A 2025 darknet leak indicates that Okenit developed “Lemmings,” a Python-based system for manufacturing and managing synthetic online personae, complete with account creation, verification, phone and email acquisition, proxies, and browser automation. The leak suggests this tooling could support future Russian influence operations at scale, with related components named SOI and SOS helping concealment, tasking, and collection. #Lemmings #Okenit #SVR #InternetResearchAgency
Keypoints
- Lemmings is a Python program leaked from Okenit that automates creation and management of fake online identities.
- The tool handles account registration, verification, session persistence, phone-number acquisition, email management, proxies, CAPTCHA solving, and browser automation.
- Leak metadata points to Okenit in St. Petersburg as the developer, with internal GitLab paths and corporate email evidence supporting attribution.
- The system appears designed as an identity-and-access layer within a larger ecosystem that includes SOI and SOS.
- Evidence from the leak suggests Lemmings was tested against real services such as VK, Reddit, Telegram, LinkedIn, X, and Facebook.
- The framework uses synthetic biographies, generated avatars, and location-aware proxying to make accounts look credible and durable.
- Analysts assess Lemmings as a potential next-generation troll-farming platform that could enable large-scale Russian disinformation operations with fewer operators.
MITRE Techniques
- [T1585.001] Establish Accounts: Social Media Accounts – Lemmings automates the creation of accounts on target platforms to build synthetic personas. (‘create online presences through account creation’)
- [T1587.001] Develop Capabilities: Malware – The leak describes a custom Python program built internally by Okenit to support persona operations. (‘a specific program set, written in Python, that is named “Lemmings”’)
- [T1585.002] Acquire Infrastructure: Domains – The tooling uses internal infrastructure and staged external mirrors to support its workflow. (‘gitlab.lan/filigree/lemmings’)
- [T1589.001] Gather Victim Identity Information: Social Media – The system constructs plausible identities using names, avatars, and profile details. (‘uses Faker-generated names and aligns sex, age, and date of birth with avatar selection’)
- [T1583.003] Acquire Infrastructure: Virtual Private Server – The platform relies on rented phone numbers, proxies, and related services as supporting infrastructure. (‘uses rented telephone numbers, SMS verification, email accounts, proxies’)
- [T1090.001] Proxy: Internal Proxy – Lemmings routes activity through HTTP(S), SOCKS4, SOCKS5, chained, and authenticated proxies to conceal origin. (‘supports multiple HTTP(S), SOCKS4, and SOCKS5 proxies and includes chained and authenticated proxies’)
- [T1027] Obfuscated Files or Information – The ecosystem is designed to hide campaigns and reduce detection by targeted platforms. (‘allow the campaigns to be obfuscated enough to bypass the security of the targeted social media sites’)
- [T1110.001] Brute Force: Password Guessing – The article notes automated verification and repeated login handling to maintain access to accounts. (‘handles … password problems by retrying with replacement resources’)
- [T1497.001] Virtualization/Sandbox Evasion: System Checks – The browser workflow removes obvious automation artifacts to avoid detection. (‘removal of obvious Selenium artifacts are used to reduce automation signals’)
- [T1078] Valid Accounts – The framework preserves cookies, tokens, credentials, and session data for reused authenticated access. (‘preserves credentials, cookies, tokens, and session data so accounts can be maintained and handed off for later use’)
- [T1219] Remote Access Software – Lemmings uses browser automation and Telethon/API credentials to operate accounts and scrape services. (‘uses Telethon, persistent StringSession data, and API credentials for scraping groups and bots’)
Indicators of Compromise
- [Domains/Hosts ] internal development and package references – gitlab.lan, info@okenit[.]ru, and other internal service names
- [Repository Paths ] internal source-control locations – gitlab.lan/filigree/lemmings, filigree, and Altar
- [Email Addresses ] project authorship and corporate attribution – info@okenit[.]ru, okenit developers info@okenit[.]ru
- [IP Networks ] internal/private development networks referenced in configs – several RFC1918 addresses, and other private ranges
- [Account/Usernames ] leaked test or persona accounts used in testing – CompetitiveRope5669, Academic-Wolverine35, Michael Schmidt, Amanda Frazier, Jennifer Watkins
- [Platform Identifiers ] live social-platform account IDs tied to test personas – VK user ID 599946564, 661627902, and 661630153
- [Package/Project Names ] software and components from the leak – Lemmings, SOI, SOS, lmgs_mock
Read more: https://dti.domaintools.com/research/lemmings-russian-persona-provisioning