Disinformation undermines true journalism and steers the public opinion in highly charged topics such as immigration, climate change, armed conflicts or refugee and health crises. Social media platforms are the battlefield of disinformation.
The war in Ukraine is no exception. This investigation presents how a large disinformation campaign targeting European audience with pro-Russian propaganda was active in social media for months. What started as an investigation of media clones of the German Der Spiegel, Bild and T-Online turned out to be a fascinating dive into the multimedia world of disinformation production.
Tracing the infrastructure of a few websites helped us to discover dozens of websites spreading Russian propaganda related to the war in Ukraine. The campaign undermined the Ukrainian government, its citizens, and Western governments supporting Ukraine and supported the lift of sanctions against Russia.
Qurium’s infrastructure research does not only show how European infrastructure has been used to host the fake news sites, but also how new domains have been registered to keep the campaign running in the very same physical servers.
Qurium’s investigation is the result of a collaboration with EU DisinfoLab, an independent non-profit organization focused on tackling sophisticated disinformation campaigns targeting the EU. Qurium has focused on the technical aspects of the campaign.
Qurium forensics report:
Under the hood of a Doppelgänger
EU DisinfoLab report:
Doppelganger
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Disinformation)
[adrotate banner=”5″]
[adrotate banner=”13″]
Security Affairs Malware newsletter includes a collection of the best articles and research on malware…
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best…
Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…
A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…
A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…
This website uses cookies.