Skip to main content
Mallory
Back to threat actors
🇷🇺 RU

Internet Research Agency

Also known asinternet_research_agency

The Internet Research Agency (IRA) is a St. Petersburg-based Russian troll farm and influence operation organization. The content describes it as Russia-based and Kremlin-linked, and in multiple sources as a proxy troll farm used to conduct coordinated online propaganda, disinformation, and election interference. It is also referred to as the St. Petersburg troll farm, Sankt Petersburg troll factory, and Russian troll factory. The organization was established in 2013; one source states it was established by Yevgeny Prigozhin, who is also described as a financier of the IRA. The Trump administration sanctioned it in 2018 for interfering in the 2016 U.S. election. The IRA is described as having employed hundreds of Russians to post pro-Kremlin propaganda online under fake identities across platforms including Facebook, Twitter, Instagram, VKontakte, LiveJournal, and comment sections on Russian news sites. Reporting in the content says workers used proxy services to conceal their IP addresses, operated from detailed daily talking points tied to current events, and maintained multiple departments, including a more selective “Special Projects” unit that built convincing personas. The organization has been linked in the content to fake stories, botnets, hacking, and online hoaxes. The IRA repeatedly used complex networks of inauthentic accounts to deceive and manipulate audiences in the United States, Europe, and Russia. The content states that it began efforts to meddle in U.S. politics in May 2014 and that by early to mid-2016 its operations included supporting Donald Trump and disparaging Hillary Clinton. Special Counsel Mueller’s indictment and report, as cited in the content, state that the IRA conducted a coordinated campaign targeting the United States, including through 470 Facebook accounts and pages, specifically crafted messaging aimed at interfering in the 2016 election, creation of social media accounts targeting U.S. politicians and public figures, and organization of rallies while posing as Americans. The content also notes that IRA-linked accounts were identified on Twitter and that Russian-linked automated accounts retweeted @realDonaldTrump far more often than @HillaryClinton during the 2016 period. The IRA is described as conducting information warfare against political opponents in Russia and perceived enemies abroad, including propaganda related to Ukraine and Russian domestic affairs. Additional content associates veterans of the IRA with later Russian influence operations and notes that Storm-1516 has been associated with the St. Petersburg-based IRA. U.S. Cyber Command reportedly took the IRA offline for several days around the 2018 U.S. midterm elections.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States

Where they're from

Attributed origin per open-source reporting.

  • RU
MITRE ATT&CK

Tradecraft

11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

5 of 15 tactics12 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1591
Gather Victim Org Information
TA0042
Resource Development
4 techniques
T1583
Acquire Infrastructure
T1583.001
Domains
T1584
Compromise Infrastructure
T1584.008
Network Devices
T1585×6
Establish Accounts
T1585.001×3
Social Media Accounts
T1586
Compromise Accounts
TA0005
Stealth
1 technique
T1036
Masquerading
TA0007
Discovery
1 technique
T1654
Log Enumeration
TA0011
Command and Control
1 technique
T1090
Proxy
T1090.003
Multi-hop Proxy
IOCS

Observables

1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping11

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables1

Domains, IPs, and hashes tied to this actor, refreshed continuously.