The Rest Is Classified

131. How Russia Made Trump: Stealing Washington’s Secrets (Ep 2)

72 snips
Feb 25, 2026
A deep dive into Russia's hack-and-leak tactics and how active measures use the internet to amplify influence. A look at GRU history, Unit 26165 and notorious APT groups like Fancy Bear and Cozy Bear. Tales of spearphishing campaigns, the Podesta phish, X-Agent malware and how Ukraine served as a testing ground for later operations.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes

Active Measures Went Digital With Hack And Leak

  • Russia reused Cold War active measures but the internet made them far faster and easier to disseminate.
  • The GRU led a 2016 hack-and-leak approach combining theft (hack) with targeted public dissemination (leak) to influence politics.

GRU Showed Up Loud While SVR Stayed Quiet

  • The GRU developed noisy, aggressive cyber units (e.g., Fancy Bear/APT28) distinct from quieter SVR hackers (Cozy Bear/APT29).
  • GRU favored disruptive operations and sabotage, tested earlier in Ukraine before targeting Western politics.

Ukraine Hack Tried To Fake Election Results

  • In May–June 2014 the GRU penetrated Ukraine's Electoral Commission and attempted to alter vote tallies.
  • The malware aimed to fake election results and Russian TV prepared to broadcast the manipulated outcome.
Get the Snipd Podcast app to discover more snips from this episode
Get the app