the deployment of hacking alongside military operations. 2008, when there's a brief conflict between Russia and Georgia, and the US starts to see these hacking groups and US security researchers start giving them names for what are called APTs, Advanced Persistent Threat Groups.

10:27David:Famously, APT-28 will become known as Fancy Bear and be linked to the GRU. Bears are the terminology for Russian hackers, as opposed to things like pandas, which are the Chinese and so on. This is CrowdStrike, which is an interesting cybersecurity company, came up with this. It was a great marketing wheeze, very successful.

10:47Gordon:Also, potentially why it's hard to take some of this stuff seriously, because you think, oh, well, it's a group called Fancy Bear that is seeking to undermine US democracy. And it's like, well, how bad could it be?

11:00David:It's even worse, because the SVR, so the main foreign intelligence services hackers, are apt29 and they're known as cozy bear which sounds even more kind of you know like comforting like i'll just go hug a cozy bear i mean it's yeah i'm not quite sure and funnily enough these are western terms for these hackers but some of them adopt it themselves and they start creating logos using these names but apt29 cozy bear svr they're quiet and they're doing the espionage but the GRU's hackers are noisier. You start to see them picking up activity around Ukraine. We talked last time a bit about how Ukraine was the testbed for a lot of Russian operations, information operations, but also cyber operations.

11:44David:After the 2014 overthrow of the pro-Russian government, Russia starts to try and subvert them. There's a really interesting case in May and June 2014 when word comes out that the GRU has penetrated the Ukrainian Electoral Commission's network. And it's a really complicated, interesting operation. We won't go into all the details of it, but they're doing things like destroying parts of the files and the systems, and also in late May, trying to fiddle with the results of the election. So if it hadn't been discovered, The software that they'd installed was designed to effectively fake the election result and make out that a nationalist leader had one with 37 % of the vote rather than another candidate.

12:35David:Interestingly enough, a Russian TV channel that evening airs a bulletin declaring that the candidate with 37 % of the vote had got 37 % of the vote, even though the cyber operation had kind of failed, which shows that they were planning to declare on Russian TV the victory that they'd also used the hackers to try and install or infiltrate into the electoral commission system. So it was a pretty complex operation, which didn't really work and was discovered, but to try and mess with those elections in Ukraine in 2014, which should have been a warning sign, shouldn't it, that they were thinking of doing that?

13:13Gordon:Yeah. I think listeners should think of Ukraine as a kind of petri dish. Ukraine of 2014 and 2015 is kind of a petri dish for the kinds of things that the Russians will end up doing in the US because the sort of active measures, hacking disinformation playbook that ends up being exported to the states is really on display in Ukraine. I mean, you even had the GRU hacking and essentially tampering with critical infrastructure, right? I mean, there was famously sabotage conducted and led by the GRU against Ukraine's electricity grid in December of 2015. And actually hundreds of thousands of people lost power for a good part of a day during the frigid winter as a result of a GRU hacking operation.

14:01Gordon:So I think it was understood what was happening in Ukraine at the time by the West, but the idea that those tools, those active measures would be exported onto the states was something that was not grasped at the time. And interestingly, I mean, you start to see little hints of this kind of cyber espionage drifting toward active measures in the US in late 2014. There's a group called the Cyber Caliphate that is claiming to be linked to the Islamic State. They actually compromise US Central Command's social media accounts, post things like, American soldiers, we're coming, watch your back, signed ISIS.

14:45Gordon:And it's actually the Russians. And it's all seen as a little bit strange at the time. I think you actually covered a lot of this in your former life, Gordon, as a BBC journalist.

14:56David:Yeah, particularly one of the most interesting campaigns was they infiltrated a French TV channel, TV Saint-Monde. And I went to Paris to see the aftermath of this attack and met the head of the TV station. It was, I think, early 2015 when they took over the TV channel. They basically wiped its systems. And it was lucky that some of the engineers could see what was happening and pulled the plug on the systems before they could take down everything but the potential was they would have destroyed that tv channel i mean wiped its system to the point where they couldn't broadcast anymore and again they claimed the hackers they were linked to this cyber caliphate when again it was the gru it was russian military intelligence and it was only in hindsight i think people really understood that they were road testing some of these cyber attack capabilities because this wasn't a particularly big french tv channel and it wasn't a particularly sensitive time it was a sign that they were exploring russian hackers what they could do how far they could go how successful they could be including at shutting down parts of the information space so we we talked about them trying to interfere with an election in ukraine now shutting down a european or a french tv channel So you can see them just pushing the boundaries in this period.

16:17David:But again, I don't think it was fully appreciated how far they go.

16:20Gordon:A lot of the story that we're going to tell focuses on these kind of shadowy hacks. And I think behind the strange names of Fancy Bear, it's important to remember that this is an intelligence operation. There are humans, intelligence officers, working inside the GRU who are employed by the Russian state and who are conducting these hacks for political purposes and the purposes, of course, of an intelligence service to collect information, right? So maybe I think good to set up a bit of like who's actually doing this stuff. And there's some good detail on this again in Michael Isikoff and David Korn's book, Russian Roulette.

17:06Gordon:So GRU has a unit numbered 26165 GRU units. They do have names, but they also have these numerical signals, I guess, that Western intelligence agencies know them by. So unit 26165 during the Cold War, it was a unit that specialized in breaking encryption. And by the mid 2000s, it has become in the kind of digital age, one of the GRU's principal computer network exploitation units. So an offensive cyber unit that hacks computer networks overseas. It's housed in buildings owned by the Ministry of Defense. We talked about this a bit, Gordon, when we did the series on the North Korean cyber bank robberies, where if you think of a bunch of people eating Pop-Tarts in the basement of their mother's house, this is not what we're talking about.

18:00David:It's a military unit.

18:01Gordon:It's a military unit. And although some of these guys in the pictures that have come out look like they do spend a decent amount of their time eating Pop-Tarts in the basement of their mother's home, this unit is a very prestigious place to work, right? A former chief of the unit winds up becoming deputy chief of the entire GRU. This is a centerpiece of the GRU's capabilities. The commander of unit 26165 is a guy named Victor Netish. How would you pronounce this name, Gordon? Netickshow. So Mr. Netickshow, he's a software engineer, trained as a mathematician. He's published several articles on probabilistic functions and neural networks, Gordon.

Read the full transcript

18:46Gordon:And he has two junior officers working for him who are going to be very important to the hack and leak operation underneath this active measure. One of them is named Alexei Lukashev. He's 25 years old. He's blonde. He's thin. He's got close-set brown eyes. And for about three years, Gordon, he's been working under the cover of a persona that he uses for American and Russian social media accounts of Den Kattenberg. And apparently, according to the Isikoff in court account, the picture that Lukashev chose, showed a much more muscular young Russian man of his own age.

19:25David:So he made himself look better in his persona.

19:29Gordon:So what Lukashev is quite good at is crafting email bait that looks like Google security warnings, but in reality are ways to trick victims into revealing their passwords. So a helpful skill if you're a hacker. The second noteworthy guy is Ivan Yirmakov. He's got bangs, Gordon, if you're curious about his hairstyle. What are dark bangs? What are bangs? Yeah.

19:57David:Should I know what they are? I'm looking around.

19:58Gordon:You don't know what bangs are? Bangs are like, yeah, hair that comes down, bangs kind of down here on your forehead. That's what a bang is. That's, you know, Gordon, come on. Remember when we did the Bulgarian Minions episodes? Remember, I did all that research on lashes and things like that because one of them was a beautician.

20:18David:I should have done some research for this. Sorry. Get with the program. There I was, researching cyber capabilities. I shouldn't have been researching haircuts.

20:24Gordon:But anyway, back to Ivan with his dark bangs. Back to Yermakov. Yermakov, for some reason, prefers female pseudonyms. One of them is called Kate S. Milton, which he has on a Twitter profile and a blog. There's a picture that accompanies that, which is of a Canadian actress. And what Kate, quote unquote, likes to do is privately approach security researchers. And he apparently also claims to work for the security firm Kaspersky, although that's not true. Now, the unit they work for, 26165, it's a pretty big unit. And I think it's fair to say, Gordon, willing to take a certain amount of risk in its operations.

21:07Gordon:It has a vast number of people and organizations and countries that it has targeted. And it has been, I think, turning its focus more and more on the United States and in particular on political targets. Because in 2016, of course, it is a presidential election year in the United States. And Unit 26165 of the GRU is going to get itself quite purposely embroiled in what is going to become one of the most brutal and toxic elections in U.S. history. So maybe there, Gordon, we take a break and when we come back, we will see how the GRU begins to meddle in this election.

21:52David:Hablas Español? Spreys to Deutsch? If you used Babbel, you would. Babbel's conversation-based techniques teaches you useful words and phrases to get you speaking quickly about the things you actually talk about in the real world. With lessons handcrafted by over 200 language experts and voiced by real native speakers, Babbel is like having a private tutor in your pocket. Start speaking with Babbel today. Get up to 55 % off your Babbel subscription right now at babbel.com slash Spotify.

22:19Gordon:Spelled B-A-B-B-E-L dot com slash Spotify. Rules and restrictions may apply.

22:28David:Well, welcome back. During that break, David, I did try and understand what bangs were, and I've learned that it's basically a fringe, which like Claudia Winkleman, do you know Claudia? I think she has a fringe. I think now I know what that means. But anyway, enough about haircuts.

22:45Gordon:So fringe is a British word for bangs.

22:49David:That's what I'm told. That's what I'm told. That's what I'm told, but I don't really know that much. I'm reaching the limits of my... Can we go back to the US presidential election rather than my lack of knowledge about hairstyles? Because I feel like I'm on safer ground there.

23:03Gordon:Well, that's true. You are. When I hear fringe, what I think of is someone who's very bald on the top of their head, but then has the stuff on the sides and it's maybe a little too long.

23:12David:But that's not a fringe in the United Kingdom.

23:15Gordon:Okay. Well, we've solved at least one mystery on this program. Back to the US election.

23:21David:So David, last time we talked about how much Vladimir Putin really despised Hillary Clinton, who'd been President Obama's Secretary of State. He blames Secretary Clinton for triggering or supporting some of those protests against his return to power 2011-2012. And by the time we get to 2015, it's looking like she is very likely to be the Democrat nominee for the 2016 presidential election.

23:51Gordon:Well, that's right. In In June of 2015, which is going to be an important month for the other big name in the story, Donald Trump, who announces his candidacy that month. But in the summer of 2015, Hillary Clinton is way ahead of Bernie Sanders in the polls, looking at who's going to represent the Democrats. I mean, she's ahead. I think there's a poll in June of 15 that showed that Clinton was the first choice for nominee of about 75 % of the party. Bernie Sanders is way behind at 15%. And polls that same month show Clinton beating the sort of then presumptive Republican nominee, former Florida governor Jeb Bush, Clinton beating him 48 % to 40%.

24:33So why are we talking about this?

24:36Gordon:The point is, is that any foreign intelligence service, Russia among them, is going to look at these polls, see them, digest them in some way. And their base case at this point is going to be that Hillary Clinton is going to be the next president. But that's a month in June. Another Republican hopeful has announced his bid. And this is, of course, when Trump descends the golden escalator at Trump Tower in New York City. He's not even mentioned in that poll. Now, at this point in the active measure, Trump almost certainly doesn't figure at all. But I think it's worth briefly examining how Moscow would have perceived Trump in relation to Clinton, because Trump is, of course, going to very quickly gain ground in polling in the summer and fall of 2015 after he announces and really never look back.

25:27Gordon:We're going to talk a little bit about the Trump-Russia kind of connection here, or how the Russians would perceive Trump. And this is going to be fact-based, so you don't have to go nuts here. You don't have to be upset. We're not talking about Trump policy thinking regarding Russia. We're not talking about collusion or anything like that. This is just setting up how the Russians perceive Trump or are likely to perceive Trump as he enters the presidential race. Although we will say, Gordon, we have a special miniseries for club members that we are doing that goes deep into the facts and the chronology of Trump's connections to Russia and the connections between Russia and his campaign and all of the drama around that.

26:15Gordon:We're going deep in a miniseries on that. So if you are interested in exploring that, go and join the Declassified Club at TheRestIsClassified.com. But stepping back, I think just a bit in time to set up, okay, how would the Russians see Trump, right? So unlike Hillary Clinton, who has interacted with Putin and Russia as first lady in the 1990s and then as Secretary of State from 2008 to 2012 and who Putin loathes, I think it's fair to say, Gordon, Trump has approached Putin by this point and Russia more broadly through a really kind of commercial lens. There's this very interesting statement in 2007, which is when Time magazine selects Mr.

26:56Gordon:Putin as its man of the year. Trump writes him a letter congratulating him and writing, as you probably heard, I'm a big fan of yours. Trump writes in that letter. Now, Trump had long sought to develop business opportunities in Russia. By the time of his campaign announcement, his most recent venture was an attempt to build a Trump Tower in Moscow. Now, that actually continues through much of the campaign. And it's an effort led by one of Trump's lawyers to actually develop a Trump Tower in the Russian capital. But by 2014, you know, Trump is visiting Russia for the Winter Olympics at Sochi. And afterwards, the press note that there's progress on developing a Trump Tower in Moscow.

27:39Gordon:There's actually a letter of intent that gets signed. Don Jr., Trump's son, is put in charge of the project. Ivanka actually goes, his daughter goes to Moscow to scope out sites. It's Trump tweets about it saying Trump Tower Moscow is next. But all of that falls apart amid sanctions on Russia following the seizure of Crimea and the kind of hybrid war that the Russians unleash in Ukraine in 2014. So the deal dies. Now, the Trump organization blames kind of vaguely, quote unquote, business reasons for the deal collapsing. But it is probably more than that because a bank key to the deal ends up getting sanctioned and financing dries up.

28:17Gordon:point is by the spring of 2016 trump is narrowly leading the republican field of the polls he's won the primaries in south carolina and nevada he is the republican front runner and any russian analyst worth their salt really any foreign government at all by that point in the spring of 2016 is going to assume the contest will be clinton versus trump we were talking earlier about how the GRU had been going after political targets in the West and in the US in particular. And who do you hit, Gordon, in an election year? Well, it'd be interesting to know what's going on inside the Democratic National Committee and the Republican National Committee.

29:06Gordon:And in fact, the GRU is going after both.

29:09David:It's worth saying, though, it's not even just the GRU, because also The SVR are actually hacking into US political systems. And even as early as 2015, they're going after the DNC, I think the first signs that they are getting into the democratic systems to spy, though. And it's worth going back to that distinction between spying and active measures, because the SVR hackers, who are known as Cozy Bear, are getting into the DNC systems from 2015 to steal information, to do what intelligence agencies normally do, which is find out what's happening? What are their policy papers or position papers?

29:44David:Who's up? Who's down? Who's likely to get jobs in administration? But what's different is, while that activity is going on by one bit of Russian intelligence, the GRU are also going to get involved with a very different purpose of getting inside for an influence operation, for an active measure. And it's particularly the DNC, which is the one which is going to be targeted for this idea of hack and leak, which we've set up, different from the espionage campaign, which is already underway at this point.

30:17Gordon:And I guess it's also worth saying, hat tip here to a number of wonderful books that have been written on this hack and on the broader active measure. We've mentioned Russian Roulette. There's a wonderful book called Active Measures by Thomas Ridd that also gets at this historical context of active measures going back to Tsarist times, Gordon, and the KGB years. And then there's a wonderful book called The Apprentice by Greg Miller, who's a Washington Post reporter. Also, the US Senate Intel Committee, Gordon, has put together a thousand page document on everything that happened this year. There really is a rich amount of information out there on this story.

31:03Gordon:Now, it's not abnormal for an adversaries to target a political campaign. We talked about some of the KGB attempts to do that during the Cold War in our first episode. But as recently as 2008, the FBI had discovered that Chinese government hackers had infiltrated the campaigns of Barack Obama and John McCain. So, again, do you think for an espionage service, it would be malpractice to not attempt to get into the files and the documents, you know, in the sort of research of a presidential campaign?

31:36David:Yeah, it's seen as almost normal, as par for the course. And in fact, when some of the first warnings come into the DNC, I think from the FBI in 2015 that someone might be in their systems, the kind of DNC barely reacts to it. They don't even take it seriously. At first, they think it might be a kind of fake call into them and kind of ends up with computer support, the DNC. This issue of espionage against campaigns, A, campaigns didn't take it seriously, and B, it was seen as just something that states do. And maybe the kind of secrets or information in a campaign was not necessarily top secret in the traditional way.

32:10David:But we are entering this new era where the GRU is getting more involved. And it is interesting because if you step back, this 2015-2016 era, Unit 26165 is getting more involved. We talked about it taking down a French TV channel in 2015. But also, they're going to hack German parliament emails that year, take a ton of data, including some material belonging to the German Chancellor, Angela Merkel. So you can start to see that in this period, the GRU is getting noisier and is looking for interesting, valuable data. Still haven't seen it leaked yet, but they're certainly collecting. And part of that will be collecting against the DNC and against specific individuals associated with the Clinton campaign.

33:03Gordon:Yeah, I think the wide net point is important because there were hundreds of officials targeted in the U.S., including many sort of current and past military and diplomatic officials. I mean, there were attempts made on Secretary of State John Kerry, former Secretary of State Colin Powell, Michael McFaul, who'd been an ambassador to Russia. And there were over 100 Democratic targets, right? The Clinton campaign's communications director, other longtime Clinton aides and confidants, all of them are getting blasted with these phishing emails. And you figure if you're the GRU, why not cast a wide net, right?

33:44Gordon:The worst someone's going to do is just delete the thing and not interact with it, but you might also get lucky. And so you cast this very white item. They'd even gone after the Clinton Foundation and the Center for American Progress, which is a progressive think tank that was at that point very close to Hillary Clinton. So they are going broadly, but what they're going to land in the spring of 2016 is that GRU will get a very, very big score. They're going to get someone who is very much at the top of the Clinton campaign. And it's maybe good to situate this in time, Gordon. So mid-March of 2016, GRU Unit 26165, which is run by this Natikshow guy, one of his hackers talked about it, Lukashev, is he's sending out these kind of booby-trapped emails, malware embedded emails to 50 different addresses every working day.

34:42Gordon:So this is kind of a volume game to some degree to see where you can get bytes. And most of these just fail. Some of the addresses are obsolete. Again, people don't interact with them. And the Clinton campaign, their kind of default email security settings required more than just a password to get in. So a lot of a lot of the staff are protected from these things. Now, you mentioned you were in the FBI knowing that something's going on. And there'd actually been a meeting at Hillary Clinton's campaign headquarters in Brooklyn back in March. There's Clinton staffers there, including Clinton campaign manager.

35:21Gordon:As you said, weirdly, they're kind of suspicious of the FBI because there happens to be an investigation ongoing into Hillary Clinton's use of a private server for email traffic, which we'll talk about more in a moment. Yes. And the FBI at the time in March is offering these kind of cryptic warnings that the campaign is being targeted by a very sophisticated spear phishing campaign. But again, there's no reference there to by whom. And there's no reference to the concurrent investigation into intrusions in the DNC's computers. And so the Clinton campaign has this point is kind of thinking, you know, to your point earlier, this is kind of what happens to presidential campaigns.

36:07Gordon:You know, you're going to be the target of foreign intelligence services. The Clinton campaign has already kind of heightened its cybersecurity posture, and they don't quite know what to make up the FBI warnings. But on the 18th of March, Lukashev's team inside unit 26165 changes tactics and they decide to go after private email accounts instead of the official campaign email accounts on the theory that those private accounts will be more vulnerable. People's Gmail, basically. Things like that. Yeah, exactly. And the next day, just before lunch, I'm sure a hearty lunch in Moscow. I wonder what the GRU canteen is like.

36:45David:Dumplings. And borscht. Borscht. Yeah.

36:49Gordon:That's very stereotypical of you, Gordon. Sorry. Shame on you. After a lunch of borscht, Lukashev and his team sends another batch of booby-trapped emails to another 70 targets. You get the sense that these guys are like, they've got to be kind of bored, don't they? I mean, this sounds like when you hear hacker, you think it's going to be cool and you can eat Pop-Tarts all day, but it feels like they've got a quota.

37:13David:Yeah.

37:13Gordon:They send out 70 bore emails. including they go after nine senior Democratic political operatives, again, on the personal Gmail accounts. Now, one of them is John Podesta, who is the chairman at the time of Hillary Clinton's campaign. The message reads like this, and it looks like it's from Google. Someone has your password. Okay, that's where it starts. It says, hi, John, someone just used your password to try to sign into your Google account, john.podesta at gmail.com. Then it goes to the details. It's Saturday, 19 March, 834. It's got the IP address.

37:53David:So it looks credible. Yeah. It looks credible. It looks like the kind of email you might get.

37:57Gordon:Yeah, exactly. Gordon's cutting me off before I can read the entirety of the robotic script. That was well done, Gordon, because I was going to finish reading it. Your instincts were right. But the details are all made up, right, even though the email looks credible. Now, Podesta's staff have access to his email account. And when they see the security warning, they forward it on to the Clinton campaign's IT help desk. And in a few minutes, the IT help desk responds and they say, OK, we got it. And they recommend that Podesta changes his password and that he turns on an advanced security feature.

38:36Gordon:And the IT guy writes, you know, this is a legitimate email. John needs to change his password immediately. But, but, but they misunderstand the email and they click on the booby trapped link that the GRU had sent instead of the safe Google link that had been provided by the IT help desk. So when they click on that, there's a malicious URL that is sitting behind this change password link that they cannot see, but they've clicked on it and that they're in trouble. Now, the link takes Podesta's staff to this forged Google login page, which looks exactly like the real Google page. And it's very crafty because it even has John Podesta's actual profile picture right there set against this background.

39:27Gordon:It looks right. Okay. And his staff, who are thinking that they're following the Clinton campaign's IT help desks guidelines and interacting with legitimate Google password change, his staff enter the password. And they're in. This is a big problem because two days later, Lukashev, in an office just reeking of borscht and pop tarts, has downloaded more than 50 ,000 emails. This is five gigs of data. He's taken all this stuff out of Podesta's inbox. And the GRU has absolutely struck gold. And now, Gordon, time for a word from our sponsors at NordVPN.

40:13David:We should have got them to sponsor this episode. We should have got a few cybersecurity firms to sponsor this episode because this is basically telling you what you need to be careful of, which is think before you click. Don't.

40:29Gordon:Just don't click on anything. Right. Don't click on anything. Period. That's not going to help.

40:34David:You have to click on something because otherwise you're not going to do anything online.

40:40Gordon:what you should do is click on over to the rest is classified.com and if you join the declassified club your emails will be will be hoovered up by by unit 26165 by goal hanger that's right that's right now a take a technician that uh doesn't smell of borscht but uh but

41:01David:monster munch most likely yeah it's what they have in the office here that's right okay so this is a

41:06Gordon:major problem. But it just keeps going. So the GRU throughout March, they just keep going after the Democrats, right? Lukashev's unit, they go after DNC staffers, they're going after the Clinton campaign, they continue sending out the bait emails, even as they've hoovered up all this stuff from Podesta's email account. Now, on April 6th, a few weeks later, the GRU succeeds in tricking an employee of the Democratic Congressional Campaign Committee, the DCCC, Gordon, bam, an organization that supports Democrats in the House of Representatives. Now, the DCCC employee had inadvertently given away her login credentials.

41:51Gordon:So Unit 26165 had been able to get inside not just individual email accounts, because keep in mind, Podesta's emails, that's his personal email. But now with the DCCC hack, Unit 26165 is inside a major political organization. So what do they do? The GRU installs a hacking tool called the X-Agent Kit. I don't know if NordVPN protects you from that.

42:19David:It's a good name, X-Agent.

42:21Gordon:But it's a good name. And they get that on at least 10 computers at the DCCC. Now, this kit is going to allow them to record and to intercept all of the activity that happens on a particular computer. So essentially, it is taking everything. It's like a keystroke log or everything a user types or sees over an entire workday. The X-Agent kit will hoover up. And you, Gordon, you know a thing or two, don't you, about the X-Agent kit?

42:49David:No, well, I was looking into X-Agent. I mean, it's a great name for a bit of malware, but it looks like it's created and customized by the GRU itself. So they've developed this bit of kit to move from machines and through a network, activate the microphones, record the audio, collect the text messages, also geolocate people when it gets onto people's phones, for instance, of where they are. And you first see it again in Ukraine around 2015, where it's being used to geolocate people. So again, it's that Ukraine is a testbed for the GRU developing some of its more advanced cyber capabilities, which now they're deploying 2016 against the US more.

43:29Gordon:Well, it had been customized also, Gordon, to communicate with a relatively inconspicuous server out in Arizona that had been leased by GRU unit 26165. And that machine in Arizona was running a control panel that would allow the GRU officers to kind of manipulate the ex-agent kit and their implants essentially on the network in Washington, right? So in the case of one particular DCCC staffer, the GRU was, I mean, was quite literally, I guess not literally Gordon, but digitally able to watch over her shoulder as she's handling personal banking information and things like that from inside her office at the DCCC.

44:14Gordon:Now, what's valuable to the Russians inside the DCCC stuff? Well, the DCCC has a bunch of opposition research on Republican candidates, right? So what you see is the Russians are going after oppo research on Ted Cruz and on Donald Trump. And after a week of trying to make sense of this information on April 18th, the GRU gets lucky because they intercept the login and password credentials of another DCCC employee who was authorized to log into the network of the Democratic National Committee. So the GRU can now pivot from the DCCC network, which I think is ultimately less interesting to them, over to the national DNC.

45:04David:Amusingly enough, the SVR's team are already in the DNC and have been in there. I just love this. The SVR's quiet, cozy bear hackers have been secretly inside the DNC's networks for a few months, exfiltrating data. And you could imagine them suddenly realizing, oh, here come those loud guys from the GRU. Their hackers are now in as well because they're competing. They're not even talking to each other. And it's the loud hackers of the GRU who are really going to draw attention to what's going on because they've now got access, the GRU, to the DCCC, the DNC, and individuals from the Clinton campaign.

45:41David:So they've got this amazing coverage across the Democratic side in 2016.

45:46Gordon:And what I also think is great is that not only did the SVR already have access inside the DNC, but later on it'll leak out that the SVR guys thought that the GRU guys did a really crappy job with the hack. As we'll see in the next episode, the sort of cozy bear guys over at SVR do have a point because the guys who are working at the organization that have the BAT logo covering the entire world are, as it turns out, a little bit clumsy with how they pull this thing off and willing to break a whole bunch of stuff and do it in kind of a roughshod way.

46:24David:Yeah. Is it clumsy or they just don't care? I mean, that's what's interesting about the GRU. If you look at GRU operations, things like the Salisbury poisoning with Novichok, they're aggressive, they're loud, they're noisy, and sometimes it feels like they don't care. So it is the difference, I think, between the way the GRU and the SVR operates. But yeah, now they are both in the network and it's the GRU, which is going to do something extraordinary, isn't it? Because it's in the network, but it's not just going to take the information. It's going to steal it and publish it. It's not just going to hack.

46:57David:It's going to leak.

46:58Gordon:That sounds like a cliffhanger to me, Gordon. I think we should end the episode there. And next time we come back, we'll see how that leak absolutely shakes the election up. But Gordon, you don't have to wait. No, you don't. If you want to listen to this entire series right now, plus that really fascinating exclusive mini-series we're doing on the Trump-Russia connection, just go and join the Declassified Club at therestisclassified.com. We'll see you next time.

From the publisher

Donald Trump is gaining ground in the 2016 presidential race, but what does his rise mean for Russian hackers desperate to take down Hillary Clinton?

In the second episode of our series on Russian interference in the 2016 US presidential election, David and Gordon delve inside the Russian active measures campaign to hack the campaigns of the Democratic and Republican candidates.

-------------------

Sign-up for our free newsletter where producer Becki takes you behind the scenes of the show: https://mailchi.mp/goalhanger.com/tric-free-newsletter-sign-up 

-------------------

Join the Declassified Club to go deeper into the world of espionage with exclusive Q&As, interviews with top intelligence insiders, regular livestreams, ad-free listening, early access to episodes and live show tickets, and weekly deep dives into original spy stories. Members also get curated reading lists, special book discounts, prize draws, and access to our private chat community.

Just go to ⁠⁠therestisclassified.com⁠ or join on Apple Podcasts.

-------------------

Get a 10% discount on business PCs, printers and accessories using the code TRIC10. Visit https://HP.com/CLASSIFIED for more information. T&C's apply.

-------------------

EXCLUSIVE NordVPN Deal ➼ ⁠⁠https://nordvpn.com/restisclassified⁠⁠ Try it risk-free now with a 30-day money-back guarantee

-------------------

Email: therestisclassified@goalhanger.com

Instagram: ⁠⁠⁠⁠⁠⁠⁠@restisclassified

Video Editor: Joe Pettit

Social Producer: Emma Jackson

Assistant Producer: Alfie Rowe

Producer: Becki Hills

Head of History: Dom Johnson

Exec Producer: Tony Pastor
Learn more about your ad choices. Visit podcastchoices.com/adchoices

More from The Rest Is Classified

All 157 episodes
131. How Russia Made Trump: Stealing Washington’s Secrets (Ep 2)The Rest Is Classified · 49 min
Listen in VO