Pravda is a Moscow-based pro-Kremlin disinformation network associated with large-scale online narrative amplification and information poisoning. It has been described as flooding the internet with high volumes of pro-Russian content in order to shape information ecosystems and increase the likelihood that those narratives are ingested by search, retrieval, and AI model training pipelines. This activity aligns with influence operations rather than traditional intrusion-focused cyber operations. The network has been linked to efforts to contaminate retrieval-augmented generation and model-training corpora so that AI chatbots reproduce Kremlin-aligned narratives. Its observed tradecraft centers on mass publication and amplification of propaganda content at scale, making it notable as an actor operating at the intersection of disinformation and AI supply-chain manipulation of information sources. High-confidence reporting in the available material supports characterization of Pravda as a Russian disinformation actor, but does not provide sufficient corroborated detail on specific sub-groups, victim countries, or industry targeting beyond its broad role in pro-Kremlin influence activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Moscow-based disinformation network conducting AI ‘well poisoning’ by seeding large volumes of pro-Kremlin content to influence LLM training/RAG corpora and bias chatbot outputs.
Russian disinformation network activity (Catalan branch referenced).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.