VORANT. Threat Intelligence Sign in Get the full feed

Storm-1516 built fake-news network against Armenia

medium threat government-nationalmedia

Russia-linked Storm-1516 ran 45 disinformation campaigns and a coordinated fake-website network to discredit Armenia's PM ahead of 2026 elections.

DFRLab's investigation documents an extensive Storm-1516 influence operation targeting Armenia since Spring 2025, ahead of the country's 2026 parliamentary elections. The campaign combined coordinated social media amplification (over 1,650 posts across 45 campaigns on X, generating 149.5+ million views) with a network of fake and hijacked websites designed to fabricate and launder stories about Prime Minister Nikol Pashinyan, ranging from assassination plots to corruption and sovereignty-undermining narratives. Storm-1516 has been previously attributed by Microsoft, the US Treasury, and VIGINUM to Russian state-linked actors, including a suspected GRU Unit 29155 officer and the sanctioned Center for Geopolitical Expertise (CGE).

Technical forensics using the Erebus OSINT Toolkit uncovered three distinct website clusters supporting the campaign: burner/hijacked domains (including previously legitimate Armenian sites armeniadaily.am and dailyarmenia.am taken over via proxy registrars), a cluster of 18 Armenian-language sites sharing a bespoke image-naming convention and centrally distributed content, and Turkish media outlets whose content was amplified by Storm-1516-linked social accounts. Strong signals—shared authors (likely fictional personas), byte-identical images, near-simultaneous IP migrations, and DOM structural cloning—indicate centralized operation despite superficial diversity in hosting, language, and geography. The infrastructure pattern (shared WordPress themes, templated builds) aligns with CopyCop, a known Russian-influence-laundering network linked to John Mark Dougan.

Social media analysis found evidence of paid amplification, including accounts previously used in Hungary's election interference and possible compensation schemes for engagement farms in Nigeria and other countries. Highly active accounts like @DangerousThinking (43,000+ posts in 2026, 94% retweets) suggest automation-assisted distribution. The operation's geographic and linguistic diversity (accounts from the US, UK, Turkey, and African nations posting in 11 languages, predominantly English) suggests a deliberate strategy to manufacture the appearance of independent global sources while primarily targeting international rather than domestic Armenian audiences.

Mentioned in this report

Threat actors GRU Unit 29155Storm-1516
Campaigns Storm-1516 Armenia disinformation operation

Source reporting: https://dfrlab.org/2026/07/29/uncovering-the-digital-infrastructure-behind-russian-interference-in-armenian-elections

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free