CSIDB logo
Threat actor

Russian Internet Research Agency

Attribution profile

Type
Nation State
Location
Russia
Known incidents
2 incidents
First seen
2022-02-15
Last seen
2022-02-15
Updated
2026-07-15 08:40
Aliases
4 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The Russian Internet Research Agency, also known as the Internet Research Agency, IRA, or Glorious Russian Empire, operates from Russia and engages in coordinated influence operations and cyber espionage. This actor employs fake social media accounts across platforms including Facebook, Instagram, and Telegram to disseminate disinformation and target specific sectors and individuals. Public reporting attributes campaigns to this group that align with Russian strategic interests, though direct state control is not explicitly detailed in available disclosures.

The group primarily targets Ukrainian entities, with a focus on the country’s telecommunications, defense, and energy sectors, alongside journalists and political activists. Operations aim to spread false narratives—such as fabricated claims about military surrenders or leadership abandonment—to undermine social cohesion and amplify confusion during conflicts. Strategic objectives include cyber espionage through credential theft via phishing and malware deployment, as well as content suppression through mass reporting of invasion-related posts. Targeting extends beyond Ukraine, with related networks linked to Belarusian and Azeri state actors compromising activist accounts and critical infrastructure in other regions.

Notable techniques involve coordinated inauthentic behavior through fabricated accounts impersonating legitimate users or media outlets to amplify disinformation. The actor leverages phishing as an initial access vector to harvest credentials, complemented by malware targeting Android devices in some operations. Meta disrupted one such campaign in March 2022, exposing the IRA’s role in a broader network of Russian and Belarusian-linked influence activities that included Belarusian KGB affiliates spreading fabricated military narratives. This operation exemplifies the actor’s integration of cyber espionage with psychological operations, blending digital intrusion with information warfare to advance its objectives.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB