Networks & agencies
Actors & Networks
The organizations, agencies, outlets, and networks behind documented operations — with attribution and its confidence level.
GRU Unit 26165 (APT28 / Fancy Bear)
A unit of Russian military intelligence (GRU) that U.S. authorities attribute the 2016 hacking of the DNC, DCCC and Clinton-campaign accounts to; twelve named GRU officers were indicted in July 2018.
Blackcore
A private Israeli influence company toward which VIGINUM's technical investigation of Rokh Solis pointed. VIGINUM identified an artificial-amplification toolset and similarities with Blackcore campaigns, while explicitly stating that the exact role of the operators behind Rokh Solis remained unresolved.
Center for Geopolitical Expertise
A Moscow-based organization, founded by the OFAC-designated Aleksandr Dugin, that the U.S. Treasury identified as a GRU affiliate used to create and distribute AI-generated disinformation and manipulated media about candidates in the 2024 U.S. election. Treasury designated CGE and its director, Valery Mikhaylovich Korovin, under election-interference authorities; OFAC records the organization as established in 2000, with the GRU-directed U.S.-election activity dating from at least 2024.
Cognitive Design Production Center
An organization the U.S. Treasury identifies as a subsidiary of Iran's Islamic Revolutionary Guard Corps. Treasury designated it after finding that it planned influence operations intended to incite tensions among U.S. voters before the 2024 election.
DRAGONBRIDGE / Spamouflage
A prolific PRC-linked cross-platform influence network tracked by Google TAG. Its output is high-volume and increasingly uses synthetic media, but Google consistently reports very low authentic engagement—a limitation that belongs alongside every account of its scale.
Emennet Pasargad
An Iranian cyber company identified by the U.S. Treasury as the lead organization in the 2020 voter-intimidation and election-disinformation campaign. Treasury reported that the company had supported Iran's Islamic Revolutionary Guard Corps Electronic Warfare and Cyber Defense Organization and rebranded after an earlier sanctions designation.
GRU Unit 74455 (Sandworm)
A unit of Russia's military intelligence (GRU), tracked by researchers as Sandworm, responsible for some of the most destructive state cyber operations on record — the 2015–2016 attacks on Ukraine's power grid, the 2017 NotPetya worm, and the 2018 Olympic Destroyer. In October 2020 the United States indicted six of its officers, including for the April–May 2017 hack-and-leak against Emmanuel Macron's En Marche campaign.
Internet Research Agency (IRA)
A St. Petersburg “troll farm” funded through Yevgeny Prigozhin-linked Concord entities, indicted by the U.S. Special Counsel in 2018 and found by a bipartisan Senate investigation to have run a covert social-media influence operation targeting the 2016 U.S. election.
Islamic Revolutionary Guard Corps
An Iranian state organisation. Google associates the threat actor it tracks as APT42 with the IRGC and documented its 2024 campaign-related phishing; the U.S. Justice Department separately charged three alleged IRGC employees over campaign hack-and-leak activity. U.S. Treasury also identified the Cognitive Design Production Center as an IRGC subsidiary that had planned influence operations targeting U.S. voters since at least 2023. The criminal charges remain allegations unless proved in court, while Treasury's designation is an administrative finding.
PRC-linked Canadian WeChat narrative network
A set of WeChat accounts and Chinese-language media channels that Canada's Rapid Response Mechanism assessed had coordinated false narratives against the Conservative Party, Erin O'Toole and Kenny Chiu during the 2021 federal election. RRM identified links to the PRC information environment but reported no clear evidence that the campaign was directed by the PRC government.
Șor Political and Influence Network
A political-financing, field-mobilization and information network centered on Moldovan politician Ilan Șor. Moldovan authorities and EU sanctions records document Russia-based organizations, a sanctioned Russian bank, Șor-affiliated political vehicles, paid organizers and disinformation around the 2024 presidential cycle; police reported related PSB, Taito and Telegram infrastructure again before the 2025 parliamentary election. The record supports a Russia-linked attribution but does not establish direct Kremlin control of every activity.
Social Design Agency (SDA)
A Moscow public-relations firm identified by France’s VIGINUM, the U.S. Justice Department and EU sanctions as an operator of the Doppelganger information-manipulation campaign.
Star Blizzard
A cyber-espionage group that the UK National Cyber Security Centre assesses is almost certainly subordinate to the Russian FSB's Centre 18. Its long-running spearphishing activity included the compromise of UK-US trade documents later leaked and promoted before the 2019 UK general election. "Star Blizzard" is a Microsoft designation adopted in 2023; at the time of the 2019 leak the group was known as Callisto Group or Seaborgium.
STOIC
An Israeli political campaign-management company identified by OpenAI as the operator behind the covert influence activity it named Zero Zeno. The disrupted accounts generated articles and comments for multiple platforms, including a brief India-focused phase during the 2024 Lok Sabha election. OpenAI's finding identifies the company as an operator; it does not attribute the activity to the Israeli state, and gives no date for when the company itself began operating.
Storm-1679 / Matryoshka operator network
The persistent pro-Russian operator set behind fabricated reports seeded on Russian-language Telegram channels and amplified through Matryoshka's coordinated account system. Public reporting links the method names Storm-1679, Matryoshka and Overload but does not identify all individual operators. VIGINUM records only probable links between the campaign and Russian actors, and states it has no technical evidence tying Matryoshka's methods to third parties; unlike Storm-1516, it is not attributed to a Russian state organ.
TigerWeb
A web-development company based in Russian-occupied Crimea that VIGINUM found played a major role in creating and administering Portal Kombat sites. VIGINUM described it as a possible service provider and did not identify the operator commissioning the network.
UNC1151
A threat cluster that Mandiant assesses with high confidence is linked to the Belarusian government and provides technical support — credential theft and account compromise — to the Ghostwriter influence campaign against Poland, Lithuania, Latvia and Germany. Technical indicators place its operators in Minsk, with evidence of a link to the Belarusian military.