Storm-1516, also widely tracked as CopyCop and also referred to as Neva Flood in some reporting, is a Russian state-aligned influence operation focused on large-scale disinformation, media impersonation, and narrative laundering. It has been active since at least 2023 and became especially prominent from 2025 onward through sustained campaigns targeting the United States, France, Germany, Armenia, Moldova, Canada, and other countries. Multiple public attributions link the operation to Russian interests, and French authorities have publicly associated it with GRU Unit 29155. Some reporting further assesses operational ties to John Mark Dougan, the Moscow-based Center for Geopolitical Expertise, and broader Russian influence ecosystems. The operation is known for creating extensive networks of inauthentic websites that masquerade as local news outlets, fact-checking organizations, political movements, and investigative platforms. These sites are used to publish fabricated or manipulated stories that blend factual fragments with false claims in order to imitate legitimate journalism. Storm-1516 also uses forged leaked documents, fake whistleblower personas, counterfeit media brands, deepfake or AI-generated videos, and impersonation of journalists or public figures to seed narratives designed to appear organic and credible. A characteristic Storm-1516 tradecraft pattern involves first introducing a false or misleading claim through a purported whistleblower, citizen journalist, or anonymous persona, then laundering that claim through a network of covert websites in multiple languages, and finally amplifying it through social media accounts, Telegram channels, video platforms, pro-Russian influencers, and adjacent propaganda ecosystems. Public reporting has linked its amplification layer to networks such as InfoDefense, Portal Kombat, and at times Foundation to Battle Injustice, while overlap or interaction with Doppelgänger-style media impersonation ecosystems has also been observed. Storm-1516’s objectives are consistent with Russian geopolitical priorities: undermining support for Ukraine, discrediting Western leaders and institutions, weakening trust in democratic processes, exacerbating political fragmentation, and exploiting local grievances in target states. Its campaigns have targeted elections and public debate, including efforts aimed at U.S. audiences, the 2024 French political environment, German politics, Moldovan elections, and Armenia ahead of its 2026 parliamentary election. In Armenia, the operation has been described as one of the most impactful foreign influence threats, using synthetic media and fabricated reporting to attack pro-Western leadership and inflame existing social and geopolitical tensions. The group has demonstrated significant operational scale and resilience. Reporting from 2025 indicates it operated more than 300 inauthentic websites, including large clusters tailored to specific countries and languages. It has used mirrored infrastructure and cloned sites to survive takedowns and rapidly reconstitute content distribution. Researchers have also assessed that Storm-1516 uses self-hosted uncensored large language models, including variants based on Llama-family models, to generate and rewrite content at scale across multiple languages. This AI-enabled production model supports high-volume narrative output and increases the operation’s ability to localize propaganda for different audiences. Storm-1516 is notable not only for direct audience manipulation but also for contaminating the broader information environment. By flooding the web with synthetic articles and fabricated investigations, it can influence search results, social media discourse, and potentially the outputs of AI assistants and large language models that ingest open-web content. This makes the operation relevant both as a disinformation actor and as a threat to the integrity of the wider information supply chain. Overall, Storm-1516 is best understood as a mature Russian covert influence apparatus that combines classic active-measures concepts with modern AI-assisted content generation, media spoofing, multilingual narrative laundering, and cross-platform amplification. Its aliases include CopyCop and, in some naming schemes, Neva Flood.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
39 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian influence operation using fabricated videos, counterfeit sites, anonymous personas, and synthetic amplification to run high-tempo disinformation and false-flag campaigns.
Referenced as part of a documented 2025–2026 Kremlin information offensive targeting Armenians ahead of Armenia’s 7 June 2026 election.
A Russian malign influence network conducting information operations and disinformation campaigns targeting Armenia, with content aimed at undermining European unity and building support for Russia’s war in Ukraine.
Russian covert influence network linked to fake websites and social media accounts used to target audiences in multiple countries; in this content it targeted Canada and Alberta separatism narratives to sow division and distrust.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.