Thursday, September 24, 2026

Oxygen Software

 

The Core Facts

  • The Entity & Rebranding: The Russian digital forensics firm originally incorporated as OOO "Oxygen Software" in 2000. Following the 2022 Russia-Ukraine war, it rebranded as OOO "MKO Systems" (МКО Системы) while maintaining its core software suite, Mobilniy Kriminalist (Mobile Forensic Expert).

  • State Procurement and FSB Integration: Public records, archived caches, and academic journals demonstrate that MKO Systems provides direct data-extraction tools (capable of bypassing encrypted apps like WhatsApp and Telegram) to Russian security services, including the FSB, Ministry of Defense (MoD), and Ministry of Internal Affairs (MVD).

  • The U.S. Front: The company operates an American subsidiary, Oxygen Forensics, Inc. (based in Alexandria, Virginia), headed by Lee Reiber. This US entity sells digital forensics tools to prominent federal agencies—including the FBI, Secret Service, ICE, and the State Department—while systematically obscuring its deep operational and developmental ties to Russia.

  • Financial Piping: Internal whistleblower accounts and structure reports indicate that a significant portion of the U.S. revenue (roughly 50%) is funneled through a Cyprus-based holding company (Oxygen Forensics Limited), with ownership structures connected via jurisdictions like Kyrgyzstan and Turkey.

The Intriguing Conspiracy & Geopolitical Correlation

The dossier outlines a startling web connecting digital surveillance tools used by Western law enforcement straight to high-level Russian state capture, sanctioned intelligence figures, and international cybercrime:

  1. The MNIIRS Takeover and the FSB Nexus: The Moscow Research Institute of Radiocommunications (MNIIRS)—where Oxygen Software originally had its roots—was taken over in 2023 by Eduard Bendersky, a sanctioned former FSB special forces (Vympel) officer.

  2. The Ransomware Family Ties: Bendersky's father-in-law status links him directly to Maxim Yakubets, a notorious ransomware hacker backed by the Russian state and wanted by the FBI with a $100 million reward on his head. This creates a bizarre operational loop where state-backed intelligence infrastructure, commercial spyware, and cybercrime syndicates overlap.

  3. The "Paging" Vulnerability Paradox: Whistleblowers within the dossier point out the ultimate irony and security blind spot: U.S. federal agencies and major corporations willingly install "kernel-level" extraction and remote-access software (Oxygen Remote Explorer) packaged as a U.S. product. Employees are actively coached to instruct client IT departments to disable firewalls, lower antivirus guards (like CrowdStrike or Windows Defender), and put "bodyguards on break" during installation.

  4. The Ultimate Irony: Given that the software is engineered and updated by developers sitting in Moscow under the regulatory thumb of the FSB, the system essentially acts as a Trojan horse—handing foreign intelligence backdoor access to sensitive Western law enforcement and corporate networks under the guise of digital forensics.

No comments:

Post a Comment

Oxygen Software

  The Core Facts The Entity & Rebranding: The Russian digital forensics firm originally incorporated as OOO "Oxygen Software"...