Skip to main content
Mallory

Matryoshka

Also known asmatryoshka

Matryoshka is a Russian disinformation and influence operation first identified in 2024 and linked in the provided reporting to the Moscow-based Social Design Agency and broader Kremlin influence activity. The operation has targeted Moldova, Ukraine-related narratives, France, Armenia, Romania, EU countries, and the 2024 Paris and 2026 Milano-Cortina Olympics. Its objectives described in the content include eroding support for Ukraine, swaying public opinion and elections, discrediting Western institutions and major events, and amplifying false narratives favorable to Russian state interests. The operation specializes in fabricated content that imitates legitimate Western media outlets, including Reuters, France 24, CBC, Euronews, and OK! magazine. Reported tactics include fake articles, fake news videos, AI-generated and AI-doctored media, AI voice cloning, impersonation of media brands and public officials, bot-network amplification across Twitter/X, BlueSky, TikTok, Telegram, Facebook, Instagram, and YouTube, and direct outreach to journalists and fact-checkers to draw attention to false content so it will be debunked and further amplified. Researchers cited in the content state that Russian outlets then reference the fabricated material to falsely suggest the narratives originated in the West. Specific activity in the content includes 39 fabricated narratives targeting Moldova over a three-month period ahead of parliamentary elections; anti-Maia Sandu influence content, often described as misogynistic in tone; expansion to YouTube; and a BlueSky campaign in which hundreds of real accounts were hijacked to post fake articles and videos. During the Milano-Cortina 2026 Winter Olympics, Matryoshka reportedly used AI voice cloning to fabricate CBC and Euronews-style segments, including false claims about Ukrainian athletes being segregated in the Olympic Village. The content also notes prior campaigns aimed at discrediting preparations for the Paris 2024 Olympics and a USAID-themed disinformation effort. Known aliases and linked entities directly mentioned in the content include Matryoshka and the Social Design Agency. The content consistently characterizes the operation as Russian/Kremlin-linked.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Media & Entertainment

Where they target

Geographies tied to known operations.

  • 🇨🇦 Canada
MITRE ATT&CK

Tradecraft

9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

7 of 15 tactics11 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1598
Phishing for Information
TA0042
Resource Development
3 techniques
T1583
Acquire Infrastructure
T1585×3
Establish Accounts
T1585.001
Social Media Accounts
T1586
Compromise Accounts
TA0001
Initial Access
1 technique
T1078
Valid Accounts
TA0003
Persistence
1 technique
T1078
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078
Valid Accounts
TA0005
Stealth
2 techniques
T1036×2
Masquerading
T1078
Valid Accounts
TA0040
Impact
1 technique
T1531
Account Access Removal
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping9

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.