DC Leaks was a false hacktivist leak persona used in the 2016 Russian influence campaign to publish and amplify stolen documents while obscuring the role of the underlying operators. It is associated with the broader activity cluster tied to Russia’s GRU and closely linked in reporting to APT28, also known as Fancy Bear. The persona operated through a dedicated leak website and affiliated social media accounts to disseminate material taken from U.S. political organizations, including documents stolen from the Democratic National Committee and the Democratic Congressional Campaign Committee. DC Leaks formed part of a broader pattern in which intrusions, credential theft, and data collection were followed by strategic public release of stolen information to shape political narratives and support influence operations. Reporting has linked the collection side of these operations to APT28 tradecraft, including spearphishing, OAuth-based credential theft designed to bypass two-factor authentication, use of zero-day exploits, and lateral movement using legitimate administrative tools. While investigators linked the theft activity to APT28 with high confidence, some reporting noted that direct operational control of individual leak personas could not always be conclusively established. DC Leaks is best understood as an influence-enabling front used to launder and publicize stolen data in support of Russian state objectives rather than as an independent hacktivist entity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Leak persona/site used to publish stolen correspondence from political targets; discussed as part of the persona ecosystem around APT28-linked intrusions.
A GRU-operated leak platform and associated personas used to publish and promote stolen political documents while masquerading as an independent transparency outlet.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.