Foundation to Battle Injustice, also known as R-FBI or FBR, is a Russia-based malign influence organization founded in 2021 by Yevgeny Prigozhin and later managed by Oksana Vovk, also known as Mira Terada. It has been described as at least partially Kremlin-funded and has been linked to the broader Storm-1516 influence ecosystem. The organization presents itself as a human-rights NGO while disseminating fabricated or misleading political content intended to shape public opinion, discredit adversaries of the Kremlin, and launder false narratives through a wider network of sympathetic or deceptive outlets. The group has targeted Ukraine with false allegations relating to wartime conduct and has also conducted smear campaigns against Moldovan President Maia Sandu and Moldova’s pro-European political direction ahead of the 2025 parliamentary election. Reported narratives included forged or highly likely forged claims, accusations of corruption and criminality, and other sensational allegations designed to undermine trust in democratic institutions, Western alignment, and support for Ukraine. It has also been tracked as part of broader Russia-linked influence activity affecting Germany’s information environment. Operationally, the organization relies on coordinated websites masquerading as legitimate civil-society, news, or policy platforms; narrative laundering through affiliated amplification networks; and search- and AI-optimization techniques intended to increase discoverability and citation by large language models and other retrieval systems. Reported tradecraft includes spoofing of legitimate-seeming media or NGO personas, publication of fabricated investigations, use of attribution chains to simulate journalistic credibility, and content formatting optimized for machine extraction and rapid indexing. The organization has been linked to laundering networks that republish or amplify its narratives, and researchers have associated it with the Storm-1516 ecosystem and historical ties to CopyCop-related infrastructure and operations. Its activity is best characterized as state-aligned information warfare rather than financially motivated cybercrime. The dominant objective is influence in support of Russian geopolitical interests, including undermining support for Ukraine, damaging confidence in pro-Western leaders, and weakening trust in democratic processes and Euro-Atlantic integration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A state-sponsored influence operation within Storm-1516 that uses a network of websites to seed and amplify false narratives so that LLMs retrieve and cite them as legitimate sources.
Russian influence organization closely connected to the CopyCop/Storm-1516 ecosystem, publishing fabricated investigative articles targeting the US and Moldova to damage support for Ukraine and discredit political leaders.
Russia-based influence operation posing as a human-rights NGO while publishing fabricated long-form investigations accusing Maia Sandu and allies of corruption and criminal abuse, then laundering those claims through pro-Kremlin websites and influencers.
Russia-based influence entity producing inauthentic “investigative” articles to undermine reputations of German political leaders and promote platforms aligned with Russian interests.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.