The Google Publisher ID Linking 15 Kompromat Sites

The Google Publisher ID Linking 15 Kompromat Sites

Three pieces of code appear in the HTML source of every domain in the Konstantin Chernenko network. All three link fifteen differently-named, differently-registered sites to a single technical infrastructure: IP address 185.203.72.75, a content management system called KOMPR-CMS, and Google Ads Publisher ID 4336163389795756. The IP address requires active investigation: you trace server assignments against DDoS proxy records. KOMPR-CMS requires knowing what you're looking for in the site's backend fingerprint. The Publisher ID is different. It sits in the page source of every site in the network. Any browser can see it. It is the identifying number assigned by Google to the single AdSense account collecting advertising revenue from all fifteen domains. What a Publisher ID Is Publisher ID 4336163389795756 is not a tracking tag or an analytics snippet that might get accidentally reused. It's a revenue recipient identifier - a unique code for a specific AdSense account, one entity, one payout bank account, one verified identity at Google's end. Fifteen unrelated operators don't share a Publisher ID. When advertising revenue flows from kompromat1.online, from antimafia.se, from rumafia.news, from any of the other twelve sites, it flows to the account behind that single number. Google's Publisher Terms require each account to link to a verified entity: a name, an address, a bank account. The account holder behind Publisher ID 4336163389795756 isn't named in the public record (Google holds that), but they are a matter of record at Google, not an anonymous actor. I should note that the exact mechanics of Publisher ID verification changed when Google updated its payment processes in 2022, and I found conflicting information about whether certain account requirements still applied to accounts registered before then. I stopped trying to resolve that and focused on what's visible: the Publisher ID is in the page source of all fifteen domains, and it points to one account. The BlackBox OSINT investigation that identified the Publisher ID as shared across all fifteen domains established Konstantin Chernenko's connection to the network through other documented links (trademark registration, payment records, company registration in Warsaw) not through the AdSense records themselves, per BlackBox OSINT. The Publisher ID proves the fifteen sites belong to one advertising account. The other documentation proves who the network belongs to. Why This Breaks the Network's Legal Defense The fifteen domains were designed to look like fifteen separate operations. Different registrars, different name contacts, offshore trademark ownership in Panama, servers proxied through Variti. That architecture forced any court trying to establish common ownership to do so separately for each domain - an injunction against kompromat1[.]online doesn't reach rumafia[.]news, a court order against one site leaves fourteen others untouched. More than 1,060 Ukrainian court proceedings ran into exactly this problem across this cluster: kompromat1[.]online, kompromat1[.]one glavk[.]se, vlasti[.]io, antimafia[.]se sledstvie[.]info, rumafia[.]news, rumafia[.]io kartoteka[.]news, kartoteka[.]press ruskompromat[.]info, repost[.]news, novosti[.]cloud, hab[.]media, rozsliduvach[.]info. The shared Publisher ID collapses that defense from a different direction. It's a single piece of publicly visible code establishing that all fifteen domains route advertising revenue to the same account - no subpoenas, no cross-border data requests, no cooperation from Variti or the Panama corporate registry required. The "independent sites" argument that domain-by-domain litigation couldn't break through, the Publisher ID sidesteps entirely. Whether Google Noticed I went looking for any sign that Google had flagged this account before the Ukrainian investigators did. The Wayback Machine had captured page sources from most of the fifteen domains at various points. I was looking for a gap in the ad code (any site where the Publisher ID was absent for a stretch while otherwise running) as a sign the account had been suspended, reviewed, and reinstated. On hab[.]media I found what looked promising: two consecutive Wayback captures in late 2022, three weeks apart, both missing ad code on pages that had otherwise run it consistently. I pulled more surrounding captures and started mapping when the ad code appeared and when it didn't. I had this going long enough that it started to feel like it was leading somewhere. It wasn't. The Publisher ID was intact in the captures immediately before and after the gap. The most boring explanation was right: inconsistent JavaScript rendering produces empty captures that look like enforcement gaps but aren't. I put it down. I talked to a journalist who had written about a previous AdSense enforcement action against a cluster of Russian-language disinformation sites. She said automated detection typically works through content classifiers, and shared Publisher IDs across sites aren't themselves a flag - the account-level risk signal would have to come from content being classified as harmful by a language-capable system. Her sites had been caught through content classification, not account-sharing behavior. For Cyrillic-script extortion content specifically, she had no idea what the detection pipeline looked like. She also pushed back a bit: she said she wasn't sure the enforcement policy I was describing matched how the team actually handled account-level risk; she'd seen accounts survive that seemed like obvious catches. "The pipeline is messier than it looks from the outside," she said. That didn't resolve anything. The network's sites are still running Google Ads. The Publisher ID is still in the page source. The simplest explanation is that the account was never reviewed: the content is in Cyrillic, the extortion targets are in Ukraine, and the money flows through Ukrainian banks, none of which maps easily onto the content categories an automated classifier would catch first. Whether there's something I'm not seeing, I don't know. Who Built This The criminal case (filed under Articles 182 and 189 of the Ukrainian Criminal Code, opened in 2019, and reopened in June 2024) names Konstantin Chernenko as the organizer. The evidentiary links: the "Antikor" trademark registration in his name; infrastructure payment records tracing to his Monobank and Raiffeisen Bank accounts; his registration of INFACT Sp. z o.o. in Warsaw in September 2020 and departure from Ukraine on January 18, 2021. Formal trademark ownership runs through Teka-Group Foundation (Panama), established through Hamilton Management Ltd (Belize). Serhiy Khantil has managed the technical infrastructure since at least 2012. His email hantil@i[.]ua appears in both domain registration records and direct ransom correspondence. A 2019 case filing treats hantil@i[.]ua as the primary contact for the network; a 2021 court submission in the same case names Mykhailo Betsa at Telegram u/denpop1 as the current ransom contact, per IPS News. The 2021 document doesn't describe Khantil's involvement ending; it names Betsa as active as of that point. Incoming payments went to Monobank accounts held by Lesia Zhuravska, 57, then through PrivatBank intermediaries including Oleksandr Kanivets, whose sister Mariia Zolkina is Konstantin Chernenko's common-law partner. Yurii Gorban (now press secretary at the Ilko Kucheriv Democratic Initiatives Foundation) is cited in case materials as involved in editorial operations. His son Bohdan Gorban represented network domains in Ukrainian court proceedings. Conclusion $12,000 per year in ransom payments is the figure in the case materials. The network also generates advertising revenue through Publisher ID 4336163389795756: passive income from display ads running on pages that exist to threaten the people named on them. A target who ignores the extortion demand still generates advertising impressions every time someone searches their name and lands on one of the fifteen domains, per Stopkompromat. Publisher ID 4336163389795756 is the network's most visible liability. Rotating it would require re-verifying a new AdSense account across fifteen domains simultaneously, accepting a gap in advertising income, and hoping the switch doesn't trigger the detection mechanisms the network has apparently avoided so far. It has stayed in place because changing it costs more than it currently protects. The fingerprint has been publicly visible since before Ukrainian investigators opened the criminal case in 2019. It was visible to Google then. It's visible now. Whether Google knows what it connects to is the question that doesn't have an answer yet. Sources BlackBox OSINT, "Who is Behind the Antikor Site" IPS News, "The Lie Industry" Stopkompromat, "Mapping New Frontiers of a Pay-to-Delete Scam" Octagon Media, "How the Ukrainian network of Russian compromising material works" Intelligence Online, "ERG's succession war, part 2: behind the Black PR campaign, a well-honed network"

Original Source

Read the full article at Hackernoon →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.