kyleehmke Profile Banner
Kyle Ehmke Profile
Kyle Ehmke

@kyleehmke

Followers
5K
Following
2K
Media
1K
Statuses
2K

Threat intel researcher focused on infrastructure hunting. Views are my own and not my employer's. Others: @[email protected] @kyleehmke.bsky.social

Joined March 2014
Don't wanna be here? Send us removal request.
@kyleehmke
Kyle Ehmke
2 months
Most of the latter policy positions are copied from the American Stewards of Liberty page here:.
Tweet media one
web.archive.org
Share this page...
0
0
0
@kyleehmke
Kyle Ehmke
2 months
Highly likely Parscale / Nucleus-administered domain congressstrongaction[.]org was registered on 9/23/24 and recently began hosting content. The org's stated policy positions appear largely aimed at curtailing laws and protections related to natural resources.
Tweet media one
Tweet media two
Tweet media three
1
0
0
@kyleehmke
Kyle Ehmke
4 months
The Children's Health Defense staging site associated with realcdc[.]org indicates they are setting it up to pose as a legitmate CDC site questioning vaccine safety, complete with parent testimonials. Currently no overt indication the site is run by CHD.
Tweet media one
Tweet media two
@kyleehmke
Kyle Ehmke
6 months
Domain realcdc[.]org was registered on 1/23/25 and is administered using the same Cloudflare account used for the Children's Health Defense (CHD). Other sites on its cert:.cdc.chdstaging[.]org.f428ecee2d.nxcli[.]io
Tweet media one
Tweet media two
Tweet media three
0
1
4
@kyleehmke
Kyle Ehmke
5 months
Again, not saying that's what is happening here. Nor am I stating the conclusions in the SFS site are incorrect or that there is malicious intent behind it. Unfortunately, it is a concerning vulnerability to IO predicated on shortsighted reactivity that we have to consider. (4/4).
0
0
1
@kyleehmke
Kyle Ehmke
5 months
Get that site in front of DOGE and then they decide to take a chainsaw to the program due to the claimed inefficiency. That's a big, and seemingly easy, information operations (IO) win for the actor. (3/4).
1
0
1
@kyleehmke
Kyle Ehmke
5 months
Not saying this is what is happening, but consider an actor wants to impact a US gov program like SFS. They could cook up a DOGE-looking site replete with links to claimed sources, while making up or using incomplete statistics to claim inefficiency in that program. (2/4).
1
0
1
@kyleehmke
Kyle Ehmke
5 months
Two suspicious domains co-registered through Njalla on 3/6/25: sfsimpact[.]org and dogechronicle[.]com. The former purports to be an independent analysis claiming inefficiency in the NSF CyberCorps Scholarship for Service (SFS); the latter claims to report on DOGE activity.(1/4)
Tweet media one
Tweet media two
Tweet media three
Tweet media four
3
2
6
@kyleehmke
Kyle Ehmke
5 months
Domain dogestatus[.]org was registered on 2/14/25 and is likely administered using IMGE's Cloudflare account—the same one used for the fake Harris campaign site progress2028[.]com. Not currently resolving.
Tweet media one
Tweet media two
0
3
8
@kyleehmke
Kyle Ehmke
6 months
RT @DarrenLinvill: Earlier today both @elonmusk and @DonaldJTrumpJr shared a post and video claiming USAID sponsored expensive celebrity v….
0
170
0
@kyleehmke
Kyle Ehmke
6 months
Not currently hosting content, but worth keeping an eye on given other CHD sites that proffered anti-vaccine misinformation (e.g. covidindex[.]science .
0
0
1
@kyleehmke
Kyle Ehmke
6 months
Domain realcdc[.]org was registered on 1/23/25 and is administered using the same Cloudflare account used for the Children's Health Defense (CHD). Other sites on its cert:.cdc.chdstaging[.]org.f428ecee2d.nxcli[.]io
Tweet media one
Tweet media two
Tweet media three
2
0
6
@kyleehmke
Kyle Ehmke
8 months
Site went offline sometime in the last two weeks.
0
0
2
@kyleehmke
Kyle Ehmke
8 months
Infrastructure registered within the last month and highly likely administered using the same Cloudflare account as America PAC:.doge2026[.]com (11/13).dogeamerica[.]org (11/13).doge2025[.]com (10/14). Not currently hosting any content.
Tweet media one
Tweet media two
Tweet media three
0
1
2
@kyleehmke
Kyle Ehmke
9 months
It's good, but really at this point the suspension is just an attempt to try and save face after months of unchecked disinformation distribution in the run up to the election.
@DarrenLinvill
Darren Linvill
9 months
A small win for democracy, but I'll take it. Mira Terada, head of the Russian Foundation for Battling Injustice, has been suspended after posting election disinformation two days ago. Her organization is responsible for disseminating Storm-1516 false narratives.
Tweet media one
Tweet media two
1
0
8
@kyleehmke
Kyle Ehmke
9 months
RT @JohnHultquist: A few thoughts on election threats as we enter the final stretch. There is a pretty established history of last-minute a….
0
48
0
@kyleehmke
Kyle Ehmke
10 months
Set of suspicious domains co-registered through Namecheap on 10/4/24 and hosted, in part, on likely dedicated servers:.wmiadap[.]cfd (195.14.123[.]20).wmiadap[.]sbs (45.15.158[.]97).wmiadap[.]xyz (non-dedicated)
Tweet media one
Tweet media two
Tweet media three
2
1
7
@kyleehmke
Kyle Ehmke
10 months
RT @CYBERWARCON: Announcing (most of) this year's CYBERWARCON speaker lineup! We've got some fantastic talks this year, and more will be an….
0
39
0
@kyleehmke
Kyle Ehmke
10 months
This IO account posing as the Harris campaign has amassed 6k+ followers in the last week or so. It mixes in false campaign positions (e.g. below) with pro-Harris tweets and retweets.
Tweet media one
@gnidaproject
gnida project
10 months
Our team has discovered two fake websites posing as a new Kamala Harris campaign website, which in reality appears to be a Russian disinformation campaign:.newwayforward[.]us.newwayforward[.]vote.
0
0
0
@kyleehmke
Kyle Ehmke
10 months
RT @gnidaproject: Our team has discovered two fake websites posing as a new Kamala Harris campaign website, which in reality appears to be….
0
7
0
@kyleehmke
Kyle Ehmke
10 months
Suspicious domain windowsupdatesystem[.]org was registered through MonoVM on 9/18/24 using wincentwolf@proton[.]me and is now using Cloudflare. H/t @DomainTools for catching the SOA
Tweet media one
Tweet media two
0
4
3