Iran’s Mint Sandstorm, are you a Victim?

So, a senior official in the Trump campaign was the victim of an email phishing trick and it worked….countless emails were hacked/stolen and began to be distributed. Microsoft has confirmed this and several Iranian cyber signatures from previous hack are providing some pretty good attributions to Iran as the hackers. But no worries, the FBI, likely the Pittsburgh office as agreed t investigate.

Just last night after some recent promoting the SPACES event hosted by Donald Trump and Elon Musk was delayed for an estimated 45 minutes due to a DDOS hit. Again, that too had the signature tactics of Iran. Mint Sandstorm Campaign's Targeted Cyber Attacks on Middle Eastern Experts source

Per CSOOnline in part:

The hackers allegedly obtained sensitive data as a result of a successful phishing campaign against Trump officials. Cheung cited the Microsoft report which said in June 2024, Mint Sandstorm, a group run by the Islamic Revolutionary Guards Corp (IRGC) intelligence unit, sent a spear-phishing email to a high-ranking official of a presidential campaign from a compromised email account of a former senior advisor.

“On Friday, a new report from Microsoft found that Iranian hackers broke into the account of a ‘high ranking official’ on the US presidential campaign in June 2024, which coincides with the close timing of President Trump’s selection of a vice-presidential nominee,” Cheung added. More here.

In part:

Threat actor Mint Sandstorm, believed to be linked to Iran, has been observed using bespoke phishing lures to attack high-profile targets while leveraging a new custom backdoor called MediaPI.

In a Jan. 17 blog post, Microsoft Threat Intelligence said the attacks were on individuals working at a high level on Middle Eastern affairs at universities and research organizations in Belgium, France, Gaza, Israel, the United Kingdom, and the United States.

The Microsoft researchers said Mint Sandstorm — also known as APT35 and APT42 — used legitimate, yet compromised accounts to send phishing lures. The researchers said Mint Sandstorm continues to improve and modify the tooling used in targets’ environments, activity that might help the group persist in a compromised environment and better evade detection.

“Based on the identities of the targets observed in this campaign and the use of lures related to the Israel-Hamas war, it’s possible this campaign is an attempt to gather perspectives on events related to the war from individuals across the ideological spectrum,” wrote the researchers.

Mint Sandstorm operates as a state-sponsored actor from Iran and, as a result, serves government agency and potential military objectives, explained Balazs Greksza, threat response lead at Ontinue. Greksza said the group employs tactics such as watering hole attacks and phishing emails, to target governments, NGOs, private entities, and academia for espionage. They often pose as journalists, government officials, or academics on social media and their primary objective is to get hold of sensitive information.

“Actors like APT35 have primary goals around geopolitics, national security, counter-intelligence,” said Greksza. “As openly shared by different intelligence agencies in the past, intelligence goals may shift rapidly based on the needs of national interests, current political and military leadership and their decision and intelligence needs.”

Ngoc Bui, cybersecurity expert at Menlo Security, added that the deployment of the custom backdoor MediaPI, along with the use of other tools like MischiefTut, indicates a shift in the operational tactics of Mint Sandstorm, marking an evolution in their cyber espionage capabilities.

***

This all begs the question, just exactly what is being done to not only protect a political campaign and election, but every website or American out there from Iran, Russia, China or North Korea and their team of hackers?

CSOOnline goes on to read –>

Iran, found extremely capable in the past of conducting cyberattacks against its foes in the Middle East, earlier in 2022 had threatened to avenge the killing of General Qassem Soleimani by the United States in a drone strike ordered by the Trump administration.

During this time, among many other efforts, Mandiant reported that the news site EvenPolitics, a Tehran-controlled disinformation site, had published articles covering the 2022 US midterm elections. An inauthentic amplification network promoting the site was taken down by the X platform that same year, yet EvenPolitics continues to operate, releasing approximately ten articles per week.

Microsoft, in its report, added that Iranian cyber-enabled influence operations “have been a consistent feature of at least the last three US election cycles”.

Iran’s mission to the United Nations, in response to inquiries about the Trump campaign’s allegations, denied any involvement. Speaking to The Associated Press, the mission stated, “We dismiss these reports entirely. The Iranian government has neither the capability nor the intention to interfere in the United States presidential election.”

Have you Met John Mark Dougan, a Former Florida Deputy Sheriff?

I continue to see friends on Facebook and a few other social media sites claiming that Ukraine’s President Zelensky and his wife are using millions if not billions of U.S. aid money to buy fancy cars and mansions….ehhh….c’mon people do that work please and stop getting punked by a former Marine and sheriff deputy from Florida that too fled to Russia….yes…fled and he is loving his deep fake life there and you are helping him win the bot/disinformation/propaganda war…and many members of Congress have bought into all this….but save yourself the humiliation and read on…

***

It is not just here in the United States by the way…Europe is getting pummeled too:

The article looks real enough, though petrolheads may note the misspelling of Tourbillon. It even cites as evidence a video recorded by a dealership employee describing the supposed sale, and a picture of a Bugatti invoice for €4.5 million made out to Mrs. Olena Zelenska. If you were under any doubt, the site’s name should lay your fears to rest: Verite Cachee or, in English, hidden truth.

In fact, the video is a deepfake, the invoice is falsified, and the entire site is part of a Kremlin-linked influence operation, using AI-generated content to deliver a payload of Russian talking points. The false attack on Zelenska was designed, it seems, to hint at corruption.

Veritecachee.fr is one of two sites set up less than two weeks after French president Emmanuel Macron announced a surprise election, the other called France en Colere (Angry France). The Bureau of Investigative Journalism (TBIJ) and the Tow Center have connected both to a network of websites linked to John Dougan, an American former police officer now living in Moscow and known for spreading Kremlin-backed disinformation. This network was first identified by researchers at Clemson University in December last year.

Even as this Dougan-affiliated network has targeted the French election, another Russia-linked disinformation operation, unmasked by French authorities earlier this year, has ramped up its activity in Europe. In June, the “Portal Kombat” network launched ten new sites, mostly aimed at Europe. Another five targeting Eastern Europe were set up in April and May. Read it all here for further context. Zelensky just bought a brand new $4.5 Million Dollar Bugatti for his ...

*** In part below:

It starts with a NewsGuard analyst happening upon what appeared to be a fledgling Washington D.C.-based news site promoting Russian propaganda. Unbeknownst to her, this was six months after her boss and his family had been threatened in a YouTube video that included an aerial shot of his home and calls to his unlisted phone number by a Russian disinformation operative working from a studio in Moscow. It turns out that this D.C. website, those threats to NewsGuard’s co-CEO, and what NewsGuard discovered were dozens of similar hostile information operations — including a “documentary” that the Russians used as an excuse to invade Ukraine — were all orchestrated by the same man — John Mark Dougan, a former Florida deputy sheriff who fled to Moscow after being investigated for computer hacking and extortion.

As of this writing, NewsGuard has discovered 167 Russian disinformation websites that appear to be part of Dougan’s network of websites masquerading as independent local news publishers in the U.S. and 15 films on Dougan’s since-removed YouTube channel. Ranging from Ukrainian President Volodymyr Zelensky siphoning off money meant to aid the war against Russia so he could buy an estate in England owned by King Charles, to a non-existent U.S. bioweapons lab in Ukraine being the reason the Russians had to invade that country, these concocted stories have been amplified on social media accounts to reach a broad global audience of more than 37 million views—including 1,300,000 views of just the narrative about Zelensky buying the king’s estate.

As a journalist based in Washington who scrutinizes the credibility of news outlets as a profession, I was familiar with the landscape of trusted local publications in the area. DCWeekly did not appear to be one of them.

I first noticed the site when it published an article reporting that the Ukrainian Azov Battalion was recruiting in France. It carried the byline “Jessica Devlin,” who was described as a “distinguished and highly acclaimed journalist.” Another scoop: The U.S. had bought a mansion for Ukrainian President Volodymyr Zelensky in Vero Beach, Florida.

Everything about the website and these articles was a red flag: The site presented itself as a credible new local news source yet was propagating fabricated narratives that smelled of Russian influence.

It turned out that “DCWeekly” is not actually based in the nation’s capital. Nor is “Jessica Delvin” a real person. As uncovered by researchers at Clemson University, the site operates from Moscow, hosted on an IP address belonging to John Mark Dougan.

His is a name I would come to know well over the coming months.

In further briefings, I learned that Dougan, a former marine, had been an officer in the Sheriff’s Department in Palm Beach County, Florida, until 2016, when he fled to Russia and was granted asylum after being targeted in a computer hacking scheme. Since then, I was told, he had become well known to the FBI and, as they put it, “our sister security agencies” as a Russian operative who specialized in producing some of the Russians’ most elaborate disinformation campaigns and narrating them as if he were an independent American journalist. 

Relatedly, it appeared that the aerial video of my home in Dougan’s video was not a simple Google satellite shot. Instead, it had probably been taken by a drone that someone had hired. [Dougan denies this; see below.] I was also told that those same sister agencies reported that Dougan was still in Russia. “So he poses no imminent threat to you,” the lead agent on the case said.

But he knows where I live and the Russians must have people all over the United States, I said. And he must have followers here on his YouTube channel that could act on their own. The FBI agents agreed. This was more serious than a few random crank emails. In a meeting a few days later with three agents and my wife sitting at our dining room table, we agreed on a multifaceted security plan to be implemented by a private security company.

I now live in a home surrounded by twelve motion-detecting security cameras, monitored remotely by the security service, and filled with dead-bolt window and door locks and other reminders of Dougan’s video—which produced multiple new death threats.

***

Related reading from the BBC 

Will the Biden Family Split $200 Million?

As a result of the devastating debate performance of Joe Biden, calls are being made by donors, some Democrat lawmakers and especially donors for Joe to drop out of the race….but c’mon Conservatives…we need him to stay on the ticket and in the race…why you ask? He is the easiest to beat now and there is the matter of $200 million…but I will get to that shortly…so follow along.

Kevin Morris has been Hunter’s sugar-daddy for quite some time as he has paid IRS debts for Hunter along with legal bills. He has even shown up in public and in hearings with Hunter and his lawyer Abbe Lowell. But allegedly, Kevin has stopped the gravy train. It is also a fact that Joe Biden took out a loan by re-financing their Delaware home (35 times per Yahoo News) . So, it is apparent the family needs some money now and certainly in the future.

Just consider that Jill and Hunter and the rest of the world for that matter including White House staffers and the media that Joe has no physical or mental stamina for the job now or for four more years…but the plots begins here…

U.S. President Joe Biden is accompanied by his son, Hunter Biden, and ...

Hunter was with the whole family at Camp David over the weekend plotting and finding blame for his awful job at the debate…furthermore, Hunter is at the White House on a full time basis leading the charge…but what charge? I say…he is so good at creating shell companies that he likely has created several more recently and they are on paper only providing services to the re-election campaign but in reality they are paying themselves through the shell companies from the $200 million in the campaign war chest.

You see, campaign finance law says that money CANNOT be transferred to another candidate…but only to Kamala if she stays on the ticket and only if Kamala becomes the nominee. That is a bug but as no one is calling for her to step up and replace Joe….so that $200 million stays with Joe…and this family could be purposely throwing his re-election for the sake of the money. Sure it is now said that Jill and Hunter are running the operation and in some cases even the White House…but running the presidency or the scheme is the question.

The whole family needs money and lots of it…and could need even more based on continuing investigations by the House into the crime operations…

The Democrat Party is in a real mess and it could get worse when the donors completely bail out from now to the convention, after all it is quite expensive to pay for a convention in Chicago and outside money is required for that in addition to DNC money.

Do we really want the Biden crime family to ride into the sunset splitting $200 million or even $100 million after learning what he have so far about them and then living through hell for the last 3.5 years?

The legal issues for Hunter are not over yet by a long shot and for that matter neither is the investigation into the whole Biden crime family…now including with the Securities and Exchange Commission given the cunning tactics of secret shell companies already, it stands to reason to do it again. The big question here is what state would they register these companies and in what names and who would be the agent of record?

Maybe a deeper dive into that pesky laptop with offer some new things to search for and some new clues…maybe someone can reach out to the James Comer and given him a heads up on something new to look for. The media likely wont do it but given how angry they are perhaps some will….

But dear readers…you all are very good at research…jump in with comments and even trails following that money.

 

 

What the Deep State Really is, Shadow Operatives

Former President Trump has said often, it is not just me they are after, they are really after you and I am in the way. It is quite true, but add intrepid investigative journalists as well and it all began under the Obama administration.

Anyone remember when the Obama Department of Justice went after several Associated Press reporters? Or how about all the way to the Biden administration as noted here:

WASHINGTON (AP) — The Justice Department said Saturday that it no longer will secretly obtain reporters’ records during leak investigations, a policy shift that abandons a practice decried by news organizations and press freedom groups.

The reversal follows a pledge last month by President Joe Biden, who said it was “simply, simply wrong” to seize journalists’ records and that he would not permit the Justice Department to continue the practice. Though Biden’s comments in an interview were not immediately accompanied by any change in policy, a pair of statements from the White House and Justice Department on Saturday signaled an official turnabout from an investigative tactic that has persisted for years.

Democratic and Republican administrations alike have used subpoenas and court orders to obtain journalists’ records in an effort to identify sources who have revealed classified information. But the practice had received renewed scrutiny over the past month as Justice Department officials alerted reporters at three news organizations — The Washington Post, CNN and The New York Times — that their phone records had been obtained in the final year of the Trump administration.

The latest revelation came Friday night when the Times reported the existence of a gag order that had barred the newspaper from revealing a secret court fight over efforts to obtain the email records of four reporters. That tussle had begun during the Trump administration but had persisted under the Biden Justice Department, which ultimately moved to withdraw the gag order.

Let’s go back to the days of Fast and Furious or Benghazi shall we? Just in the last week, former CBS investigative correspondent of 21 years Sharyl Attkisson gave an detailed update to her case against the Department of Justice and the FBI as initially explained in her book titled Stonewalled.

In full disclosure, I read that book back and the chill still runs through my veins. After listening to her most recent podcast explanation, the takeaway is how all of government is still being used to stonewall the case not only with her but now too Catherine Herridge, just recently fired from CBS for refusing to reveal her sources for a story. so much for a free press. So, please take the time to hear the Attkisson podcast to fully grasp the government dragnet and then understand how it all flows down to we the people…..including we the people.

Now consider just what these deep state ghost operatives have been plotting and planning going forward. Use your imagination as Miss Sharyl has provided the mission template and tactics.

We are now living in a Stasi environment an additional form of terror…the war on information and truth.

The Free Palestine Movement Never Mentions Mohammed Salameh

Has anyone asked Rashida Tlaib, the Palestinian congresswoman from Michigan about Mohammed Salameh and his prison sentence? Who is he and what did he do you ask…. well the first World Trade Center bombing was caused by massive explosives inside a van in the parking garage and Salameh…rented that van. He was later arrested after he reported the van stolen and wanted his cash deposit of $400.00 refunded….ah HAH!

He entered the United States on a six-month tourist visa in 1988 but then overstayed. He was still in the country illegally in 1993 during the World Trade Center bombing. He applied for an immigration amnesty under a 1986 law that set up the Special Agricultural Worker program despite never having been eligible. However, he was still guaranteed work authorization.

World Trade Center Bombing 1993 — FBI

Salameh’s 1978 Chevy Nova was used to ferry the nitric acid and urea used to construct the bomb used in the past 1993 bombing.

Despite failing his driving test four times, Salameh had been the driver for the group. On January 24, 1993, he jumped a curb and tore the undercarriage from his car, injuring himself and Ramzi Yousef. He was checked out of Rahway Hospital the following day and went to the garage to clean his car while Yousef remained in the hospital for four more days.[3]

With his Nova in for repairs, Salameh got Nidal Ayyad to use his corporate account with Allied Signal to rent him a new car. However, he got in a car accident again on February 16 and collided with a car.

***Parole Board Votes to Release RFK Assassin Sirhan Sirhan

Then there is Sirhan Sirhan…remember him? He killed Robert Kennedy, at the time he was a presidential candidate. The Jordanian Palestinian was in fact paroled and George Gascon refused to oppose his release but Governonr Gavin Newsom eventually blocked the release of Sirhan in 2022 and he was again denied parole in 2023.  Sirhan was born in ‘mandatory Palestine’ of the West Bank and later became a citizen of Jordan. His family immigrated to te United States when he was 12 years old. He never became a U.S. citizen.

***

Now at issue is President Biden is considering issuing visas to Palestinians in Gaza that have family members in the United States. Discussions are in fact underway and include those who are legal permanent residents in the U.S. become U.S. citizens. It is notable that no country in the Middle East especially Jordan or Egypt want any Palestinians. Biden’s mission is to use a tool called DED, deferred enforced departure. Those Palestinians already i the United States that are under threat of deportation for various reasons have deferral under his executive order for at least 18 months.

One has to ask if those pro-Palestinians or in fact are Palestinians that have been arrested for the threats and protests on college campuses are protected under the Biden DED program.