CRC Spotlight: Propaganda, Recruitment and Sabotage: Influence Networks as Emerging Hybrid Threats

Since late July 2026, CRC analysts have investigated a cross-platform infrastructure attributed to a Russian proxy actor, tracked as UNK_SmoothOperator. Mapping the network’s operational assets and recent activity revealed a concerning pattern: alongside Russian state propaganda, the network disseminated explicit calls for Europeans to sabotage EU and NATO targets, as well as recruitment offers on behalf of Russian officials and the Russian Armed Forces.
This Spotlight examines a broader trend exemplified by UNK_SmoothOperator: the use of hostile influence infrastructure to facilitate incitement, recruitment, and mobilization by adversarial actors. When influence networks expand from spreading propaganda to recruiting personnel and inciting physical attacks, influence defense and domestic security stakeholders should assess them as potential high-risk hybrid threats.
CRC assesses that counter-FIMI frameworks focused solely on information manipulation are insufficient to address these threats. A coordinated pan-European response is needed, integrating cognitive security, narrative intelligence, and counterintelligence.
Remediation
CRC has classified UNK_SmoothOperator as a high-risk hybrid threat cluster. In September 2026, CRC published a CDN Incident Alert and shared additional information with relevant partners.
A supplementary report detailing the investigation’s findings and insights will be published soon.
[Download the full report here]
_edited.png)
.png)



