Secondary Infektion is a Russia-linked influence operation active since at least 2014. It is known for coordinated inauthentic behavior conducted across a very large number of online platforms and services, using forged or manipulated material and deceptive personas to seed false narratives and then amplify them across the information ecosystem. The operation has been associated with broader Russian government-linked influence activity, although public attribution in the supplied facts does not identify a specific sponsoring organization beyond Russian geographic origin. The campaign has been used to support pro-Russian narratives and to manipulate political discourse, including activity tied to fabricated documents and other forgeries. Its tradecraft centers on spoofing authentic sources, creating and distributing falsified content, and attempting to influence journalists, researchers, platforms, and public audiences through cross-platform dissemination. Secondary Infektion is best characterized as an information operation rather than a financially motivated intrusion set or ransomware actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as historical background among prior Russian influence campaigns.
Known Russian influence operation referenced as the source of a forged document later amplified by the Ukraine-focused network discussed in the report.
A Russia-linked cross-platform influence operation using strong operational security and burner-style activity to inject narratives into mainstream discourse, with limited breakthrough success.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.