Internet Research Agency
The Internet Research Agency (IRA) is a St. Petersburg-based Russian troll farm and influence operation organization. The content describes it as Russia-based and Kremlin-linked, and in multiple sources as a proxy troll farm used to conduct coordinated online propaganda, disinformation, and election interference. It is also referred to as the St. Petersburg troll farm, Sankt Petersburg troll factory, and Russian troll factory. The organization was established in 2013; one source states it was established by Yevgeny Prigozhin, who is also described as a financier of the IRA. The Trump administration sanctioned it in 2018 for interfering in the 2016 U.S. election. The IRA is described as having employed hundreds of Russians to post pro-Kremlin propaganda online under fake identities across platforms including Facebook, Twitter, Instagram, VKontakte, LiveJournal, and comment sections on Russian news sites. Reporting in the content says workers used proxy services to conceal their IP addresses, operated from detailed daily talking points tied to current events, and maintained multiple departments, including a more selective “Special Projects” unit that built convincing personas. The organization has been linked in the content to fake stories, botnets, hacking, and online hoaxes. The IRA repeatedly used complex networks of inauthentic accounts to deceive and manipulate audiences in the United States, Europe, and Russia. The content states that it began efforts to meddle in U.S. politics in May 2014 and that by early to mid-2016 its operations included supporting Donald Trump and disparaging Hillary Clinton. Special Counsel Mueller’s indictment and report, as cited in the content, state that the IRA conducted a coordinated campaign targeting the United States, including through 470 Facebook accounts and pages, specifically crafted messaging aimed at interfering in the 2016 election, creation of social media accounts targeting U.S. politicians and public figures, and organization of rallies while posing as Americans. The content also notes that IRA-linked accounts were identified on Twitter and that Russian-linked automated accounts retweeted @realDonaldTrump far more often than @HillaryClinton during the 2016 period. The IRA is described as conducting information warfare against political opponents in Russia and perceived enemies abroad, including propaganda related to Ukraine and Russian domestic affairs. Additional content associates veterans of the IRA with later Russian influence operations and notes that Storm-1516 has been associated with the St. Petersburg-based IRA. U.S. Cyber Command reportedly took the IRA offline for several days around the 2018 U.S. midterm elections.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian proxy troll farm referenced as an example of a covert influence operation that the United States disrupted.
St. Petersburg-based Russian troll farm associated in the content with Storm-1516 and known for election meddling and influence operations.
Conducting foreign influence and disinformation campaigns.
Referenced as a Russian information/disinformation operation that was disrupted by US Cyber Command around the 2018 US midterm elections.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.