The Internet Research Agency (IRA), also known as the St. Petersburg troll factory or Sankt Petersburg troll factory, is a Russian influence-operation organization established in 2013 and financed by Yevgeny Prigozhin. Although organized as a private entity, it supported Russian government propaganda and disinformation objectives, promoting pro-Kremlin narratives domestically and conducting covert influence campaigns abroad. The IRA is best known for interference in the 2016 United States presidential election. Its operations used fictitious American identities, coordinated social media accounts, political messaging, and organized real-world rallies to exploit societal divisions and undermine trust in political institutions. Its election-related messaging supported Donald Trump and disparaged Hillary Clinton. In 2018, the United States indicted the organization and associated individuals and imposed sanctions over election interference. Its operational methods include coordinated inauthentic behavior, impersonation of local residents and journalists, fictitious news outlets and think tanks, paid advertising, and cross-platform amplification. Operators blend political propaganda with ordinary personal or lifestyle content to build credible personas and conceal coordinated activity. IRA-linked campaigns have recruited unwitting freelance journalists and used local personnel outside Russia. Proxy services and deceptive identities help obscure operator attribution. Beyond the United States, IRA-linked operations have targeted audiences in Russia, Ukraine, Europe, North Africa, Sub-Saharan Africa, and the Middle East. Their messaging has promoted Russian geopolitical interests, criticized Western policies and Ukrainian politicians, supported Russia’s annexation of Crimea, and promoted Wagner Group activities. Associated networks have influenced political discourse in the Central African Republic, Libya, Sudan, and Syria, using locally tailored narratives and apparently independent media or civic entities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted influence operations against American audiences using fabricated personas, audience research, paid advertising, and organic engagement. Its historical staffing and coordination practices illustrate administrative work that AI could reduce; the article does not establish current IRA use of AI.
Russian proxy troll farm referenced as an example of a covert influence operation that the United States disrupted.
St. Petersburg-based Russian troll farm associated in the content with Storm-1516 and known for election meddling and influence operations.
Conducting foreign influence and disinformation campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.