The Microsoft Click That Hacked Berlin

Roughly 5.8 terabytes left the Landesnetz in five days of August. That is the sound of about 100 megabits per second of sensitive data being sucked out of Berlin. That transfer rate alone is a story, given the Copperhead history of German broadband. The dump went unmeasured. The victim learned its size from the attackers’ index, three weeks after the CERT found the intrusion.

The click.

The TerminalFix lure on linked-log[.]com.
Source: Microsoft Threat Intelligence, 28 August 2026

Attackers landed in a Microsoft product and tricked the user to run a Microsoft-signed binary, using a technique Microsoft had documented in March, and, in the pattern BSI describes, moved the data into Microsoft’s cloud.

This intrusion chain is documented and exactly what properly funded security teams are trained on. Microsoft Threat Intelligence published the tooling on 28 August under the name TerminalFix. The BSI advisory BITS-B 2026-287419-1032 of 4 September, TLP:CLEAR, criticality 2 of 4, reports an August compromise of an unnamed “staatliche Institution” matching that chain, and the BSI’s Mastodon post the same afternoon places the advisory beside its work on the Berlin incident. Tagesspiegel’s reconstruction supplies the victim perspective: just one employee of the transport administration clicked just one link in a phishing email.

Initial access came by drive-by compromise (T1189): a compromised site overlays a fake Cloudflare Turnstile and writes PowerShell to the clipboard. Execution by user (T1204.002, T1059.001): the page instructs Win+X, I, Ctrl+V, Enter, opening Windows Terminal and running the paste. Defence evasion by DLL sideloading (T1574.002): a signed Microsoft binary, LockScreenContentServer.exe, loads a forged dui70.dll from C:\ProgramData. Second stage by steganography (T1027.003): payloads reassembled from PNG pixel data. Persistence by Run key and hourly scheduled task (T1547.001, T1053.005). Discovery by nltest, net group “domain admins”, ADSI queries and a ping sweep of servers named for backup, database and gateway roles (T1482, T1069.002, T1087.002, T1018). Command and control by a Python reverse tunnel over TLS WebSocket to gitnow[.]dev:443 (T1572), launched through pythonw.exe to suppress any console window.

BSI gives us the rest of it, beyond Microsoft’s sample: staging of attacker cloud storage and exfiltration with azcopy (T1567.002), an attempted ransomware deployment (T1486), and the loader itself, LoremIpsumLoader or AxolotLoader, attributed to Vice Spider, the operator of Rhysida.

Dwell time is so far isn’t being discussed. The exfiltration is dated 7 to 12 August; the reconnaissance and tunnel that preceded it are undated in public sources. Detection came on 13 August from an availability ticket, a domain controller fault reported by a third Senate administration, which the ITDZ CERT traced into the two affected houses. Containment followed on 14 August. Reconnection on 23 August. Extortion demand on 28 August. Credential rotation was ordered on 1 September, nineteen days after discovery. Publication on 4 September at 15:35, with a second package containing credentials overnight into 6 September.

The failure to properly fund detection and response, causing failure to scope the breach, is now on the parliamentary record.

On 7 September Digitalstaatssekretär Florian Hauer told the Innenausschuss that until Friday 15:35 the Senate’s knowledge of what had left was the index the attackers had posted, and that the Senate had put the stolen records at a maximum of 215,000 on that basis. The first release ran to about 755,000 files by the LKA’s count, the Saturday night package to a further 550,000 to 560,000; the leak site listing, as reported, comes to 1.44 million. Downloading 6TB from Tor takes days, at least. Triage will be AI-assisted to rank files by risk; Hauer told the committee every file will still be checked individually, so the ranking decides only which of the weeks come first. Hauer’s classification finding so far: everything found carries VS-NfD, the lowest of four levels, and the files that looked at first glance like Militärischer Abschirmdienst material turned out to be parking permits.

To be fair, simple violations by travelers in Berlin, especially riding without a valid BVG ticket, can get fairly militant.

The same afternoon, in the Digitalisierungsausschuss, Baustaatssekretär Alexander Slotty said the question of how and where the attack began remained open, and he was as curious as everyone else. That statement came three days after the BSI advisory and its Mastodon toot. Slotty’s reassurance was that only one percent of the data on the Bauverwaltung’s servers had left, and that systems in both houses remain unencrypted. One percent, by his own figure, runs to over a million files. Being unencrypted matches BSI’s description of a ransomware deployment that was attempted and stopped short of encryption.

From the high-level, the message is that very little of the attack should have worked. Zero vulnerabilities were used. Every stage runs on Windows operations, and that means telemetry that Windows or its default security tools provide a properly funded security team. Microsoft’s own mitigation section is a list of switches. Each attack step below is listed with the control that stops it and the log event.

Stage Control that stops it;
log that records it
Execution Paste into Windows Terminal. Stop: multi-line paste warning (on by default), AppLocker or WDAC denying PowerShell to standard users, Constrained Language Mode. Log: script block logging, Event 4104.
Sideloading Signed LockScreenContentServer.exe loads a forged dui70.dll from C:\ProgramData. Stop: Defender ASR rule on low-prevalence executables. Log: image load outside SystemApps, Defender “unexpected DLL” alert, Sysmon 7.
Persistence HKCU Run key, hourly scheduled task. Stop: task creation restricted by policy. Log: Security 4698, Sysmon 13.
Discovery nltest /domain_trusts, net group “domain admins”, ADSI enumeration, ping sweep. Stop: tiered administration. Log: 4688 with command line, Defender “Possible hands-on-keyboard pre-ransom activity”.
C2 pythonw.exe from C:\ProgramData tunnelling to gitnow.dev:443, TLS unverified. Stop: proxy egress allow-list, block unapproved interpreters. Log: proxy WebSocket upgrade to a .dev domain.
Exfiltration azcopy to attacker Azure storage, terabytes over days. Stop: egress allow-list, DLP on blob endpoints. Log: NetFlow baseline, proxy bytes-out per host.

The detection in three of those rows is decades old.

Decades.

The discovery row is the oldest pre-ransomware signature in the field. A workstation running nltest /domain_trusts and net group “domain admins” /domain is a sure sign an operator has already decided the box is worth more than its data and is measuring the domain for ransom. Sigma rules for these commands have existed since the Ryuk era. Microsoft’s own detection name for the pattern is “Possible hands-on-keyboard pre-ransom activity”.

Berlin politicians cut the funds for classic tooling that raises an alarm. The American firm CrowdStrike arrived after the fact, per Tagesspiegel, as someone’s idea of a German government response, and the district of Lichtenberg has refused to let it onto its servers at all. Hauer called that refusal to rush German data onto an American cloud grossly negligent; Slotty threatened to cut the district from every Fachverfahren of both houses. Four weeks into the response, the Land is negotiating forcing Americans into endpoint visibility with its own districts. Talk about some real incompetence. Clownstrike is like if someone said Coors now would be served instead of German beer at the Senate.

The exfiltration is just old math. 5.8 terabytes across five days is a sustained flow visible on any egress link graph. BSI describes that pattern as attacker-provisioned cloud storage, Azure as the example, filled with azcopy. When a hyperscaler is the target, the proxy allow-list does the job: a Senate workstation writing to a non-approved storage account is an anomaly any properly funded security team alerts on faster than a wasp finds an applesaft in August. A DLP policy on blob endpoints alerts on the first gigabyte. NetFlow shows a bump by the second day. Tagesspiegel’s sources say outflow monitoring is non-existent.

The identity row is documented the most by Tagesspiegel. The Senate administrations ran like it’s 2006, without mandatory password managers or two-factor authentication. The attackers found files named Passwort.txt and a spreadsheet named Zugangsdaten inside the data they took. Once the tunnel was up, the reconnaissance results and those files could expand the attack surface. The affected houses were island networks, kept outside the ITDZ because their systems fell short of its technical minimum standard, and described internally as unreachable for that reason. The domain controller fault that triggered discovery was in a third house. Whatever trust relationship connected them, nltest found it before the CERT did.

The execution row is interesting because it’s unsettled. Windows Terminal warns on multi-line paste by default, and Microsoft lists that warning among its mitigations. Whether the Berlin lure was a single line, or whether the warning was dismissed, hasn’t been explained so far. Either way the control existed, unlike the other areas.

The prior art is so basic it hurts. Microsoft disclosed the Win+X, I variant on 5 March 2026 for a campaign observed in February. BSI’s advisory notes the captcha JavaScript on several hundred websites in historical data.

The lure was five months old when it reached the Landesnetz. The technique it belongs to is older than that. So is the governance: heise reports that the Land’s Leitlinie Informationssicherheit and its IKT-Sicherheit description last saw revision in 2017, and that the CDO post is held part-time by a Staatssekretär whose main brief is federal and European affairs. Hauer told the committee that further checks would most probably expose structural deficits dating back years, and that fixing them would cost money the Landeshaushalt has yet to provide.

A response timeline in incident terms brings us back to the point of this post: detection by an operations ticket rather than a security alert; containment within 24 hours of the ticket; public statements on 19 and 24 August that sensitive data had stayed put, made while the inventory of the outflow was incomplete; credential rotation nineteen days after discovery; exfiltration scope learned from the leak site on day 22; entry vector reported unknown to the affected house on day 25, three days after the federal office published it. Rhysida’s own statistics, as reported by BSI’s commercial provider, are a 92 percent publication rate and an eleven-day average from listing to leak. Berlin was published in seven.

The table shows every control as a policy setting, a default, or a log that already ships with the platform Berlin runs. Berlin left them unset. The 2025 budget passed by the CDU-SPD coalition cut Landes-IT and E-Government, and the Linke’s digitalisation spokesman warned in November 2024 that savings on intrusion detection would gut the Landesnetz’s island security model. The 2026/2027 double budget cut a further 50 million from digitalisation, and two thirds of Senate administrations and Landesbehörden still run their own IT security outside the ITDZ. The attackers walked into operations where the coalition had already removed the alarm. The Land Berlin should hold that coalition accountable, and hold the AfD to its own record of demanding surveillance of everything (trash cans!) while funding the security of nothing.

DHH Omarchy Doctrine: Fascism Stage One by Definition

David Heinemeier Hansson has published again; this time it’s his movement’s public face. The decoder for his “creed” post comes from his other writing.

Source: Twitter

The Omarchy Doctrine, posted for his Linux distribution, runs ten lines: three equations, six imperatives, one promise. Heritage is duty. Hold the line. You’re somebody now. The creed leaves its referents unnamed. His essays of the past year name them: a London mourned for its lost “native” population and a march branded Unite the Kingdom, a call for remigration, a post that sets Romani people in Copenhagen parks beside a wolf population and prescribes shooting for one and deportation for the other, and a July essay announcing the return of the will to power through a hero generation that rejects managed decline.

Roger Griffin defines exactly this as the fascist core of palingenetic populist ultranationalism: rebirth from decay, against a corrupt establishment, for an ethnically defined people.

The July essay meets each term.

The new creed supplies the mobilization.

Robert Paxton’s The Anatomy of Fascism tells us to watch five stages. The first is the creation of a movement with a creed, a leader and followers. The second is rooting in the political system through alliance with elites who believe they can use it.

Stage one is complete by definition: a creed, a leader, followers.

The next stage requires a foothold in the state. The money for it is already being boasted about, $18.5 million pledged to a foundation with no jurisdiction, legal form or filing on record. Here’s how it runs:

Paxton stage Test Omarchy record Status
1. Creation of a movement A creed, a leader, followers The Omarchy Doctrine; DHH as founder and foundation president; followers who call themselves Omarchs, at meetups on five continents this week Reached. We are here.
2. Rooting in the political system Alliance with elites who believe they can use the movement; a foothold in parties or institutions $18.5 million, of which $18 million comes from twelve individual patrons at $1 million each, among them Tobi Lütke, Patrick Collison, Michael Dell, Jack Dorsey, Matthew Prince and Brian Armstrong, and nine corporations, among them Meta, OpenAI, Anthropic, DigitalOcean and 1Password Financing present. Political foothold absent.
3. Seizure of power Entry into government, historically by invitation of conservatives None Absent
4. Exercise of power Governing in tension with the state and the elites who opened the door None Absent
5. Radicalization or entropy Escalation toward war and purge, or decline into routine None Absent

This of course reads different for Thiel and Musk, who are at stage four or even five.

NY Tesla Kills One in “Veered” Crash

Police are investigating.

A Tesla crashed into scaffolding in Midtown Manhattan on Wednesday morning, killing the vehicle’s passenger and sending the driver to the hospital, according to police.

A preliminary police investigation revealed that a gray 2024 Tesla Model Y SUV driven by a 27-year-old female collided with scaffolding, a bus stop and a mailbox at approximately 2:43 a.m. on Wednesday, a New York Police Department spokesperson told ABC News.

2026 National Firearms Survey of AR-15 Hunters Who Don’t Exist

The 2026 National Firearms Survey claims 36 million Americans hunt every year. The federal government counts 14 million. The gap is 21 million mystery people, and that gap now sits unexplained in front of the Supreme Court.

William English of Georgetown posted the second wave of his survey to SSRN on August 24. Eleven days later, on September 4, he filed an amicus brief in his own name, with the Center for Human Liberty, in Viramontes v. Cook County and Grant v. Higgins, telling the Court his unreviewed working paper “warrants reliance” as proof that AR-15 type rifles are in common use for lawful purposes. Page 9 of the brief lists those purposes. Hunting sits third, at 50.2 percent of owners, behind home defense and target shooting.

I’m a bit perplexed at how little data integrity there is in this whole system.

The raw data is on Harvard Dataverse. I downloaded it and ran the numbers. Every headline figure in the paper reproduces exactly: 16,688 validated owners, 30.0 percent owning an AR-15 or similar rifle, 50.2 percent of those citing hunting. The math is simple, and the problem is what it’s being used falsely to imply.

16 million AR-15 hunters, 14 million hunters

The survey asks every validated gun owner whether they go hunting at least once in a typical year. 40.8 percent say yes. The paper puts the adult gun-owning population at 88 million. Multiply those and the survey implies 35.9 million annual hunters in the United States, roughly one adult in seven.

The U.S. Fish and Wildlife Service runs the National Survey of Fishing, Hunting, and Wildlife-Associated Recreation every five years, since 1955. The 2022 wave drew over 100,000 respondents and counted 14.4 million hunters aged 16 and over, six percent of the population. It counts anyone who hunted, licensed or unlicensed, on public land or private, with a rifle or a bow. It is the benchmark every state wildlife agency and every hunting organisation in the country uses.

English’s survey question anticipates there will be a license objection. Its wording very clearly invites respondents to “count hunting on private land, which may not require a hunting license.” The federal survey already does also, however. The 2.5x gap isn’t explained by the caveat.

Then look at the AR-15 subsample. 63.8 percent of AR-15 and similar-rifle owners say they hunt every year. Applied to the paper’s 26.4 million owners, that is 16.9 million AR-15 owners hunting annually. The entire American hunting population, by the federal count, is 14.4 million. The survey’s AR-15 owners alone outnumber it by two and a half million.

Look at this the other way now. Among respondents who say they hunt every year, 47 percent own an AR-15 or similar rifle. Half of America’s hunters owning a pistol-grip semiautomatic is a claim anyone who has stood in a check station line can weigh against what actually comes through it.

Overcount explained

Self-reported hunting has a hard external check, because the federal government has measured it for seventy years. Against that check, the gun owners in this sample overstate by a factor of two and a half. The same respondents, in the same sitting, supplied the defensive gun use figures and the rifle and magazine counts that the brief carries to the Court. Those rest on self-report alone. The one variable that can be measured with an outside benchmark fails it.

The data offers other insights about who was answering. Among the 5,001 AR-15 owners with complete counts, 23.1 percent entered more AR-15 type rifles than total rifles owned. Individual respondents reported owning 5,678, 1,513, 1,332, and 1,000 AR-15s. The paper drops those counts from the stock estimate and keeps the respondents as owners for the 30 percent prevalence figure. Median completion time for the full owner questionnaire, including itemised magazine counts by capacity and narrative defensive incident questions, was five minutes. Nearly half finished in under five.

The ownership question itself opens with “Some have argued that few gun owners actually want or use” these rifles, before asking whether the respondent owns one. That is a leading stem, and the paper prints it as a methodological refinement. The instruction that follows tells owners to include rifles “modified or moved to be compliant with local law.” A California featureless rifle is legal precisely because the statute defines it as something other than an assault weapon. The survey counts it as one, and the note under Table 8 adds rifles kept in other states to the tally, which is how California, New York, New Jersey, Massachusetts and Maryland all land near the 30 percent national figure despite bans. The brief then spends three pages accusing a rival study of a “demonstrable coding error.”

The same respondents, on self-defense

The leading stem is a troubling pattern. The AR-15 question opens with “Some have argued that few gun owners actually want or use” them. The magazine question opens with the identical clause. The defensive gun use question opens with “Many policymakers recognize that a large number of people participate in shooting sports but question how often guns are used for self-defense.” The deterrence question hands the respondent an example before asking, a landowner with a rifle on his shoulder turning away a trespasser.

Every contested number in the brief comes from a question that first told the respondent who was arguing against them. That’s not subtle.

The defensive gun use estimate of 2.2 million per year reproduces from the data. It comes from dividing every incident a respondent ever reported by the adult years the respondent has lived, then multiplying by 88 million owners. That method assumes a rate that holds across a lifetime.

The data says that’s wrong.

Gun owners aged 18 to 20 report 0.47 defensive uses per adult year, roughly one every two years. Owners aged 26 to 30 report 0.09. Owners over 80, who lived their prime years through the 1970s, 80s and 90s when the FBI violent crime rate ran well above today’s, report 0.002. The rate falls in every single bracket from 18 to 80, by a factor of 200 end to end. Lifetime incident counts should rise with age, since a longer life offers more chances. Here they peak at 26 to 30 and fall to almost nothing.

The paper calls this “concentrated in early adulthood.” The easier explanation is that the youngest respondents in an online panel say yes the most.

Yes, there are yes clusters.

Respondents who own an AR-15, own a magazine over ten rounds, and hunt every year report a lifetime defensive gun use at 64.6 percent. Respondents with none of the three report it at 20.8 percent. 1,239 validated owners said yes to all five contested items in the survey: the rifle, the magazine, the hunting, the defensive use, and the deterrence. Owning a rifle that also gets used for deer makes a gun no better in a fight. It makes a respondent more likely to say yes. The defensive use rate tracks the person answering, and the survey has no way to tell the two apart.

Then look at the gunfire. 23.7 percent of reported incidents involved firing the gun, with a median of two rounds. At the paper’s own 2.2 million annual figure that is 521,000 defensive shootings a year, over a million rounds fired at people or animals in self-defense. One respondent reported firing a million rounds in a single incident, two more reported 500.

A million rounds.

The FBI’s justifiable homicide data for 2015 through 2024 records 2,776 killings by private citizens across the whole decade, 88.5 percent with a firearm. That is about 246 a year. One attacker killed for every 2,100 defensive shootings. 53.3 percent of the incidents took place outside the home but on the respondent’s property, and 8.4 percent were against animals.

The brief tells the Court that 70.6 percent of defensive uses were so successful there was no crime to report. The FBI figure suggests a far simpler reading of why nothing was reported.

Built for the brief

The Azrael, Blocher, Cook, Hemenway and Miller critique of the 2021 wave took three years to reach print in the SMU Law Review. By then the first paper had been cited in roughly sixty-five briefs and at Supreme Court oral argument. The second wave reached the Court in eleven days, carried by its own author, with the survey firm named as a data-quality credential and The Trace’s funders named in a footnote on the same page where the brief borrows The Trace’s numbers.

The 40.8 percent hunting rate appears nowhere in the body of the paper. It sits in one row of an appendix table on page 69. The body text on page 41 says instead that “half report using them for hunting.” Respondents ticked “Hunting” from a list of reasons for owning the rifle. The paper turned a ticked box into use, and the brief carried the upgraded version to the Court.

Page 5 says the survey “was sponsored and paid for by a grant from the Wealth of Nations Institute.” The Wealth of Nations Institute is a Delaware nonprofit with an IRS ruling year of 2024, a Kennett Pike mail-drop address in Wilmington, and a single public filing reporting under fifty thousand dollars in program spending. A 51,398-respondent Centiment panel costs more than that. Whose money came through that vehicle is unstated. The PDF’s own metadata lists its creator as OpenAI Prism, with a creation date of August 26, two days after the date on the title page.

Harry Frankfurt defined bullshit as speech produced with indifference to whether it is true. The purpose it serves sits downstream of the speaker, and here the downstream is a docket.

The 2026 National Firearms Survey answers a question a court asked. It reports that half of American hunters own an AR-15 and that AR-15 owners alone outnumber every hunter the federal government can find. That is some real bullshit in the Supreme Court’s docket. The test was easy, so I’m guessing it’s not being done for a reason.