The Internet Research Agency (IRA) is a Russia-based influence operation organization widely known as a St. Petersburg troll farm. It has been linked to Yevgeniy Prigozhin and is assessed to have supported Russian government disinformation and propaganda objectives. Public reporting and legal actions have tied the IRA to sustained coordinated inauthentic behavior, social media manipulation, and political interference campaigns targeting domestic Russian audiences as well as foreign audiences, especially in the United States and Europe. The IRA became internationally prominent for its role in interference surrounding the 2016 U.S. presidential election. U.S. legal proceedings alleged that it operated large numbers of false personas and social media accounts posing as Americans, organized and promoted rallies, amplified divisive political narratives, and sought to support Donald Trump while disparaging Hillary Clinton. Platform investigations have repeatedly linked later covert influence campaigns to individuals associated with past IRA activity, including operations targeting U.S. racial and social justice debates, European political discourse, and narratives about Ukraine. The organization’s tradecraft centers on coordinated inauthentic behavior across major social platforms and adjacent web infrastructure. Reported methods include creation of fake personas, use of fabricated or compromised accounts, recruitment of unwitting contributors, operation of sham media or think-tank fronts, multilingual content production, cross-platform amplification, and efforts to conceal operator identity and coordination. Historical reporting also describes regimented work schedules, centrally assigned talking points, proxy use, and specialized teams dedicated to building more convincing long-term personas. IRA-linked campaigns have promoted pro-Kremlin narratives on issues including Ukraine, NATO, Western politics, Russian domestic opposition, and Russian geopolitical interests in Africa and the Middle East. Activity attributed or linked to the IRA has targeted audiences in the United States, United Kingdom, Algeria, Egypt, Libya, Sudan, Syria, the Central African Republic, and other countries, often by posing as local voices or independent media. The actor is primarily associated with influence operations rather than traditional network intrusion, although some reporting has loosely associated it with broader Russian information warfare ecosystems that also referenced hacking and botnet activity. High-confidence public attribution most consistently supports its role in propaganda, disinformation, and covert online influence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian proxy troll farm referenced as an example of a covert influence operation that the United States disrupted.
St. Petersburg-based Russian troll farm associated in the content with Storm-1516 and known for election meddling and influence operations.
Conducting foreign influence and disinformation campaigns.
Referenced as a Russian information/disinformation operation that was disrupted by US Cyber Command around the 2018 US midterm elections.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.