top of page


Ceuta and Melilla: Russian-Aligned Narrative Exploitation of the Border Crisis
CRC analyzed hundreds of posts across eleven languages following the 30 July 2026 Ceuta/Melilla border crossing, mapping five narrative clusters from "invasion" framing to conspiracy theories alleging a US-Israel-Morocco plot over the Strait of Gibraltar. The blog traces a decontextualized 2019 tweet used as false "evidence," flags RT's selective amplification, and argues the crisis has a digital-cognitive dimension serving Russian, Chinese, and Iranian interests.
Jul 31


Counter-FIMI as FIMI: Russian Narrative Manipulation and Reputational Hijacking
Hybrid threat actors increasingly exploit credibility in influence campaigns by posing as research institutes, news outlets, or open-source investigation platforms to appear trustworthy. This blog examines three models: OSINT investigation platforms, impersonated news outlets, and pseudo research institutes—all leveraging borrowed legitimacy to spread misleading narratives while disguising state-dictated agendas.
Jul 29


Iran War Post-MoU: From Cyfluence Operations to STRATCOM Efforts
Hybrid threat actors increasingly exploit credibility in influence campaigns by posing as research institutes, news outlets, or open-source investigation platforms to appear trustworthy. This blog examines three models: OSINT investigation platforms, impersonated news outlets, and pseudo research institutes—all leveraging borrowed legitimacy to spread misleading narratives while disguising state-dictated agendas.
Jul 15


How Dating Apps Became Vectors for Cyber Attacks and Influence Operations
Hybrid threat actors increasingly exploit credibility in influence campaigns by posing as research institutes, news outlets, or open-source investigation platforms to appear trustworthy. This blog examines three models: OSINT investigation platforms, impersonated news outlets, and pseudo research institutes—all leveraging borrowed legitimacy to spread misleading narratives while disguising state-dictated agendas.
Jun 29


Borrowed Legitimacy: Three Models of Credibility Abuse in Influence Operations
Hybrid threat actors increasingly exploit credibility in influence campaigns by posing as research institutes, news outlets, or open-source investigation platforms to appear trustworthy. This blog examines three models: OSINT investigation platforms, impersonated news outlets, and pseudo research institutes—all leveraging borrowed legitimacy to spread misleading narratives while disguising state-dictated agendas.
Jun 15


Behind the Curtain: Leaked SDA Files, Russian Influence Operations, and Defensive Cyfluence
This blog article examines the paradox of authoritarian information control through the case of Russia and Telegram. While the Kremlin seeks to restrict the platform and promote the state-aligned messenger MAX, Telegram remains essential for military communication, propaganda, and influence operations. This creates a structural dilemma: authoritarian regimes aim for total control over information flows but remain dependent on open digital platforms they cannot fully govern.
Jun 1


Mad MAX: The Kremlin’s Attempt at Complete Information Control
This blog article examines the paradox of authoritarian information control through the case of Russia and Telegram. While the Kremlin seeks to restrict the platform and promote the state-aligned messenger MAX, Telegram remains essential for military communication, propaganda, and influence operations. This creates a structural dilemma: authoritarian regimes aim for total control over information flows but remain dependent on open digital platforms they cannot fully govern.
Mar 16


Once More Unto the Breach: Cyfluence Operations Hijack Iran’s State Media Amid Internet Shutdowns
This blog analyzes a recent cyfluence operation that briefly hijacked Iranian state TV amid a nationwide internet blackout. It focuses onRecently, activists briefly hijacked Iranian state television. This blog analyzes the events surrounding what may be a recent cyfluence operation.
Jan 21


The Sound of Silence: Detecting Influence Operations Through Internet Blackouts
Following Iran’s nationwide internet blackout, the sockpuppet accounts driving several coordinated narrative strands abruptly stopped posting in near unison. This repeated blackout-to-silence pattern is a strong indicator of foreign CIB and materially increases confidence in attribution to Iran-based operators.
Jan 14


This Time it’s Personal: China Targets the Human Factor in Cyber-Influence Defense
China is increasingly using “counter-operator” measures: instead of only targeting content, it pressures the people behind influence and cyber operations through bounties, doxxing, sanctions, and “naming and shaming” (e.g., Taiwan, Canada). The aims are deterrence, degrading adversary capabilities, and narrative control.
Dec 16, 2025


Anthropic’s Report and Its Implications for Cyfluence Operations
Anthropic claims that Claude Code ran most parts of a cyber-espionage intrusion on its own. Experts doubt this because clear technical proof is missing. The text applies this disputed case to HIC and Cyfluence. It asks how agentic AI could speed up influence workflows, automate key tasks, and scale operations. If such autonomy becomes reliable, the technical phases of influence campaigns could expand in speed and impact.
Dec 9, 2025


Tonga Before the Election: Influence and the Information Space
Tonga votes on 20 Nov 2025. The Pacific monarchy faces economic dependence, regional competition, and growing information disorder. Local efforts exist, but limited institutional capacity leaves gaps ahead of the elections.
Nov 10, 2025


Not All-Powerful: A Granular Perspective on Influence Networks
This blog introduces the actor-specific, granular analytical approach, which assesses digital influence operations by examining actors, structures, and intentions, rather than treating them as a uniform threat. Using IRSEM’s "Baybridge" case, it shows how bureaucratic incentives and commercial self-interest can undermine strategic effectiveness.
Oct 27, 2025


Dancing with Cyfluence – Travolta, Telegram & the Moldovan Leak
A September 3 data leak exposed internal files of pro-Russian Moldovan politician Ilan Shor and his “Victorie Bloc,” revealing a financed influence network linked to Russia. The leak, paired with targeted intimidation messages, severely disrupted the group. Analysts view it as a coordinated “Cyfluence Counteroperation” that effectively neutralized and delegitimized Shor’s organization just before Moldova’s elections.
Oct 12, 2025


Influence in Czechia: Digital Battles Ahead of the 2025 Elections
The Czech parliamentary elections on 3–4 October 2025 face heavy digital interference. Russia and increasingly China exploit Telegram networks, disinformation portals, and fake TikTok accounts to spread distrust, voter apathy, and anti-Western narratives. According to CERA, the main risks are erosion of democratic trust, voter demobilization, and the strengthening of populist and pro-Russian forces.
Oct 2, 2025


Influence in Moldova: Coordinated Campaigns Ahead of Critical Elections
The FDEI Country Report highlights how influence in Moldova is being shaped by coordinated campaigns targeting the 2025 elections. Russian-linked networks deploy cloned news sites, Telegram bots, and AI-generated content to spread disinformation and manipulate public perception. These campaigns aim to erode trust in institutions, polarize the electorate, and undermine cooperation with the EU and neighboring states.
Sep 26, 2025


Stark Industries Solutions: A Threat Activity Enabler (TAE) in Focus
This blog examines how Stark Industries Solutions acted as a Threat Activity Enabler (TAE) in hostile cyber and influence operations. It explores the company’s role in providing resilient infrastructure for disinformation and attacks, its sanctioning by the EU in May 2025, subsequent rebranding moves, and why infrastructure-focused analysis is essential to track continuity behind shifting names and entities.
Sep 21, 2025


Vietnam Framed Villain, China Not Found: Influence Ops on Repeat
This week, we turn to a case study from Philstar. The report examines a coordinated influence operation on X (formerly Twitter) that was active from late 2024 to mid-2025, with the goal of framing Vietnam as the main aggressor in the South China Sea.
Sep 9, 2025


Cross-border influence targeting Romania’s vote and Moldova’s leadership
This week, our Weekly Blog highlights a recent DFRLab report uncovering a coordinated network of at least 215 cross-platform accounts – 116 on Facebook, 79 on TikTok, and 17 on Instagram. Between December 2024 and June 6, 2025, these accounts generated 8,514 posts, attracting more than 16 million views and 681,000 likes. The investigation reveals how pro-Russian influence targeting Romania Moldova has been systematically amplified through this network, exploiting major social
Aug 29, 2025


Beyond Contractors: China’s Cyber Militia Model
The China cyber militia model shows how civilian, state, and military actors are fully interconnected. Rather than outsourcing, Beijing embeds information operations within this system, blurring boundaries and ensuring all parts can be mobilized as extensions of state power.
Aug 21, 2025
bottom of page
_edited.png)
.png)