Full Report
Ahead of Moldova’s 2025 elections, Russia-linked influence operations seek to undermine EU integration, discredit President Sandu, and destabilize democratic processes through coordinated disinformation campaigns and hybrid tactics.
Analysis Summary
# Threat Actor: Russian Influence Operations (General Designation)
## Attribution & Identity
The activity is consistently linked to **Russia-linked influence operations (IOs)** aimed at achieving Kremlin objectives regarding Moldova.
Known associated groups/operations include:
* **Operation Overload** (also tracked as Matryoshka, Storm-1679)
* **Operation Undercut** (activity observed on TikTok for the first time)
* **Foundation to Battle Injustice** (a Russia-based NGO)
* **Portal Kombat** (ecosystem including Pravda Moldova)
* Networks associated with Moldovan oligarch **Ilan Shor’s “Evrazia” organization**
* **Moldova24** (a very likely Shor-sponsored, Russia-state-backed television network)
## Activity Summary
Multiple Russian influence operations are actively converged on destabilizing **Moldova’s September 28, 2025, parliamentary elections** and derailing the country's accession to the European Union (EU).
Key campaigns observed include:
* A vilification campaign against Moldovan President **Maia Sandu** and the ruling **Party of Action and Solidarity (PAS)**, active since at least April 2025 (Operation Overload).
* The Foundation to Battle Injustice publishing inauthentic investigations designed to damage the credibility of President Sandu and PAS.
* Operation Undercut actively targeting Moldovan social media users with anti-Sandu, anti-PAS, and anti-European integration messaging.
* Shor-linked entities (Evrazia and Moldova24) disseminating anti-Sandu messages through social media advertising.
* Pravda Moldova (part of Portal Kombat) serving as a high-volume amplifier and launderer of pro-Kremlin content.
The overarching narrative theme is framing the current Moldovan leadership as corrupt, portraying EU integration as disastrous, and suggesting a closer relationship with the Kremlin is favorable.
## Tactics, Techniques & Procedures
* **Influence Operation (IO):** Coordinated information warfare campaigns across multiple platforms.
* **Vilification Campaign:** Specifically targeting President Sandu for character assassination (Operation Overload).
* **Inauthentic Reporting:** Publishing "inauthentic investigations" to damage credibility (Foundation to Battle Injustice).
* **Narrative Amplification:** Projecting negative views of EU integration and associating the West with disastrous outcomes.
* **Election Interference:** Conditioning audiences to expect rigged elections (Operation Undercut) and undermining election security/integrity.
* **Social Media Exploitation:** Use of Facebook advertising (Shor/Moldova24) and activity on TikTok (Operation Undercut).
* **Content Laundering:** Using dedicated media assets (Pravda Moldova) to amplify pro-Kremlin messaging.
* **AI Manipulation:** Portal Kombat ecosystem members were recently identified as engaging in **poisoning the output of artificial intelligence chatbots**.
* **Incitement (Mentioned as historical/contextual risk):** Inciting protest violence in Russian-speaking regions like Gagauzia and Transnistria.
## Targeting
* **Sectors:** Domestic Moldovan political landscape; International perception regarding Moldovan EU accession.
* **Geography:** Primarily **Moldova**, with content aimed at manipulating both international and domestic public perceptions.
* **Victims:** Moldovan President **Maia Sandu**; Ruling **Party of Action and Solidarity (PAS)**; Moldovan voters generally.
## Tools & Infrastructure
* **Malware Families Used:** Not explicitly detailed for these influence operations.
* **Infrastructure (C2, domains, IPs):**
* **Operation Undercut Social Media Handles (examples):** @aaron2492397222, @hubbard_tr92086, @jenkinS\_ma18433, @JamesSanto1236
* **Foundation to Battle Injustice Domains:** fondfbr[.]ru, vtforeignpolicy[.]com, eadaily[.]com, londontimes[.]live, bakomkulisserna[.]info
* **RT- and MD24-Affiliated Domains (hosted on 95[.]181[.]226[.]185):** ahilesva[.]info, mldvideo24[.]pro, news-365[.]ru, artel[.]watch, moldova24[.]online, rtdoc[.]tv, etc.
* **Portal Kombat’s Pravda MD Domains:** md[.]news-pravda[.]com, pravda-md[.]com, moldova[.]news-pravda[.]com
## Implications
These operations pose significant risks to **media integrity and public trust** ahead of the 2025 elections. While current success in shaping opinion is limited, the potential for scaling up volume poses a threat. Narratives aimed at undermining election security could suppress voter turnout, and consumption of inauthentic content risks amplifying malign messaging. The actors are focused on fundamentally shifting Moldova away from the EU path and restoring pro-Russian alignment.
## Mitigations
* Monitor the identified sources (IOs and infrastructure) to inform public messaging strategies.
* Bolster election-related cyber defenses.
* Proactively expose the malign influence operations to reduce their potential impact on public discourse and voter behavior.