Remember this name: Activists have identified the author of a phishing campaign targeting anti-war Russians.
Civil activists and developers Alexander Litreev и Artem Tamoyan He also revealed the name of the person maintaining clone websites of the "Freedom of Russia Legion," the "Russian Volunteer Corps," and the Ukrainian website "I Want to Live" (a hotline project for Russian soldiers surrendering). The data of people who clicked on phishing links was leaked to security forces, after which this information went to bed as a basis for criminal cases.
They discovered that the owner of the legionliberty[.]space domain, likely through negligence, had forgotten to delete their contact information—email and phone number. Then Litreev and Tamoyan learned the username and found a YouTube channel of the same name, a GitHub account, a Firefox browser extension developer page, and a Trello profile. The same avatar was used across all platforms. The activists learned the name of the account owner— Alexander Ostaenkov from Yekaterinburg.
They later discovered that the phone number was linked to a birth year of 1999. It was also linked to Ostaenkov's profiles at Sberbank, the DNS store, and the tax service database.
As a result, the activists managed to find Ostaenkov's VKontakte profile. Everything matched: his date of birth, his nickname, and his place of residence in the Sverdlovsk region.
Previously, social anthropologist Alexandra Arkhipova опубликовала material on how she used scientific methods to identify a serial informer Ivan Abaturov (who, by the way, is also from Yekaterinburg), operating under a pseudonym "Anna Korobkova".
Remember: by clicking on suspicious links, you can lose not only money, but also your freedom.

