Leak Reveals Russian-Linked Lemmings Tool for Mass Persona Provisioning

Summary
A leaked Python framework attributed to Russian firm Okenit automates synthetic persona creation, account verification, and persistent access across platforms. DomainTools found evidence of testing, but not proof of operational use in influence campaigns.
Key points
- A darknet-forum leak exposed Lemmings code; internal repository references and project metadata link its development to Russian company Okenit, not necessarily directly to the SVR.
- The framework’s artifacts date to 2020, with testing evidence from 2021–2022 and package maintenance continuing into 2024.
- Lemmings automates synthetic identity creation and online account registration, using email, rented phone numbers and SMS verification, CAPTCHA handling, and browser or API workflows.
- It manages proxies, geographic presentation, and browser behaviors to reduce automation signals, while preserving credentials, cookies, and session tokens for continued access or handoff.
- The analysis places Lemmings alongside SOI concealment and collection components and SOS tasking functions, though their exact operational relationships remain under investigation.
- Matching VK and Reddit accounts support testing against live services; they do not establish that Lemmings was used in operational influence, intelligence, or collection activities.
- The framework could enable large-scale influence, collection, or social-engineering operations, but the report does not link it to a specific campaign or confirm deployment.
Article Details
- Attack Vectors
- Automated creation of synthetic social-media identities using consistent biographical data, age- and gender-matched avatars, and controls to limit photograph reuse.
- Account registration and verification using rented telephone numbers, SMS codes, email accounts, CAPTCHA handling, and browser or API automation.
- Preservation of credentials, cookies, tokens, and session material to maintain authenticated accounts and support later operator handoff.
- Geographically aligned proxies, including chained and authenticated proxies, conceal network origins and make account activity consistent with claimed persona locations.
- Browser fingerprint variation, persistent profiles, cookie seeding, website pre-visiting, and removal of obvious automation artifacts reduce account-registration and authentication detection signals.
- Authenticated accounts support group and bot scraping and could enable subsequent outreach, social engineering, or influence activity; the article does not establish operational deployment.
- Defensive Notes
- The article recommends further investigation into whether the system entered production, with the goal of developing hunting packages for synthetic-persona activity at scale.
- Proxy-provider outages and resource replacement can disrupt consistency between account geography, telephone numbers, and network location.
- Matching live accounts substantiate registration, authentication, and persistence testing, but do not establish subsequent operational influence or intelligence activity.
- Private development-network addresses cannot independently identify an external operator.
MITRE ATT&CK
T1090.003 · Multi-hop ProxyLemmings supports chained proxies through its SOI integration to further obscure account-workflow network origins.T1585.001 · Social Media AccountsLemmings automates creation and maintenance of synthetic social-media accounts, including coherent biographies, avatars, verification, and persistent access for later operator use.T1585.002 · Email AccountsLemmings provisions and maintains email accounts that support synthetic-persona registration, verification, recovery, and continued access across platforms.
People
Threat Actors
DoppelgangerDescribed as using fake Western personas, controlled infrastructure, impersonated media properties, and coordinated social-media distribution. Its architecture is compared with Lemmings without establishing a connection.Internet Research AgencyDescribed as operating a Russian troll farm and using personas, proxies, and social-media accounts for active measures. The article also refers to this organization as SDA and IRA; no operational connection to Lemmings is established.IRAUsed by the article as a shortened reference to the Internet Research Agency. Its influence infrastructure is compared with Lemmings, without establishing a connection.okenit_hackersDarkforums account that posted leaked material on October 9, 2025 and claimed to have hacked an SVR server. The article identifies the breached organization as Okenit and does not confirm the claimed SVR ownership.SDAUsed by the article as a parenthetical name for the Internet Research Agency, which operated a Russian troll farm. No operational connection to Lemmings is established.
Vendors
Products
Facebookhistory found in the leak. Lemmings-related test artifacts date back to 2020. These include X and Facebook session material, with additional account, email, and authentication testing continuing through 2021 andLinkedInLinkedIn shows a different but related capability; Lemmings can build foreign-facing professional personas with synthetic occupations and employer identities. It creates complete email and telephone verifications,RedditAcademic-Wolverine Reddit AccountTelegramTelegram provides the clearest evidence that Lemmings was designed to create accounts for later authenticated collections.VKThree VK accounts correspond to identities preserved in the code and test data: Xdevelopment history found in the leak. Lemmings-related test artifacts date back to 2020. These include X and Facebook session material, with additional account, email, and authentication testing continuing through
Tools
Lemmingsof fake personae.The files leaked contained a specific program set, written in Python, that is named “Lemmings” (Лемминги). The program allows an organization or individual to generate and manage personae, as welllmgs_mockcookies, tokens, and session data so accounts can be maintained and handed off for later use. The lmgs_mock python testing framework indicates the system was built and tested as a production-grade accountSeleniumand authenticated proxies for further obfuscation. This allows for switching proxy settings in both Selenium browser sessions and direct requests sessions. Selenium Wirecadence timing, and character-by-character input while using persistent profiles. Meanwhile, Selenium Wire, cookie seeding, and website pre-visiting with removal of obvious Selenium artifacts are used toSOIfunction as the identity and access layer within a larger ecosystem involving other components, including SOI (concealment and routed access) and SOS (tasking and collection management), which enable the campaigns toSOSwithin a larger ecosystem involving other components, including SOI (concealment and routed access) and SOS (tasking and collection management), which enable the campaigns to be obfuscated enough to bypass the
Countries
Russiaof concept. The organization tasked with its creation is Okenit, a company located in St. Petersburg, Russia. Interestingly enough, Okenit is about eleven miles from the Internet Research Agency (SDA) that ran theUnited Statescampaigns after smaller units tied to state organs like the SVR and GRU were exposed and sanctioned by the USA. Using this program and the infrastructure it builds, a few operators could fairly easily carry out large