Anonymous Release 10TB Leaked Data Exposing Kremlin Assets, Russian Businesses

217 points by deepnet 2 months ago | 91 comments
  • swdev281634 2 months ago
    I downloaded and extracted the files in a fresh Linux virtual machine with tools for viewing Word, Excel, and PDF documents. After reviewing the contents for about 30 minutes, the data appears technically authentic—not AI-generated—but nothing particularly noteworthy stood out.

    The files "Vulnerabilities/Fetched Data.txt" appear to be output from an automated security scanner that targeted public-facing web servers. Some directory labels are inaccurate. For instance, a company listed as a crypto exchange—Cryptopro—is actually an IT consulting firm focused on cryptography and PKI.

    A number of Word, Excel, and PDF files containing corporate reports and similar materials appear to be publicly accessible online and even indexed by search engines. I was able to locate several by searching their titles.

    One file, "Part 1/Report those Russian ringleaders/russRingleadersPerDFUNAFO.txt", seems to be the likely source of the "Kremlin Assets in the West" mention. It’s a brief list of Twitter accounts and may have been assembled through open-source intelligence methods.

    While the leak might contain some mistakenly published or sensitive material, I didn’t come across anything as significant or dramatic as implied by the article linked.

    • ValveFan6969 2 months ago
      Who woulda thunk the AI generated article doesn't know what it's talking about
    • mmastrac 2 months ago
      From a quick scan of the file listing of the 18GB compressed folder linked for download elsewhere, looks like it's a collection of completely random data hacked over a number of years from various accounts that may or may not be connected with Russia (Guy Ritchie? Kanye West? Why?).

      Also, why a PNG?

        2022-12-02 10:25:11 ....A        10530        10092  Leaked Data of corrupt officials/Part 1/Leaked Data of Kanye West's Instagram account/IP, Port, Hostname.png
        2022-12-02 10:26:08 ....A        39852        37635  Leaked Data of corrupt officials/Part 1/Leaked Data of Kanye West's Instagram account/SSL info.png
        2022-12-02 10:27:01 ....A       124662       114729  Leaked Data of corrupt officials/Part 1/Leaked Data of Kanye West's Instagram account/Vulnerabilities.png
      
      Some bank data seems to be exposed here (internal control panels), but in other cases it's just a dump of public website HTML?

      10TB seems just plain wrong (didn't bother downloading the whole thing, though).

      • jijijijij 2 months ago
        > Vulnerabilities.png

        Clever. Instagram is an image hosting platform. At the firewall, guards watching the network traffic wouldn't notice png encrypted screenshots of cracked IP addresses being exfiltrated, drifting in plain sight in the usual pixel streams.

        • mmastrac 2 months ago
          I didn't bother looking at the files, but I would wager that it's not as clever as you suggested here. If there's gold in this leak, I'd suggest it's buried in an Everest of crap.
    • jmclnx 2 months ago
      Yikes, the archive article asked me to install Abobe Flash, and I am on Linux. I guess it is really from Russia :)
      • constantcrying 2 months ago
        It's an article from an Indian right wing conspiracy news website. Check out their other hard hitting journalism: https://archive.ph/8RGAb
        • kcindric 2 months ago
          oufff, okay, this puts the reliability of the article much lower now.
          • starspangled 2 months ago
            Well gentlemen, we will always remember this as the day we almost caught Donald J. Trump, again.
          • Craighead 2 months ago
            [dead]
        • Rallen89 2 months ago
          Seems very dubious, new accounts in the comments urging people to download it ( u/Sonnigeszeug) all the 'sources' go back to the same file, claims it is on torrent trackers yet providing no evidence for? A very sensational article with no proof and if it was true downloading russian government data with no idea whats in it? the sweetest of honey right here
          • constantcrying 2 months ago
            I am sure the other reports from the website are very real: https://archive.ph/8RGAb
            • A_D_E_P_T 2 months ago
              Most people have absolutely no way to handle a 10TB file, anyway. Even 1TB csv files can be a challenge. Need to use DuckDB or chunk it somehow.

              A lot of ways to hide nasty surprises in such a file, too.

              • miningape 2 months ago
                Pack it into a nice executable "csv" and you've got baby's first malware
            • Sonnigeszeug 2 months ago
              Dude... i'm a software engineere in germany.

              I create new accounts because i spend too much time on hn...

              I suggest to download stuff because i assume people on HN are well equiped to check it out.

              Click yourself some cheap vm in the cloud, download it, check it out. Cost involved? $10

              Do you expect journalists with less it knowledge to do this? I mean yeah they can and should but people on hn should do too

              • benterix 2 months ago
                > i'm a software engineere in germany.

                Fake German detected. A true one would write "I'M A Software Engineer In Germany".

                • znpy 2 months ago
                  they said he is a software engineer in germany. they didn't say they are from germany.
            • kif 2 months ago
              "Leaked data" seems like a stretch. Sounds like someone ran a vulnerability scanner on some Twitter accounts. Don't have time to go through all the data though, so maybe there are interesting things in there.
              • ty6853 2 months ago
                It is is a real thing though that Russian databases are routinely compromised or stolen.

                People that engage in tax fraud in places like Mexico and Russia often legitimately do it because they do not want the mob/cartels to find out how much money they have and then extort them. The data gets out.

                • pseudo0 2 months ago
                  Yeah, from the screenshots on Twitter a lot of it looks like archives of publicly accessible Twitter and Telegram accounts, plus data from old breaches. That makes it seem pretty unlikely there will be anything new and valuable here.
                • Rallen89 2 months ago
                  Any validity besides one news article? seems to be getting the hug of death atm.
                  • EdwardDiego 2 months ago
                    Hugged? Or DOSed?
                    • 42lux 2 months ago
                      Just download the data and validate it yourself if you are skeptical? I guess that's why they released it...
                      • Rallen89 2 months ago
                        10 TB file from a random website that I have never heard of? Seems like if someone was to leak this a more reputable news agency would have been notified instead of... trendsnewsline
                        • 42lux 2 months ago
                          You don't have to download the whole 10TB...
                          • 2 months ago
                            • Sonnigeszeug 2 months ago
                              Who if not people / experts reading on hn?

                              Click yourself any server anywhere, download it, analyse it, share your findings.

                            • owebmaster 2 months ago
                              That's a fast way to get hacked or become a target. We can do better in this forum security-wise
                              • 42lux 2 months ago
                                We are on a forum were most users should know how to operate data that has the probability of malware in it...
                          • rokkamokka 2 months ago
                            That's fun. Someone feeling up to feeding the 90k trump files into an LLM for a synopsis?
                            • close04 2 months ago
                              > the 90k trump files

                              Just a question I asked below. That's the size column in WinRAR (left of the Compressed column). Is it by coincidence also the number of files?

                              • deepnet 2 months ago
                                [flagged]
                                • t0lo 2 months ago
                                  That's the worst ai summary i've ever read. I could surmise that in my brain from like 3 sentences about the issue
                                  • 2 months ago
                                  • Havoc 2 months ago
                                    Can we please keep the AI junk off hn…

                                    Bad enough that it’s everywhere else

                                    • pseudo0 2 months ago
                                      Why are you quoting AI slop from reddit? That's an incredibly vague summary of the article about the leaked data and provides no useful information.
                                      • deepnet 2 months ago
                                        Because the article is currently down so the summary is all there is for now.

                                        Yes it provides no extra information but in the [hnews hug of death] of the article it is the only information at the moment

                                  • jijijijij 2 months ago
                                    If this is real, there will be claims made and the general public has no way to verify. 10TB is technically challenging to handle for the vast majority of people. Would be really important for someone to re-upload and index the extracted files for online browsing.
                                    • xyst 2 months ago
                                      Just like the Panama Papers?

                                      Did anything even happen after the Mossack Fonseca law firm was hacked? All I remember was a few people stepping down from govt positions, some rich folks get caught in the xfire (some football player used them).

                                      But nobody went to jail.

                                    • constantcrying 2 months ago
                                      "If this is real". Do you think this is real: https://archive.ph/8RGAb ?
                                      • 2 months ago
                                      • 2 months ago
                                      • t0lo 2 months ago
                                        So do we have a verdict yet? Anything more than scraped osint and telegram chats?
                                        • scotty79 2 months ago
                                          Finally. More than 3 years to get russia hacked properly is a bit much. I think IT security got a bit too secure for the safety of freedom.
                                          • yobannyvrot 2 months ago
                                            One ai slop article, and an 18gb mediafirelink from some twitter literally who. Taking bets for complete nothingburger...
                                            • constantcrying 2 months ago
                                              What is wrong with people. Who believes this is real?

                                              Do you really think a WordPress website from India posting obvious fake news and conspiracies should be trusted?

                                              Do you think the source that brought you this is reliable in any way: https://archive.ph/8RGAb "Shocking Footage: Hunter Biden & Ellen Caught in Adrenochrome Bust!"

                                              • t0lo 2 months ago
                                                People need to believe someone else out there will solve their geopolitical problems for them.
                                                • constantcrying 2 months ago
                                                  I thought at least people on this website would be able decipher that this is an obvious fake news website, it also posts some of the most generic right wing conspiracy theories. Quite disappointing to be honest.
                                                • otabdeveloper4 2 months ago
                                                  > Do you really think a WordPress website from India posting obvious fake news and conspiracies should be trusted?

                                                  Depends. Does it validate my Russian collusion delusion?

                                                • deepnet 2 months ago
                                                  • petee 2 months ago
                                                    I'll happily wait for someone else to open that archive and let us know whats in the folder.

                                                    Somehow feels like a great way to get a bunch of people to download a rar with a zero day

                                                    • bgwalter 2 months ago
                                                      Yes, an example:

                                                      https://blog.google/threat-analysis-group/government-backed-...

                                                      I also do not understand how Anonymous would sift through 10TB to confirm the validity of the claims.

                                                      • Rygian 2 months ago
                                                        > Instead of bailing out, ShellExecute proceeds to call “shell32!ApplyDefaultExts” which iterates through all files in a directory, finding and executing the first file with an extension matching any of the hardcoded ones: “.pif, .com, .exe, .bat, .lnk, .cmd”.

                                                        So the vulnerability is not in WinRAR, but rather in the ShellExecute windows code that desperately tries to find something else to run when asked to execute a file that does not exist.

                                                        As my security officer says at $dayJob, "having a security hole there for thirty years does not make it somehow less of a security hole".

                                                        • 2 months ago
                                                        • Sonnigeszeug 2 months ago
                                                          So always wait for others to do something?

                                                          Don't just download it on your windows home pc with your private data of course.

                                                          • petee 2 months ago
                                                            In some cases, yes.

                                                            An unknown threat, potentially from the supposed nation-state target itself, has a very high risk.

                                                            I'm not versed in creating ultra-sterile lab conditions -- things can escape VMs, escape your network, nothing is impossible. Do I instead bring it to my employers systems and let them take the risk? And to what benefit, when I can just wait?

                                                          • 2 months ago
                                                          • LANcaster 2 months ago
                                                            How 18.84GB file is 10TB?
                                                            • jijijijij 2 months ago
                                                              Probably mostly text, which is highly compressible.
                                                            • close04 2 months ago
                                                              > Trump has ~91k files in the data

                                                              That's the size column in WinRAR (left of the Compressed column). Is it by coincidence also the number of files?

                                                              • nottorp 2 months ago
                                                                Judging by the OP's profile, we should be happy that the "AI" managed to recognize a number :)
                                                                • deepnet 2 months ago
                                                                  I am not an LLM [edit] ( as far as I know ;-), but thanks for the profile crit I probably should tidy it up.
                                                            • 2 months ago
                                                              • t0lo 2 months ago
                                                                how did this become popular in the first place? was it this user? was it a plant on reddit if it was a scam?
                                                                • pseudo0 2 months ago
                                                                  Archive, since the site appears to be down. It's AI-generated slop with basically no informational value though.

                                                                  https://archive.ph/2C1WB

                                                                  • gwill 2 months ago
                                                                    anyone have an alternate link?
                                                                  • fastglass 2 months ago
                                                                    am I just being a newb or is OP god-tier with their WPM?

                                                                    I really despise these things where its a drop n run, and all these yahoos in the comments just talk oblivious towards the fact that person who submitted it remains silent about it..

                                                                    like... this looks like a sweaty guessing game with everyone in the comments, especially over something that's very likely just troubled/plagued assets to begin with

                                                                    like, just ask the dude who submitted the shit about more information first or something

                                                                    • gigatexal 2 months ago
                                                                      I wish they’d leak Trump’s grades from college. And his associates’s trades around his tariff announcements, and all the things.
                                                                      • constantcrying 2 months ago
                                                                        https://archive.ph/8RGAb here is the other reporting from the website. How high would you rate their faith that they accurately reported in this case?
                                                                        • gigatexal 2 months ago
                                                                          The they here I meant was anonymous not this random site.
                                                                      • thowaway7564902 2 months ago
                                                                        CAREFUL - it could very well be an attempt to get you to download malware.

                                                                        - As pointed out by constantcrying, this was published by Trendsnewsline, "an Indian right wing conspiracy news website": https://archive.ph/8RGAb

                                                                        - New account Sonnigeszeug encouraging downloading of the archive

                                                                        I'd recommend you avoid downloading anything unless you understand the potential consequences. Ideally do so in a sandboxed environment.