Storm-1516, also known as CopyCop and Neva Flood, is a Russian covert influence operation publicly attributed to Russia’s military intelligence service (GRU), including GRU Unit 29155. Active since at least 2023, it conducts multilingual disinformation and election-interference activity intended to advance Russian geopolitical interests, weaken international support for Ukraine, erode trust in democratic institutions, and exacerbate political polarization. The operation has targeted audiences in Armenia, France, Germany, Moldova, Canada, the United States, and Ukraine. Storm-1516 operates a large ecosystem of inauthentic websites impersonating local news organizations, political movements, fact-checkers, and established media brands. It uses fabricated investigations, forged documents, fictitious whistleblower personas, counterfeit media reporting, manipulated or AI-generated audio and video, and deepfakes to attack political leaders, electoral processes, Western investment, and pro-Western policies. It launders narratives through staged publication: seeding claims through purported citizen journalists or whistleblowers, republishing them through ostensibly independent websites, and amplifying them through social-media accounts, Telegram channels, video platforms, pro-Russian influencers, and related influence ecosystems. The operation has used self-hosted, uncensored large language models to generate and rewrite content at scale across multiple languages. Its infrastructure employs cloned and mirrored web properties to maintain resilience against takedowns. Campaigns have included efforts to undermine Armenian elections and Western-aligned investment, discredit French and German political figures, promote polarization around Alberta separatism in Canada, and disseminate anti-Ukrainian narratives to Western audiences. Storm-1516 has also been assessed as contributing to information-source pollution affecting search results, AI assistants, and other systems that retrieve material from the open web.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
46 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian-linked influence operation targeting German and French political figures using fake videos, ballot-manipulation allegations, and coordinated election-focused disinformation.
Influence operation targeting Western investment in Armenia through media impersonation and disinformation narratives aimed at undermining confidence in the Firebird AI data center project.
Influence operation targeting Armenia’s Firebird AI data center and previously Armenia’s 2026 parliamentary elections, using fabricated narratives and impersonated media content to undermine Armenia’s westward pivot.
Conducting information influence operations using AI-generated deepfake content and media impersonation to target French political figures in a pre-election context.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.