Storm-1516, also widely tracked as CopyCop and Neva Flood, is a Russian state-linked influence operation assessed to support Kremlin geopolitical objectives, particularly by undermining support for Ukraine, weakening European and transatlantic cohesion, and exacerbating political fragmentation in targeted states. Multiple public attributions link the operation to Russia’s GRU, including reporting that associates it with Unit 29155, and some investigations assess operational support from Moscow-based influence infrastructure and affiliated operators. The operation has been active since at least 2023 and expanded substantially in 2025–2026. It is characterized by industrial-scale creation of inauthentic websites impersonating local news outlets, political movements, and fact-checking organizations across multiple countries and languages. Storm-1516 commonly launders narratives through a staged dissemination model: fabricated or manipulated claims are first seeded through anonymous personas, purported whistleblowers, or citizen-journalist fronts; these claims are then echoed by covert websites and amplified through social media accounts, Telegram channels, YouTube, and pro-Russian influencer ecosystems. The group has also used cloned and mirrored infrastructure to survive takedowns and maintain narrative persistence. Storm-1516 is notable for extensive use of AI-assisted tradecraft in information operations. Reported techniques include generation and rewriting of articles with self-hosted large language models, production of deepfake or AI-generated videos and audio, fabrication of counterfeit media branding, and creation of synthetic investigations and forged leaked documents. The operation blends factual fragments with fabricated allegations to imitate legitimate journalism and exploit local grievances. It has also been associated with attempts to contaminate search results, AI assistants, and retrieval-based language-model outputs by flooding the web with optimized false content. Targeting has prominently included France, Armenia, Canada, the United States, Germany, and Moldova, with narratives tailored to domestic political tensions, elections, separatist sentiment, corruption allegations, and anti-elite themes. In France, the operation has impersonated media brands and pushed fabricated stories targeting political figures and public debate. In Armenia, it has been identified as a major foreign influence threat around the 2026 election cycle, including synthetic media targeting Prime Minister Nikol Pashinyan and narratives favoring pro-Russian opposition currents. In Canada, it has been linked to amplification of Alberta separatist narratives. In Germany and other European states, it has used fake news sites and impersonation to discredit candidates and institutions. Known associated ecosystems and amplifiers include Portal Kombat, InfoDefense, and the Foundation to Battle Injustice, although coordination levels may vary by campaign. Storm-1516 also shows thematic and infrastructural overlap with broader Russian influence activity such as Doppelgänger-style media impersonation and other Kremlin-aligned information operations. Its dominant motivation is espionage in the form of state-directed political influence and information warfare rather than direct financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
42 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting information influence operations using AI-generated deepfake content and media impersonation to target French political figures in a pre-election context.
State-sponsored information warfare campaign involving manipulation of LLM retrieval through GEO/RAG poisoning, with the Foundation to Battle Injustice operation used to spread false narratives about alleged Ukrainian war crimes.
Russian influence operation using fabricated videos, counterfeit sites, anonymous personas, and synthetic amplification to run high-tempo disinformation and false-flag campaigns.
Referenced as part of a documented 2025–2026 Kremlin information offensive targeting Armenians ahead of Armenia’s 7 June 2026 election.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.