HBGary's high-volume astroturfing technology and the Feds who requested it

The enormous corpus of email leaked from federal security contractor HB Gary following Anonymous's hacking of the company's servers continues to deliver compromising payloads.

This time, it's internal emails detailing the creation of "persona management" software to simplify the process of pretending to be several people at once online, in order simulate widespread support for a point of view — astroturfing automation software. The software appears to have been developed in response to a federal government solicitation seeking automated tools for astroturfing message boards in foreign countries.

Persona management entails not just the deconfliction of persona artifacts such as names, email addresses, landing pages, and associated content. It also requires providing the human actors technology that takes the decision process out of the loop when using a specific persona. For this purpose we custom developed either virtual machines or thumb drives for each persona. This allowed the human actor to open a virtual machine or thumb drive with an associated persona and have all the appropriate email accounts, associations, web pages, social media accounts, etc. pre-established and configured with visual cues to remind the actor which persona he/she is using so as not to accidentally cross-contaminate personas during use…

To build this capability we will create a set of personas on twitter,‭ ‪blogs,‭ ‪forums,‭ ‪buzz,‭ ‪and myspace under created names that fit the profile‭ (‪satellitejockey,‭ ‪hack3rman,‭ ‪etc‭)‪.‭ ‪These accounts are maintained and updated automatically through RSS feeds,‭ ‪retweets,‭ ‪and linking together social media commenting between platforms.‭ ‪With a pool of these accounts to choose from,‭ ‪once you have a real name persona you create a Facebook and LinkedIn account using the given name,‭ ‪lock those accounts down and link these accounts to a selected‭ ‪#‭ ‪of previously created social media accounts,‭ ‪automatically pre-aging the real accounts…

Using the assigned social media accounts we can automate the posting of content that is relevant to the persona. In this case there are specific social media strategy website RSS feeds we can subscribe to and then repost content on twitter with the appropriate hashtags. In fact using hashtags and gaming some location based check-in services we can make it appear as if a persona was actually at a conference and introduce himself/herself to key individuals as part of the exercise, as one example. There are a variety of social media tricks we can use to add a level of realness to all fictitious personas

UPDATED: The HB Gary Email That Should Concern Us All

(via MeFi)

(Image: Shadows and Gold, a Creative Commons Attribution (2.0) image from kevandotorg's photostream)