InfoDefense is a pro-Kremlin influence network centered on Telegram channels that disseminate disinformation and propaganda related to Russia’s war against Ukraine to international audiences. The network has operated across more than ten languages and more than twenty countries, presenting itself as a source of truthful information while amplifying Kremlin-aligned narratives, Russian state messaging, and content from official Russian diplomatic and state-media sources. It is closely linked to the Node of Time network and has also been observed amplifying or being amplified by other Russian influence ecosystems, including CopyCop and Portal Kombat. The network is characterized by coordinated channel creation, shared branding, extensive cross-posting, and multilingual forwarding behavior across language communities. A large cluster of interconnected InfoDefense channels frequently redistributed each other’s posts despite language barriers, indicating organized amplification rather than organic audience overlap. Operational tradecraft appears relatively unsophisticated, with evidence of machine translation, non-native language production, public recruitment of volunteer translators and editors, and limited obfuscation. Despite these weaknesses, the network achieved broad international reach. InfoDefense content has targeted foreign audiences with pro-Russian, anti-Ukrainian, and anti-Western narratives, particularly in Europe and other regions where support for Ukraine is politically salient. The network has relied heavily on reposting statements and narratives from Russian officials, state media, and Russian embassies abroad, including embassy channels in multiple countries. Its role is best understood as influence operations and narrative amplification in support of Russian state objectives rather than financially motivated cybercrime or ransomware activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian influence network used to amplify CopyCop-promoted narratives, including anti-Ukraine messaging.
A large multilingual pro-Kremlin Telegram disinformation network that acted as a hub for translated propaganda, recruiting volunteers to translate and distribute content in numerous languages for global dissemination.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.