Doppelgänger is a pro-Russian influence operation active since at least 2022 and widely attributed to Russian entities including the Social Design Agency (SDA) and Structura National Technologies, with multiple reports also linking the activity to direction or control by the Russian Presidential Administration. The operation is also known as Recent Reliable News (RRN). Its strategic objective is to reduce international support for Ukraine, promote pro-Russian narratives, and influence political discourse and elections in countries backing Kyiv. A defining characteristic of Doppelgänger is large-scale impersonation of legitimate media outlets, government entities, and ostensibly independent news brands. The operation uses cloned or lookalike websites, fabricated articles, manipulated videos, caricatures, and in some cases deepfake content. It disseminates narratives in multiple languages including English, German, French, Hebrew, Italian, and Ukrainian, tailoring themes to local political and social fault lines such as immigration, inflation, protests, elections, sanctions, and security concerns. Distribution and amplification rely heavily on coordinated inauthentic behavior across major social platforms, especially X, but also Facebook, Instagram, TikTok, YouTube, and others. Operators have used waves of burner or centrally managed accounts, paid advertisements, fake personas posing as local citizens, and influencer-style amplification. Reported sub-campaigns include Operation Matriochka, which targeted journalists, media outlets, and fact-checkers. The operation has also been linked to election-focused influence efforts in the United States and Europe and to narratives targeting the 2024 Paris Olympics by portraying France as unprepared and insecure. Technically, Doppelgänger has used resilient, scalable web infrastructure built around multi-stage redirection chains, obfuscated JavaScript, traffic-tracking platforms such as Keitaro, rotating redirector domains, geofencing, and redundant hosting. Researchers have also identified parallel infrastructure supporting Russian-language propaganda, suggesting both foreign and domestic information manipulation missions. Reporting further links the operation to abuse-tolerant hosting ecosystems and infrastructure associated with Russian state-linked or pro-Russian activity. The campaign has primarily targeted audiences in France, Germany, Ukraine, and the United States, while also reaching the United Kingdom, Poland, Lithuania, Switzerland, Slovakia, Italy, and Israel. Doppelgänger is best characterized as a state-aligned influence operation whose dominant purpose is geopolitical influence in support of Russian strategic interests rather than conventional cyber intrusion, ransomware, or financially motivated crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
174 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Coordinated Russian influence operation characterized by resilient/scalable infrastructure and systematic media brand impersonation, with geographic micro-targeting across EU member states and the U.S.
Russian disinformation/influence operation leveraging a large domain infrastructure to run coordinated propaganda sites.
Russian disinformation / influence operation focused on infrastructure and information operations rather than malware-centric intrusions (as described here).
Russia-linked influence operation targeting European domestic audiences by impersonating media outlets and pushing Kremlin-aligned narratives (notably anti-Ukraine themes and denigration of pro-European figures).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.