top of page

OMG, WTF and the rest

  • Writer: RFERL Watch
    RFERL Watch
  • Apr 8, 2023
  • 7 min read

Updated: Apr 9, 2023

Three letters that often say everything. They are often synonymous with mystery, the unknown, power and emotions. They influence our being and non-being worldwide, they help us with a shorthand and without a long speech to express who is who and where they belong. And if we accidentally get involved with one of them, it will be important what time we live in, and most importantly - which side we are on.



Radio ГA / ГA, better said its version 0.0, was born during the Cold War. The "USA" stood at his cradle, more precisely its "MFA" and the all-powerful "CIA" assisted in the birth. In the birth certificate there was written the place of birth Munich, "BRD", or "NSR".


As in any respectable family, there were also various affairs there. During puberty, in May 1965, it was the affair of "PSB" captain Andrzej Czechowicz, and in 1969, the 7-year affair of "STB" captain Pavel Minařík. To this day, I still remember the nursery rhyme and jokes from those times, in which this his heroic act was described as - "Thank you very much for the dollars, I'm Pavel Minařík!". And there have also been several attempted assassinations, kidnappings and intimidation - by those with whom we were friends and whom we even applauded for that. Whether they were friends from "KGB", "Stasi", from "Jackal" or from "Securitate". Attempts at cyanide poisoning in a salt shaker in the canteen, or obtaining information from eavesdropping through it, these events are particularly well-known. It was just such a cool place where the agents of all the great powers, together with the agents of their satellites, visibly met and harmed each other. It was a strange time...


But times have changed, our friends "forever and ever" are now our arch-enemies, and heartless enemies have become our best friends. As time went on, funding from the "CIA" jumped and money began to flow from the "USC" (US Congress) and other sources. In its best years, it changed its permanent residence from Munich to Prague, then it also changed its logo "image" from a bell to a religiously neutral torch, and in 2021 it celebrated a beautiful 70 years here in good health.


But its mission remained unchanged. He no longer fears the use of jammers, does not have to release promotional balloons with leaflets, or drop radio receivers from helicopters. Truths, falsehoods and the "right opinions" can be spread much more effectively - via satellites, the Internet, spending money from anyone in role of modern preachers.


Holt, the form of "the one with the horse's leg" propaganda has changed a lot. But has the content changed?

Only the sides have changed.


Sometimes someone somewhere shut him down, or someone with a different opinion blocked someone's website. And when it got too bad, just like in its younger days, they tried to hire there.


USAGM as its founder has warned them several times that they are not doing well if they do not deal with IT security. As they wrote to them here via "GOVERNMENTATTIC.ORG" which published reports between 2017-2019 monthly and they informed here on 3.7.2018 that Russian Hacker group "STRONTIUM (known as "APT28", "Fancy Bear", "Pawn Storm", or "Sofacy Group"), subordinated to "GRU, has registered and took ownership of their official "rferl-mysharepoint.com" Microsoft domain and is trying to spoof their official web site.


Their friends-agents are known even in our "pools and groves" - as the organizers and executors of the attack on the ammunition warehouse in Vrbětice in 2014.

Even Microsoft was not idle and tried its customers (also Radio ГA / ГA as well) to point on the activities of this hacking group here and since I had the opportunity to meet them "face to face", I can only confirm truthfulness of all the facts there.


Even though I don't really love this company, they published very interesting data in their study pricing information for "hacking" according to the type of attack used:


  • Identity theft and phishing attacks are cheap, but their price has been rising lately

  • DDoS attack (website flooding with queries) on unsecured sites is cheap and costs around $300 per month

  • Extortion attacks, of which there are many types, are conducted using ready-made tools that allow even average attackers to earn big money



I don't think these information about the average prices for a cybercrime service need to be translated. With a price of $250 for a specific task, or with a price of $100 to $1000 for a successful identity theft? On the other hand, not quite a "buck" for selling 1000 login names and passwords seems quite a bit, don't you think?


But Radio ГA / ГA did not listen and "beat" this "bad guys" group through the keyboard and the website of its American journalist. Thanks to this published information, it is not surprising that all those activities were as a "red rag" to them, and thus he was the first in the chain who indirectly started the whole action with my dismissal.


Some of his articles from previous years are here, here, here, or perhaps here. Another taster with information about the "STRONTIUM" group from its site just before the phishing attack is also here and here.


The fact that the incident at Radio ГA / ГA on 07.10.2019 occurred with the active contribution of the hacker group "STRONTIUM" it can be read in the statement of #JS ("Joints Smoker"), which he made at police station in November 2019 and under oath. It is interesting that this statement did not appear in the court file and the lawyer #MV ("Mgr. Prasátko") did not introduce it to the court at all.



A possible reason is offered - I officially blocked this account on 26/11/2019 in the afternoon, and if this incident was known to Radio ГА / ГA already on 25/11/2019 and its technicians were already investigating the details of it before that day, it could be said with a high probability that indeed my supervisor #RC ("Remotely controlled"), who blamed this whole incident on me, really knew about it earlier (as I claimed in court), and most importantly - he did not act. This would make his so-called sworn statement with further other date manipulations appeared there, they all were quite implausible for the "independent" judge #JH ("Dr. Hustá").

 

So briefly how it happened.


On October 7, 2019, hackers attacked the journalist's account and successfully carried out a phishing attack on him twice. At this time, I successfully tested a special anti-phishing software that used elements of artificial intelligence to analyze attacks and was supposed to prevent similar events. When configuring it, I was warned by the supplier that I will wonder what is happening in our systems.


And they were not wrong.


In the course of testing, reports of stolen identities began to appear, some true, some false. Holt, the system gradually learned from the environment and started offering the first recommendations. And so it happened that while manipulating this hacked account, the identity of my personal account and also of the global administrator were stolen, which was revealed by the tested software. Such suspected activities did not fail me about 144 times before, as stated by the legal puritans at Radio ГA / ГA.


Into the silence of our "open space" office, my unforgettable words were heard at the time: “OMG! WTF?”. The same as the biblical one, also appeared here - "in the beginning was the word...".

In 16 minutes, according to an extract from the verifiable protocols, "in about an hour", as my superhuman #RC ("Remotely Controlled") claimed under oath, I was automatically prompted by the system to perform procedures, among which changing the password was a crucial point solving this problem. When logging in, I had no idea that the bad Russian guys had installed the malicious program "Evilginx" on the "carrotsoft" page two days before, which "intercepted" communications and even bypassed my two-phase authentication in the "authenticator" application on my mobile by using the "man in the middle" technique .


For all those who believe that "man in the middle" is the use of some ticklish sexual position derived from the Swedish threesome, here is a short explanatory video here. Similar to this video, in my case it was an "Evilginx" hack, except that the link was redirected to a stolen Microsoft O365 site, used in their cloud for other users to test, which is why I initially assumed that site as legitimate.


If I hadn't tested this software and had it almost ready to deploy, I probably wouldn't have learned, like "Janush" in the video, that my identity had been stolen. But as soon as the system evaluated it, it gradually guided me through pre-prepared procedures to save my "butt". The crucial thing was, as the software advised me, to immediately change the password for this account, which I did immediately. Anyway, the bad guy meantime has created a clone of me, almost indistinguishable from another real user, and after a short tug of war over access to the system, he finally gave up to attempt to use on my own account.


I had the feeling that I had won. I had my lost identity back after all! But they knew for sure that it was not true.
 

And so a foreign student appeared in Radio ГA / ГA. He had a good preparation from the "GRU" and "FSB" and learned quickly with us. Very soon he exceeded my knowledge, obtained only from the Google search web site. I know, I'm making it difficult again - "there was no money for your training, comrade", I thought aptly.


And so, with the help of another colleague of mine, I discovered and ignominiously blocked him on 26/11/2019. My American action hero #RC ("Remotely Controlled"), who supposedly discovered it hours earlier, didn't block the account and instead ran away from work to hide in the subway. Here he was waiting for me to do it. In his version of the investigative file, which I have never seen and which was then used in my deposition, he identified himself as the one who discovered the account. He discovered and did not act, that is what I told him in our last private conversation.


He laughed at me and with the confidence of a superman replied with an ironic smile - "no one will believe you anyway, I have all the evidence".

Now it actually occurs to me - why was the bad boy interested in his account right after the account of the highest in the food chain Radio ГA / ГA? Suspicious coincidence, don't you think?


Just like then, this time I didn't hide my emotions.


OMG! WTF?


For those 46 days, as the self-proclaimed IT specialists of Radio ГA / ГA #MV ("Dr. Prasátko") and #JH ("Dr. Hustá") emphasised in court, I allegedly let him do harm here and only changed password. Even #MV ("Mgr. Prasátko") had a flaming rant about the doorman, the key, and locking the entrance after inviting bad guy in! Simply, Jožka Urválek was "cowboy" compared to him.


Three letters that often say everything. They influence our being and non-being worldwide, they help us to express who is who and who belongs where in short and without long words. They changed my life, especially my professional life. But I didn't mess with any of those three letters and I still stayed on the right side.

 

But how long will my conviction last?


And anyway, which side is actually the right one?

Comments


bottom of page