Storm-1679, also associated with Oka Flood and commonly linked to the broader Operation Overload or Matryoshka ecosystem, is a Russian-aligned influence operation focused on online disinformation and perception shaping. The actor is known for producing and amplifying fabricated media intended to manipulate public opinion, undermine confidence in institutions, and exploit politically sensitive events. Activity attributed to this cluster has targeted major international events and geopolitical issues including the 2024 Paris Olympics, Ukraine-related narratives, immigration, and elections. The group has used spoofed media branding, fabricated intelligence-style warnings, fake documentaries, synthetic audio, AI-generated voice cloning, and deepfake-style content to increase the credibility and reach of false narratives. During Olympics-related campaigns, Storm-1679 disseminated fake terror-threat messaging and impersonated well-known media outlets and official organizations in English and French. Reported examples include fabricated broadcast segments and a fake documentary using an AI-generated celebrity voice. The operation has also been observed attempting to provoke fact-checkers and researchers into amplifying its narratives. Storm-1679 is assessed as aligned with Kremlin propaganda and Russian influence objectives. Microsoft has categorized it as an influence-operations actor within its naming taxonomy. Reporting also associates it with the Matryoshka and Operation Overload labels, though some public analysis has noted uncertainty about the precise degree of direct Russian state control. High-confidence reporting supports Russian alignment and operational focus on influence activity rather than network intrusion, ransomware, or destructive cyber operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian influence operation using AI-generated and deepfake content to spread false terror-related narratives around major sporting events.
Russian influence operation adapting conflict-related narratives for media impersonation and disinformation targeting European audiences.
Large-scale, AI-driven disinformation campaigns targeting global elections and controversial issues to sow discord in democratic countries.
Russia-linked influence operations cluster listed in Microsoft's naming taxonomy mapping.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.