Full Report
The Czech outlet Seznam Zprávy has exposed an operation by the Russian propaganda project Rybar to film a documentary series in Europe. The publication’s…
Analysis Summary
# Incident Report: Exposure of Rybar Propaganda Operation in Europe
## Executive Summary
The Czech investigative outlet *Seznam Zprávy* exposed a covert influence operation by the Russian propaganda entity Rybar, which attempted to film a documentary series in Europe. Journalists conducted a counter-operation, luring a Russian film crew to Prague to reveal their ties to sanctioned Russian state entities and intelligence-linked organizations. The incident highlights Rybar’s transition from digital disinformation to physical reconnaissance and influence operations within EU borders.
## Incident Details
- **Discovery Date:** September 23, 2026 (Public reporting date)
- **Incident Date:** Mid-September 2026
- **Affected Organization:** Czech Elves (Targeted), Rybar (Exposed)
- **Sector:** Media / Information Security / Civil Society
- **Geography:** Czechia (Prague), Germany (Berlin), Russia (Moscow)
## Timeline of Events
### Initial Access
- **Date/Time:** September 2026
- **Vector:** Social Engineering / Direct Contact
- **Details:** A producer using the pseudonym "Boris" (identified as Boris Dvorkin) contacted Bohumil Kartous of the Czech Elves via WhatsApp using a Russian phone number to solicit an interview for a "documentary."
### Lateral Movement (Physical/Geographical)
- The film crew, consisting of Vitaliy Chashchukhin and Igor Dolmatov, traveled from Berlin, Germany, to Prague, Czechia, to conduct interviews. They had previously been active in other European countries for the same project.
### Data Exfiltration/Impact
- The operation aimed to collect interviews and visual footage to be repurposed for "Rybar," a Telegram-based project used for information warfare and interference in foreign elections.
### Detection & Response
- **Detection:** *Seznam Zprávy* journalists recognized the solicitation as a propaganda front and coordinated a sting operation.
- **Response:** Journalists accompanied the target (Kartous) to the meeting, utilized hidden cameras to record admissions of Rybar’s involvement, and confronted the crew, causing them to flee.
## Attack Methodology
- **Initial Access:** Social Engineering via WhatsApp messaging.
- **Persistence:** Use of legitimate-appearing press credentials and residence permits (Germany) to move freely within the Schengen Area.
- **Defense Evasion:** Use of shell projects ("documentary series") and pseudonyms to mask the involvement of sanctioned entities.
- **Discovery:** Reconnaissance on European disinformation experts and media literacy activists.
- **Collection:** Audio/Visual recording for information warfare.
- **Impact:** Manipulation of public perception; portrayal of European economic decline.
## Impact Assessment
- **Financial:** N/A (Project funded by Rostec/Prigozhin-linked entities).
- **Data Breach:** None; counter-operation prevented compromised narratives.
- **Operational:** Disruption of a multi-country propaganda tour.
- **Reputational:** Significant blow to Rybar’s ability to operate covertly in the EU; public exposure of film crew members.
## Indicators of Compromise
- **Network Indicators:** WhatsApp communications from Russian country codes (+)7.
- **Behavioral Indicators:** Requests for interviews by "independent" producers who, when pressed, reveal ties to sanctioned entities like Rybar or the History of the Fatherland Foundation.
- **Key Actors:**
- Vitaliy Chashchukhin (Correspondent for Izvestia/Channel Five)
- Igor Dolmatov (Cameraman)
- Boris Dvorkin (Producer/Recruiter)
- Mikhail Zvinchuk (Rybar Founder - Sanctioned)
## Response Actions
- **Containment:** Counter-investigation by local journalists to identify the actors before the propaganda could be published.
- **Eradication:** Identification and public naming of the individuals involved to burn their "press" cover.
- **Recovery:** Public reporting to warn other European experts of the specific social engineering tactics used by Rybar.
## Lessons Learned
- **Social Engineering Sophistication:** Threat actors are utilizing professional film crews and documentary formats to gain access to high-profile targets.
- **Physical-Digital Link:** Digital propaganda outlets (Rybar) are increasingly deploying physical assets in Europe to gather content.
- **Verification:** Verification of "producers" and "journalists" via leaked databases and reverse-image searches is effective in identifying covert operatives.
## Recommendations
- **Verification Protocols:** Individuals targeted for interviews by unknown media entities should verify credentials through official channels and check for ties to sanctioned organizations.
- **Cross-Border Intelligence:** EU states should monitor the movement of media personnel affiliated with sanctioned Russian outlets (e.g., Izvestia, REN TV) who may be moonlighting for covert projects like Rybar.
- **Public Awareness:** Educate civil society groups on the "Rybar" recruitment model—using historical or analytical "foundations" as fronts for intelligence gathering.