Leak Reveals Russian-Linked Lemmings Tool for Mass Persona Provisioning

· Original article ↗

Summary

A leaked Python framework attributed to Russian firm Okenit automates synthetic persona creation, account verification, and persistent access across platforms. DomainTools found evidence of testing, but not proof of operational use in influence campaigns.

Key points

  • A darknet-forum leak exposed Lemmings code; internal repository references and project metadata link its development to Russian company Okenit, not necessarily directly to the SVR.
  • The framework’s artifacts date to 2020, with testing evidence from 2021–2022 and package maintenance continuing into 2024.
  • Lemmings automates synthetic identity creation and online account registration, using email, rented phone numbers and SMS verification, CAPTCHA handling, and browser or API workflows.
  • It manages proxies, geographic presentation, and browser behaviors to reduce automation signals, while preserving credentials, cookies, and session tokens for continued access or handoff.
  • The analysis places Lemmings alongside SOI concealment and collection components and SOS tasking functions, though their exact operational relationships remain under investigation.
  • Matching VK and Reddit accounts support testing against live services; they do not establish that Lemmings was used in operational influence, intelligence, or collection activities.
  • The framework could enable large-scale influence, collection, or social-engineering operations, but the report does not link it to a specific campaign or confirm deployment.

Article Details

Attack Vectors
  • Automated creation of synthetic social-media identities using consistent biographical data, age- and gender-matched avatars, and controls to limit photograph reuse.
  • Account registration and verification using rented telephone numbers, SMS codes, email accounts, CAPTCHA handling, and browser or API automation.
  • Preservation of credentials, cookies, tokens, and session material to maintain authenticated accounts and support later operator handoff.
  • Geographically aligned proxies, including chained and authenticated proxies, conceal network origins and make account activity consistent with claimed persona locations.
  • Browser fingerprint variation, persistent profiles, cookie seeding, website pre-visiting, and removal of obvious automation artifacts reduce account-registration and authentication detection signals.
  • Authenticated accounts support group and bot scraping and could enable subsequent outreach, social engineering, or influence activity; the article does not establish operational deployment.
Defensive Notes
  • The article recommends further investigation into whether the system entered production, with the goal of developing hunting packages for synthetic-persona activity at scale.
  • Proxy-provider outages and resource replacement can disrupt consistency between account geography, telephone numbers, and network location.
  • Matching live accounts substantiate registration, authentication, and persistence testing, but do not establish subsequent operational influence or intelligence activity.
  • Private development-network addresses cannot independently identify an external operator.

MITRE ATT&CK

People

Threat Actors

Vendors

Products

Tools

Countries

Related Articles