AFAIK Jake Williams didn't get singled out because he only "wrote a blog post" about Shadow Brokers - it was because he was involved in a Twitter based dispute with Shadow Brokers.
Somebody created a fake Twitter account and were sending all sorts of tweets to the Shadow Brokers, someone who was either in the IC or formerly in the IC.
This is why the Shadow Brokers outed him in this post[0]
> TheShadowBrokers is having special invitation message for “doctor” person theshadowbrokers is meeting on Twitter. “Doctor” person is writing ugly tweets to theshadowbrokers not unusual but “doctor” person is living in Hawaii and is sounding knowledgeable about theequationgroup.
> Then “doctor” person is deleting ugly tweets, maybe too much drinking and tweeting? Is very strange, so theshadowbrokers is doing some digging. TheShadowBrokers is thinking “doctor” person is former EquationGroup developer who built many tools and hacked organization in China.
> TheShadowBrokers is thinking “doctor” person is co-founder of new security company and is having much venture capital.
It was easy for everyone on Twitter to figure out who he/she/they were referring to. I think this is important context - Shadow Brokers aren't just outing random operatives, they're flexing their access and abilities when being prompted to
I also wonder if this wasn't part of a plan to bring the Shadow Brokers out of their shell a little - coax them into revealing a little more about themselves than the usual document and software dumps - which would require the NSA to spend money to get a picture of what tools are available.
Jake says to the NYTimes that he isn't working with the NSA - but he'd also say this if he were working with the NSA to get a little more out of Shadow Brokers
I've never bought the theory that Shadow Brokers is Russia, or that it was Harold T Martin (or stolen from him). I think the Jake Williams incident lends further credibility to the theory that it is a former TAO or NSA employee.
The fake Russian style writing of the Shadow Brokers isn't ordinary bad English Russian (which has a number of characteristics that aren't reflected in how Shadow Brokers write). As the article mentions, there are also far too many cultural and infosec "inside baseball" references in the writing of Shadow Brokers for it to not be someone who is either familiar with the community or part of it.
I also don't recall Russian ops having OPSEC this good - to the point where they can't be identified or linked. The good OPSEC suggests the person/people behind the Shadow Brokers are familiar with what the NSA are capable of, and what they're not. Most Russian and Chinese ops are usually linked one way or another back to to them as they're less concerned about OPSEC as they have the operational advantage of not fearing arrest or extradition
Differences between SB and Fancy Bear or Russian ops: bad security practices (not locking down bitly) vs good, using clearnet domains[1] emails[3] vs steemit and onions, using VPNs rather than Tor, the use of Bitcoin vs Monero/Zcash, speaking only (broken) English vs either plain English or Russian[2], financial motive vs political motive, etc.
It feels like someone upset with the NSA, who knows the organization very well and is also motivated financially - but I wouldn't attribute greater than 50-60% certainty to any theory at the moment. If the Shadow Brokers go on to never be identified it would really be an incredible situation.
[0] https://steemit.com/shadowbrokers/@theshadowbrokers/theshado...
[1] https://www.secureworks.com/research/threat-group-4127-targe...
[2] https://www.fireeye.com/blog/threat-research/2014/10/apt28-a...
[3] https://www.threatconnect.com/blog/fancy-bear-anti-doping-ag...