Uncovering the digital infrastructure behind Russian interference in Armenian elections

How Russia’s Storm-1516 reached millions of social media users with fabricated stories about Armenia.

Uncovering the digital infrastructure behind Russian interference in Armenian elections

Share this story
THE FOCUS

BANNER: Cluster of Armenian-language Storm-1516 domains sharing behavioural signals. (Source: Erebus OSINT Toolkit)

Since Spring 2025, Storm-1516 has been running coordinated disinformation campaigns against Armenia and its leadership, spreading fabricated stories ranging from assassinations to marriage scandals. Using website forensics and social media analysis, this investigation examines forty-five campaigns attributed to Storm-1516 that targeted Armenia and illustrate how open-source investigation methods can expose the infrastructure behind election interference. 

Storm-1516 is one of the most active Russian “information manipulation sets” (IMS), which conducts influence operations against multiple countries. It has been attributed to Russian state actors by multiple sources. Microsoft describes the operation as a likely offshoot of Russia’s Internet Research Agency. The US Department of the Treasury sanctioned the Center for Geopolitical Expertise (CGE) for directing and subsidizing the creation and publication of deepfakes and disinformation targeting candidates in the 2024 US election. VIGINUM, in turn, noted that designation could indicate CGE may be responsible for creating and disseminating Storm-1516’s content. A suspected GRU Unit 29155 officer has been publicly accused of financing and coordinating Storm-1516 since its inception, per the Washington Post. VIGINUM corroborated the links but couldn’t confirm his direct involvement.

Ahead of its 2026 parliamentary elections, Armenia was one of the most heavily targeted countries by Russia’s disinformation ecosystem. According to estimates from the Institute for Strategic Dialogue, the scale of the recent Storm-1516 campaigns against Armenia was more extensive than that of any other country. Most of the campaigns documented in this investigation aimed to discredit Prime Minister Nikol Pashinyan and undermine public trust in the Armenian government. 

On X

The selected campaigns covered a wide range of political, cultural, economic, and security-related claims, but most of them promoted several recurring narratives. Several campaigns portrayed Pashinyan and his government as undermining Armenia’s traditional and Christian identity through the alleged promotion of an LGBTQ+ agenda, the construction of mosques, and the preferential treatment of Islam. Others claimed that authorities were weakening Armenia’s sovereignty by making territorial concessions, allowing the establishment of a Turkish military base in Armenia, abandoning recognition of the Armenian Genocide, or facilitating the mass resettlement of refugees from the Middle East. Several campaigns also focused on alleged corruption, misuse of public funds, and non-transparent agreements with foreign companies. Personal allegations against Pashinyan, his wife, and other senior officials were also used to reinforce the broader narrative that the government was corrupt or acting against Armenia’s national interests. 

For the social media analysis, we collected over 1,650 original posts across forty-five campaigns on X targeting Armenia between June 2025 and June 2026. Posts were analyzed and categorized across five different categories.

A network analysis of more than 450 X accounts that appeared across most of the campaigns revealed a distinct cluster of closely connected accounts. Many of these accounts were previously spotted engaging in other foreign elections. The DFRLab conducted a cross-campaign network analysis to identify accounts that appeared together most frequently across campaigns. The connection (edge) was established between accounts in the same campaign. The more frequently accounts appeared together, the thicker the edge. The graph below shows connections between accounts that appeared together in at least five campaigns.

Network graph showing X accounts that appeared together in more than five campaigns.

The DFRLab conducted an AI-assisted text similarity analysis that revealed a primary and secondary cluster of accounts that were posting close-to-similar messages across the forty-five analyzed campaigns. Messages were first translated into English using the Google Translate function in Google Sheets. The similarity analysis was then performed using a Python script; a large language model (Claude Sonnet 4.6) was used to help write that script.

The script calculated term frequency (TF) for both unigrams (single terms) and bigrams (pairs of consecutive terms) and weighted these by inverse document frequency (IDF), computed as log (total posts/posts containing the term or term pair), to isolate the terms that make a post distinctive relative to the others. Multiplying TF by IDF produced a value for each term, and the script calculated cosine similarity between posts within each campaign. Cosine similarity ranges from 1 for identical posts to 0 for posts sharing no terms. We treated scores above 0.75 as high similarity, signaling coordinated, template-based posting.

Fifty-six of 529 messages, or over 10 percent, were translated into English for comparison. Machine translation tends to normalize varied source-language phrasing into common English wording, which reduces the lexical variation the metric depends on. This may have resulted in slightly inflated scores, which we note as a limitation of the approach.

Further, accounts reporting on the same event will share vocabulary regardless of whether they are coordinated. Journalists covering a single election, for instance, independently rely on the same names, places, and terminology, so high similarity is not on its own proof of coordination. We note that similarity was assessed only within campaigns and against a deliberately high threshold, and we note shared-topic convergence as a factor that our score cannot fully distinguish from coordination.

The results showed the most frequently connected accounts across the campaigns are the same as those visible on the network map. Namely, @TFMDMIA, @its_The_Dr, @DangerousThinkg, @Mai_ASUR, @MaimunkaNews, and @bertalanzoli were found posting near-identical messages across twelve to eight campaigns. The text published by @TFMDMIA was identical to @DangeorusThinking in only two cases, signaling coordinated but not automated behavior. 

Table showing the six most connected accounts based on the text similarity score. Source: (DFRLab via Claude Sonnet 4.6 via Excel) Link to the vis: https://drive.google.com/file/d/1czvUwREvCkiBFuwAYHBO8Do3sjUaLE7d/view?usp=sharing

The account @DangerousThinking was the most active, appearing in twenty-six campaigns with forty-three total posts. The account was created in May 2023, and it has published over 373,000 posts as of June 21, 2026. This means that the account publishes over 325 tweets per day on average, which is highly suspicious behavior indicating that the account operator(s) may be using some form of automation. We analyzed over 43,000 posts published by the account in 2026 and found that 93.9 percent of all posts were retweets, which shows that this account mostly works on distribution rather than original content creation. 

The chart shows the ten most active accounts in the Storm-1516 operation across two dimensions: the number of campaigns in which they posted (red bars) and their total post count across all campaigns. (blue bars) (Source: X, Meltwater, Claude). 

The DFRLab assesses with moderate confidence that some accounts may be receiving financial remuneration in exchange for promoting the campaigns targeting Armenia. On May 27, an X account posted a screenshot allegedly showing a French user on X being offered €100 ($115)  in exchange for posting a Storm-1516 video about Pashinyan. While the incident remains unconfirmed, VIGINUM separately reported that Storm-1516 operators directly paid social media accounts to post and amplify their narratives. According to CNN reporting, a pro-Donald Trump X user, @AlphaFox78, claimed they were being paid $100 per post by pro-Kremlin figure Simeon Boikov (@aussiecossack); both AlphaFox78 and Boikov have posted Storm-1516 content. The Clemson University Media Forensics Hub previously identified a network of commercial marketing accounts that amplified Storm-1516 narratives ahead of Hungary’s 2026 parliamentary election. The researchers found that these accounts, many of which had metadata links to Nigeria or other parts of Africa, had shifted from promotional and engagement-driven content to political messaging and concluded they were likely receiving compensation for their amplification activity. We found that at least seven accounts from this network also appeared in the datasets of campaigns targeting Armenia: @sakpo0007_, @ade_babyyyyy, @FemmyVickky, @_ElectricVibex, @PurelyMide, @Buddol01, and @Unusual_Dami. This overlap suggests that the same commercial infrastructure could have been used to distribute Storm-1516 content across different countries and political contexts.

We also observed that many X accounts in the dataset had ID verification in place. According to X’s recommendation algorithm documentation, verified accounts benefit from algorithmic preference in X’s ranking systems, and their posts are more likely to surface in recommendations and search results. 

To assess whether verified accounts benefited from amplification due to their verification, we selected a sample of fifteen campaigns from the dataset. The percentage of verified accounts varied across the analyzed campaigns. The verified account percentage dropped significantly in the last five campaigns, from 59 percent in the campaign about banning the recognition of the Armenian genocide to 30 percent in the campaign about accepting 250,000 refugees. Despite this sharp decline, views remained high; the refugee campaign generated 15.86 million views, and the genocide recognition ban reached 12.87 million. Moreover, campaigns with similar verified account rates produced drastically different results in terms of views. Thus, the sample analysis suggests that views were driven not by the proportion of verified accounts but could have been triggered by other factors, including the nature of the narrative or how effectively it triggered algorithmic amplification in other ways. 

Blue bars show the total number of views of posts across the analyzed campaigns, and the green line shows the percentage of verified X accounts for each campaign. Dates show the month in which each campaign was active.  (Source: X, Meltwater, Claude).

The fifteen analyzed campaigns generated over 149.5 million views and 175,781 interactions across 475 posts. The territory handover campaign recorded the highest views at 24.13 million, followed by the campaign about accepting 250,000 refugees at 15.86 million and the Jesus statue ban at 14.93 million. When it comes to engagements, the campaign asserting that Pashinyan’s wife was dating a Muslim man recorded the highest number at 27,258, followed by the campaign alleging Pashinyan would replace ministers with LGBTQ activists, with 26,004 engagements. 

The contrast between views and engagement is also worth noting. The territory handover campaign, despite generating the most views at 24.13 million, produced a comparatively modest average of 434 engagements per post. Similarly, the banning of the Armenian genocide recognition campaign reached 12.87 million views but garnered just 142 interactions per post. Meanwhile, the campaign asserting that Pashinyan’s wife was dating a Muslim man achieved only 7 million views but averaged 751 interactions per post. 

Blue bars show total engagements on posts per campaign and the green line shows average engagement per post. (Sources: X, Meltwater, Claude) 

An analysis of account locations and post languages across the sample set of fifteen Storm-1516 campaigns revealed geographic and linguistic diversity. A Meltwater Explore analysis found that over 52 percent of all posts came from accounts with no identifiable country. Among the 224 posts with an identifiable country, the United States ranked first with 118 posts, present across every single campaign, followed by the United Kingdom with twenty posts. Turkey accounted for thirteen posts across five campaigns, and Russia appeared in only four posts across two campaigns. 

There are also accounts from geographies such as Ecuador, Uganda, the Philippines, Nigeria, Cameroon, and other African or Asian countries across multiple campaigns. It is suspicious that accounts based in these countries would independently discover and amplify breaking stories about Armenian domestic politics within minutes of each other. 

Across all fifteen campaigns, posts were published in eleven languages, but English posts accounted for 91 percent of the total posts. Turkish was the second-most-used language with twelve posts, followed by French with eight posts. The Jesus statue ban was the most diverse campaign linguistically, as its content was distributed in seven languages. This suggests a deliberate effort to spread the narrative across different regions. One account posted content in English, Spanish, and French within a 7-minute window concerning the alleged poisoning of former Azerbaijani prisoner Vicken Euljekjian. 

Armenian-language content appears in just two campaigns, indicating that the campaigns were designed to shape external perceptions of Armenia rather than to directly influence domestic public opinion.

The blue bar chart on the left shows the top fifteen locations of accounts involved in the analyzed campaigns, and the green bar chart on the right shows the distribution of posts by language. (Sources: X, Meltwater, Claude). 

Detecting coordination between websites

Operators behind websites tend to leave correlated fingerprints across the layers of the web stack. This is because building dozens of sites by hand is expensive, so operators optimize: they reuse hosting providers, templates, code, and registration details. These provide signals that can help identify suspicious or coordinated activity. 

An analysis of the websites used in the Storm-1516 campaigns in our dataset focused on three tiers of technical evidence. Strong signals are identity-based signals, which include shared tracking IDs, shared author accounts, shared email addresses, and shared Gravatar profiles. These are the hardest to justify as coincidences because they reflect deliberate choices by an operator. Supporting signals cover infrastructure and content reuse: shared IP addresses, shared content management system (CMS) themes, document object model (DOM) structural cloning, and shared images. Context signals are common by default, such as shared hosting providers, popular plugins, and widely used server stacks, which on their own carry no evidential weight but can reinforce higher-tier findings. Clusters in this report are formed only from strong and supporting signals, and context signals never independently form a cluster. 

Signal types used to attribute suspicious websites to a common operator, grouped by infrastructure layer and weighted by evidential strength. (Source: Erebus, Claude)

Signals were extracted using the Erebus OSINT Toolkit, which captures a fingerprint profile of websites across the different layers of the stack: live HTML from the site and historic HTML from the Wayback Machine (CDX) archive, the DOM fingerprint of page structure, transport layer security (TLS), linguistic markers, and media metadata. Profiles are generated and compared across sites and across clusters. Infrastructure findings and resulting signals are correlated in ErebusGraph, a Neo4j-backed STIX 2.1-compatible graph that holds every domain, IP, certificate, identity, and code artifact as a node and every shared evidence relationship as an edge. Correlation is then a graph query: find the values reachable from two or more domains.

Storm-1516 relies heavily on a network of fake websites to publish, launder, and amplify its false stories. We collected three clusters of websites likely used by Storm to target Armenia. The first cluster consisted of thirteen mostly burner websites or websites that were seemingly taken over by Storm operators. The second cluster consisted of a sample of Armenian language websites, which were attributed to Storm-1516 by CheckFirst. The third cluster consisted of Turkish media websites whose published content targeted Armenia and was heavily amplified by social media assets affiliated with Storm-1516. 

The sections that follow apply infrastructure forensics to each cluster in turn and test whether the sites within it share a common origin. The analysis indicates, for the first two clusters, coordinated networks of common origin; it does not, by itself, attribute them to Storm-1516 or to a named operator.

Examples of articles published by websites in the first cluster. (Sources: Armenian Insider , left; Courrier France 24, centre; Daily Armenia, right)

Cluster 1: burner and taken-over websites

We conducted multi-domain analysis on a sample of twelve English- and French-language websites associated with Storm-1516 and assessed whether technical and content-layer signals could establish connections between them. Eleven of twelve domains published content directly targeting Armenia, while two websites, Torontojournal.ca and Enquetedujour.fr,   targeted other countries but were attributed to Storm-1516. We intentionally selected these two websites to compare Storm-1516’s website infrastructure used for targeting Armenia with the infrastructure used to target other countries. The analysis identified one cluster of ten domains supported by multiple corroborating signals, while two domains from the initial selection showed no coordination evidence in the infrastructure layer within the scope of the selected websites.

Our investigation showed that no two domains in the dataset shared tracking identifiers, such as Google Analytics, AdSense account, Facebook Pixel, or Yandex Metrika ID. Each site that carried a tracker used a unique one. Furthermore, the WordPress sites that reveal Gravatar author avatars each use distinct accounts, and no author email hash appears across more than one domain. 

Two domains in the sample, armeniadaily.am and dailyarmenia.am, warrant a closer introduction. Both came in through the initial selection of Storm-1516-linked domains, and they stand out as the most tightly connected pair in the cluster: they shared a registered author, near-identical page structure (86.2 percent DOM similarity), and both relaunched in October 2025. Moreover, both websites belonged to Armenian organizations before 2020. It appears that until 2019, armeniadaily.am belonged to Armenian Global News LLC, registered in Armenia, and dailyarmenia.am belonged to the travel company Just Travel LLC, also registered in Armenia. Historical WHOIS records for these websites do not contain ownership details between 2019 and 2020, and both armeniadaily.am and dailyarmenia.am were registered again in October and November 2025 through a proxy intermediary, abcdomain (ABCDomain LLC). We contacted Global News company and received confirmation that the domain used to belong to them until February 2019, and since then, they have had no connection with it. This gap in website ownership from 2019 to 2025 and the abrupt change in the content type suggests that the website was taken over by new operators in 2025. The DFRLab previously reported on a similar campaign in which Storm-1516 operators took control of an Armenian website previously owned by an Armenian NGO. Taking over previously active Armenian domains may indicate eliberate search engine optimization (SEO) strategy – older domains with established histories and prior indexing by search engines rank more quickly and credibly in search results than newly created sites. SEO could make these old websites more effective for spreading disinformation and this can be an explanation of why Storm-1516 operators used old websites.

Historical Whois information of dailyarmenia.am and armeniadaily.am show previous ownership of the two websites. (Sources: dailyarmenia.am and armeniadaily.am)

The Russian-language traces in these sites’ Armenian-language articles take two forms, and both point to a translation pipeline rather than errors in writing. These articles are written in fluent Armenian, but isolated Russian words surface mid-sentence, left untranslated. The first is fixed quote-attribution and hedging vocabulary: the Russian reporting verb “заявил” (stated) appears untranslated in four armeniadaily.am articles, each time in the Russian quotation frame «quote», заявил [name] (here,here,here andhere), and in one dailyarmenia.am article; the Russian hedge “якобы” (allegedly) likewise appears once each on armeniadaily.am and armenianinsider.am

The second indicator is hybrid words in which an untranslated Russian stem carries Armenian grammatical endings, for example, “штаб-квартиրում” (Russian “headquarters” with an Armenian locative suffix) appears in two armeniadaily.am articles (here and here), and “криминалистиական” (Russian “forensic” stem with an Armenian adjective suffix) appears in a third, each correctly inflected inside otherwise fluent Armenian sentences. Both hybrid words are reproduced from the archived page source: each is hybrid in the literal sense that its root is a real Russian word in Cyrillic letters and its ending is a correct Armenian grammatical ending in Armenian letters. We did not find equivalent Russian-into-Armenian leakage on any of the mainstream Armenian outlets in our sample. This would be consistent with content assembled through an automated Russian-language pipeline. The mechanism remains suspected rather than confirmed, and the signal binds armeniadaily.am, dailyarmenia.am, and armenianinsider.am specifically; it says nothing about the rest of the cluster on its own.

A collection of screenshots shows Russian-language words appearing in the source code of pages with Armenian-language articles. (Sources: Erebus OSINT Toolkit from live-crawls and Wayback Machine archives)
A hybrid word combining a Russian stem with an Armenian grammatical ending, alongside stray English and Chinese fragments in the same article. (Sources: Erebus OSINT Toolkit from live-crawls and Wayback Machine archives))

The most pervasive signal across the cluster was a shared WordPress theme, Fox, which functions as a network-wide backbone, connecting sites that carry varying degrees of additional linkage on top of it. Taken alone, this would be insufficient evidence because Fox is commercially available and could be used independently by unrelated operators; the weight comes from its consistent pairing with higher-tier signals across nearly every domain. 

Using a shared theme across these websites fits the infrastructure pattern of CopyCop, a website network run by former American police officer John Mark Dougan that, according to VIGINUM, publishes and launders content for multiple Russian influence operations, including Storm-1516 among its primary beneficiaries. CopyCop has previously deployed a single shared WordPress theme across a cluster of its sites, as observed by Recorded Future. A templated, single-theme fleet is therefore an established CopyCop infrastructure signature, and its presence here aligns the Armenian cluster with that pattern. 

The Erebus tool captured the DOM fingerprint of homepage and article pages for each domain and compared them pairwise across sites, scoring the closest-matching pair of pages from 0 to 100; unrelated sites typically score below 50.

Scores in the 80 to 88 percent range mean the underlying HTML element hierarchy, layout logic, and page architecture of two sites are near-identical. The strongest pairs cross both language and country: 

  • 86.2 percent: armeniadaily.am and dailyarmenia.am 
  • 88.3 percent: armeniadaily.am and torontojournal.ca
  • 83.2 percent: armenianinsider.am and dailyarmenia.am 
  • 81.1 percent: armeniadaily.am (Armenian language) and infofrancaisedujour.fr (French language)

Against the below-50 baseline of unrelated sites, these scores are anomalous. Closer inspection shows where the similarity comes from: the same CMS, the same theme, overlapping plugins, and the same theme settings; the more of its build a pair of sites shares, the higher it scores. This is what you would expect with a single operator deploying one template across multiple domains with minimal modification. 

The matrix shows structural HTML similarity between websites in Cluster 1. Higher scores mean more of the build is the same, common CMS, common themes and plugins, and common settings on the themes. The consistently high scores across all Armenian (.am) and French (.fr) domains,  with the closest pair reaching 88%, suggest they were built by the same actor. See the Turkish group of news sites for reference on how similar news sites normally are. (Source: Erebus OSINT Toolkit)

At the hosting layer, the cluster shares no hard links: no two of the thirteen sites share an IP address or an SSL certificate. The hosting providers do concentrate, however. Five sites (armeniadaily.am, armenianinsider.am, dailyarmenia.am, timescanada.ca and velvetnews.co.uk) resolve to Hostinger infrastructure, and four (courrierfrance24.fr, dailymail.uk.net, euleaks.eu and torontojournal.ca) have resolved to Shinjiru, a Malaysian hosting provider, at points in the collection window, in each case on different IP addresses within the provider’s ranges. Shared commodity hosting is a weak, context-level signal on its own, and we treat it as such: it is consistent with the code-and-content evidence but does not independently link the sites.

Thus, the available evidence shows that a set of websites in this cluster are highly likely to be built and operated by the same actor(s), using a shared technical stack. Spreading website domains across Armenian, French, Canadian, and British location names points to a strategy of manufacturing the facade of geographically diverse, individual sources.

Cluster 2: Armenian-language websites linked to Storm-1516 campaigns

We collected a random sample of eighteen Armenian-language websites from the list of websites attributed to Storm-1516 by CheckFirst, to examine infrastructure-level signals between them.

The strongest cluster-wide signal is behavioural: how the sites name their images. All eighteen sites publish images under short random strings such as nTCCV1Y.jpg or TZZNSFHTR.jpg, generated from what we call the bespoke alphabet: a restricted, non-standard set of letters and digits that excludes a large share of the normal alphanumeric range and skews heavily toward a handful of favoured characters. It is distinctive enough that no publicly available naming tool we tested produces it, and no site outside the cluster in our dataset reproduces it, whether the sites in the other clusters or a separate forty-three-site control test of other Armenian outlets spanning major mainstream titles and pro-Russian Armenian media. The same pattern holds when the analysis is restricted to uploads from the current operational period (mid-2025 onward). Each of the eighteen sites individually reproduces the bespoke alphabet, despite the sites running sixteen distinct WordPress themes between them (only two theme names repeat, each on a single pair of sites) and three WordPress versions. This shared pattern is consistent with a single custom publishing tool feeding all eighteen sites. Reinforcing this, 476 byte-identical images of ten kilobytes or larger recur across the fleet, typically carrying a different generated name on each site.

These two behavioural signals also extend the cluster: on infrastructure and metadata signals alone, sixteen of the eighteen sites interlink. But both behavioral signals run across the entire fleet. All eighteen sites reproduce the filename alphabet, and every one of the 18 sites has images used by other sites in the cluster.  That is what pulls the remaining two sites in: reportarmenia.am and yerevanpress.am, which share 93 and 83 identical images with peers in the cluster, and both use the bespoke alphabet. 

The chart shows, for each of the eighteen sites, what share of its own generated image filenames sit entirely within the bespoke alphabet. Every site clears at least 91 percent, and most sit at 97 to 100 percent, showing that the pattern is not the product of one or two unusual sites but is reproduced independently across the whole fleet. Source: (Erebus OSINT Toolkit to identify the bespoke alphabet, and using live-crawls and Wayback Machine archives as sources)

We applied the same measure to the two other clusters in the investigation, not just the eighteen target sites. The bespoke alphabet is essentially unique to cluster two, confirming that the pattern is not an artefact of the measurement itself. 

Bar chart showing the prevalence of the bespoke alphabet across the three website clusters. (Source: Erebus OSINT Toolkit from live-crawls and Wayback Machine archives)

Furthermore, a single byte-identical image file was dropped within 45 minutes across fifteen of the sites on May 13, each site storing it under a fresh random filename drawn from a new naming convention. From this date on, no site used the bespoke finger-printed alphabet, indicating possible centralized control.

Chart showing the coordinated move away from a bespoke alphabet, from images where precise timing could be identified. (Source: Erebus OSINT Toolkit from live-crawls and Wayback Machine archives)

This same image drop also shows coordination through how fully it spread to all domains within this cluster. Sixteen of the eighteen sites carry it as a byte-identical PNG file, down to identical resized thumbnail variants, while the remaining two received the same graphic re-encoded as a byte-identical JPEG pair the following morning. On every site the image is the featured image of the same article, published under an identical URL slug, in which unnamed American journalists accuse Prime Minister Pashinyan of carrying out “economic terrorism” against Armenia. The combination of a byte-identical file, identical article slugs, and near-simultaneous upload times is consistent with centrally supplied and distributed content rather than independent editorial choices.

Infographics showing the same image being shared across the cluster as 2 drops. 1 drop within a 46-minute timeframe as PNG files, and one drop as .jpg files the next day. One further PNG had no recoverable time. (Source: Erebus OSINT Toolkit, using HTTP Last-Modified headers, live-crawls and Wayback Machine archives)

Another strong infrastructure link is the shared IP address 208.109.215.186, on which six domains are co-hosted: hayreniknews.am, armreporter.am, armenianews24.am, armenianjournal.am, arevmedia.am, and yerevantimes.am, with each domain migrating to this address within a window running from November 2025 to January 2026. The near-simultaneous migration window, together with a tightly banded certificate re-issue from November 18 to 29, 2025, is consistent with coordinated deployment by a single operator. A second co-hosting relationship links armbreaking.com and haypressinfo.com on 31.210.50.51, both registered within four days of each other (2025-11-25 and 2025-11-29) under the same provider, Ultahost.

At the identity level, several domain pairs share named authors publishing across multiple sites simultaneously. For example, armreporter.am, and newsyerevan.am share three named Armenian-language journalists: Zhora Poghosyan, Ishkhan Stepanyan, and Lernik Yavryan (Ժորա Պողոսյան, Իշխան Ստեփանյան, and Լեռնիկ Յավրյան), and they appear on both sites’ author pages. While armbreaking.com and haypressinfo.com share two named authors, Zaruhi Gulumyan and Seda Beglaryan (Զարուհի Գուլումյան and Սեդա Բեգլարյան), and armword.am shared the author (Eduard Muradyan) Էդուարդ Մուրադյան with newsyerevan.am. However, we could not find real journalists with these names and surnames, and it appears likely that they are fictional personas. 

The signal matrix below summarizes every pairwise link in the cluster, each cell coloured by the strongest tier of signal the pair shares; the co-hosting, author, and metadata findings described here appear as its red and amber cells.

Image metadata adds a supporting link between armreporter.am and hayreniknews.am: the two sites publish images carrying identical Adobe XMP document identifiers, meaning the same edited image files, not merely similar photos, appear on both sites. The embedded creation timestamps show the two source documents were created minutes apart, consistent with a single editing session. This supports a shared content source or publishing workflow; it does not identify the machine that did the editing. Weaker tool chains that overlap across the fleet (shared camera models and the same Photoshop build as the creator tool, visible in the signal matrix) are consistent with this picture but too common to carry weight on their own. Structural cloning adds a further supporting link: the two closest DOM pairs in the cluster are shown below.

Armenianway.am and haypressinfo.com, which received 95 percent DOM structural similarity. (Source: Armenianway.am, haypressinfo.com, Erebus OSINT Toolkit)

Armbreaking.com and armdailynews.com, with 98.5 percent DOM structural similarity. (Source: Armbreaking.com, armdailynews.com, Erebus OSINT Toolkit)

Cluster 3: Turkish media outlets

The Turkish websites and their role is different from the websites in the first two clusters because they are not one-off websites created by Storm-1516/CopyCop to carry out a specific campaign. The Turkish outlets that appear in these campaigns are established media platforms with real audiences and distinct editorial profiles, spanning nationalist, left-wing, Islamist, and state-backed orientations. The narratives observed in this activity tend to align with the editorial leanings of the outlets where they surface, a pattern consistent with Storm-1516 aligning its content to be most receptive by the audience.  More than half of the narratives analyzed above were initially reported by these outlets and then heavily amplified by Storm-affiliated assets on X. In its posts, the Storm-1516 amplifier network on X would cite these articles as “Turkish media reports” to make these narratives appear as though they were independently corroborated.

According to VIGINUM and ISD, the network has increasingly shifted from easily identifiable fake websites and AI-generated content farms to a more sophisticated form of “narrative laundering.” Fabricated stories are first published by legitimate foreign outlets and then amplified by coordinated bot networks and influential accounts, allowing the original Russian-linked source to remain hidden. This investigation did not establish that these websites are participating in such activity.

To check the presence of infrastructure-level connections between these outlets despite them being seemingly independent from each other, we applied the same forensic methodology used for clusters 1 and 2. Unlike the previous two clusters, the analysis returned no meaningful coordination signals. 

On inspection, the infrastructure evidence does not support a common-operator conclusion. No shared tracking identifiers were found across any pair of domains: no common Google Analytics, AdSense, Facebook Pixel, or Yandex Metrika IDs. Registrant data was either obscured by privacy proxies (Domains By Proxy, PrivacyProtect.org) or resolved to unrelated organizations. The single identity-grade signal the tool surfaced was a shared byline on both aydinlik.com.tr and cgtnturk.com. We note it explicitly, but assess it as ordinary journalistic syndication between a domestic outlet and a state broadcaster’s Turkish-language edition rather than covert coordination. The DOM similarity matrix also showed a lack of similarity between the sites.

The matrix shows structural HTML similarity between websites in Cluster 3. (Source: Erebus OSINT Toolkit)

Several domains share common third-party advertising and analytics platforms, including jsc.idealmedia.io and cdn2.bildirt.com, but this reflects the broader Turkish digital-media ecosystem rather than deliberate infrastructure sharing. IP co-location was identified in a small number of cases, such as aydinlik.com.tr, odatv.com, and ulusal.com.tr on 195.142.135.35. But the three sites are never all co-resident at once: aydinlik was observed on a single day (2022-02-19), more than a year before the others, while odatv appears on a single day (2023-09-08) inside ulusal’s open-ended window from 2023-06-16.  The remaining apparent IP overlaps carry no attributive weight either: they fall in Cloudflare’s 104.21.x and 8.x anycast ranges (AS13335) and are CDN artifacts, not dedicated hosting.

Conclusion

This investigation documents a sustained Russian information operation targeting Armenia ahead of the country’s June 2026 parliamentary elections. The website forensics analysis revealed two clusters of coordinated infrastructure: one cluster with English- and French-language sites sharing infrastructure patterns and another one consisting of Armenian-language sites linked by a unique image-naming pattern consistent with a single custom publishing tool. Russian words embedded in Armenian-language articles confirm that the operators are likely Russian speakers, who rely on automated translation. Such errors would be invisible to most readers, but they can be revealed through forensic analysis. The operation mostly targeted Western and diaspora audiences, with 91 percent of posts published in English. This suggests that its primary goal was not to influence Armenian voters directly but to shape how the outside world perceived Armenia and its leadership. This investigation also shows Storm-1516’s operational ability to redirect existing infrastructure toward a new geographic target, which makes Storm-1516 a persistent and adaptable IMS. 

The full technical dossier of the analyzed domains is available upon request.


Cite this case study:

Andreas Sjöstedt, Givi Gigitashvili, Ani Grigoryan, Nika Aleksejeva, “Uncovering the digital infrastructure behind Russian interference in Armenian elections” Digital Forensic Research Lab (DFRLab) and CivilNet, July 29, 2026, https://dfrlab.org/2026/07/29/uncovering-the-digital-infrastructure-behind-russian-interference-in-armenian-elections/.