Skip to main content

Deepens Its Playbook with New Websites and Targets

Medium
Published: Thu Sep 18 2025 (09/18/2025, 03:21:10 UTC)
Source: AlienVault OTX General

Description

CopyCop, a Russian covert influence network, has significantly expanded its operations since March 2025, creating over 300 new fictional media websites targeting various countries. The network, likely operated by John Mark Dougan with support from Russian entities, aims to undermine support for Ukraine and exacerbate political fragmentation in Western countries. CopyCop's tactics include using deepfakes, AI-generated content, and impersonating media outlets to spread pro-Russian narratives. The network has widened its target languages and geographical scope, now including Turkey, Ukraine, Swahili-speaking regions, Moldova, Canada, and Armenia. While its core objectives remain unchanged, CopyCop has made marginal improvements to increase its reach, resilience, and credibility, including the use of self-hosted large language models for content generation.

AI-Powered Analysis

AILast updated: 09/18/2025, 09:17:16 UTC

Technical Analysis

CopyCop is a Russian covert influence network that has significantly expanded its operations since March 2025 by creating over 300 new fictional media websites targeting multiple countries. The network is believed to be operated by John Mark Dougan with support from Russian entities. Its primary objective is to undermine support for Ukraine and exacerbate political fragmentation in Western countries through disinformation campaigns. CopyCop employs sophisticated tactics including the use of deepfakes, AI-generated content, and impersonation of legitimate media outlets to spread pro-Russian narratives. The network has broadened its linguistic and geographic scope to include Turkey, Ukraine, Swahili-speaking regions, Moldova, Canada, and Armenia, in addition to its previous targets. Technically, CopyCop has enhanced its operations by deploying self-hosted large language models to generate content, increasing the credibility, reach, and resilience of its disinformation efforts. These tactics align with known adversary techniques such as creating fake media (T1583), using social media for influence (T1592), and leveraging AI and deepfake technologies (T1608 series). Although no direct exploitation of software vulnerabilities is involved, the campaign represents a sophisticated information operation leveraging emerging AI technologies to manipulate public opinion and political processes.

Potential Impact

For European organizations, especially those involved in media, government, election monitoring, and public policy, CopyCop's campaign poses a significant threat to information integrity and public trust. The spread of AI-generated disinformation and deepfakes can distort political discourse, influence elections, and exacerbate societal divisions. This can lead to reputational damage for media outlets, increased polarization among the public, and challenges in governance and policy-making. Organizations responsible for cybersecurity, media verification, and public communication may face increased operational burdens to detect and counteract such influence operations. Moreover, the erosion of trust in legitimate news sources can have long-term detrimental effects on democratic institutions and social cohesion within European countries.

Mitigation Recommendations

European organizations should implement multi-layered mitigation strategies tailored to counter sophisticated disinformation campaigns like CopyCop's. These include: 1) Enhancing media literacy programs to educate the public on identifying deepfakes and AI-generated content; 2) Deploying advanced AI-based detection tools capable of identifying synthetic media and verifying the authenticity of news sources; 3) Establishing partnerships between governments, media outlets, and cybersecurity firms to share threat intelligence and coordinate responses to disinformation; 4) Monitoring newly registered domains and suspicious websites to identify and block fictional media outlets early; 5) Strengthening social media platform policies and cooperation to rapidly detect and remove coordinated inauthentic behavior; 6) Supporting independent fact-checking organizations with resources and technology to debunk false narratives promptly; 7) Encouraging transparency in media sourcing and promoting trusted news brands to counterbalance fake outlets; 8) Preparing crisis communication plans to respond swiftly to disinformation spikes during sensitive political events such as elections.

Need more detailed analysis?Get Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.recordedfuture.com/research/copycop-deepens-its-playbook-with-new-websites-and-targets"]
Adversary
CopyCop
Pulse Id
68cb7aa638a3244a9fa2ea60
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip198.54.116.120
ip185.11.145.145
ip89.31.82.185

Domain

ValueDescriptionCopy
domainactu-net.fr
domainactualite360.fr
domainactualitesmaintenant.fr
domainactualitespourtous.fr
domainactubretagne.fr
domainactudirecte.fr
domainactuiledefrance.fr
domainactuperspectives.fr
domainactus-independantes.fr
domainactus-sanscensure.fr
domainactus24.fr
domainactusetinfosdupays.fr
domainaffichedujour.fr
domainagorahexagone.fr
domainalbertaseparatist.com
domainallstatesnews.us
domainalohadigest.com
domainame-nationale.fr
domainanalyse-actus.fr
domainardennesinfolive.fr
domainbayoucity.news
domainbayoucitycrier.com
domainbayoucitytoday.com
domainbref-france24.fr
domaincapitalcitydaily.com
domaincapitoldaily.news
domainchroniquesfrancaises.fr
domainchronoinfo.fr
domainclearstory.news
domaincourrierfrance24.fr
domaindailyweekly.news
domaindarkpulsar.ai
domaindarkquasar.tech
domaindedfuture.com
domaindirect-nouvelles.fr
domainechorhonealpes.fr
domaineclairinfo.fr
domaineditorialesactus.fr
domainenquetedujour.fr
domainevenementsetactus.fr
domainexpressactus.fr
domainflash-actualites.fr
domainflash-bourgognefranchecomte.fr
domainflashhexagone.fr
domainfldaily.news
domainflga.news
domainfondfbr.ru
domainfrance-aujourdhui.fr
domainfrance-droite.fr
domainfrance-premiere.fr
domainfrance-vision.fr
domainfrance24-7.fr
domainfrance24actus.fr
domainfranceactuelle.fr
domainfranceactuweb.fr
domainfranceavanttout.fr
domainfrancechronique.fr
domainfrancedetail.fr
domainfranceencolere.fr
domainfrancepatriotique.fr
domainfrancepourlesfrancais.fr
domainfrancerealites.fr
domainfrmedialive.fr
domaingoldengatedaily.com
domaingreenarmenia.org
domaininfo-grand-est.fr
domaininfo-minute.fr
domaininfofrancaisedujour.fr
domaininfofrance-focus.fr
domaininfohexagone.fr
domaininfos-encontinu.fr
domaininfosdupays.fr
domaininfosinternationales.fr
domaininstantactus.fr
domaininvestigateurfrancophone.fr
domainjournalrepublicain.fr
domainkjfk.news
domainklas.news
domainklax.news
domainkmia.news
domainkpbi.news
domainkphl.news
domainksfo.news
domainksmo.news
domainla-francegaullienne.fr
domainlachronicle.news
domainlactualite-provencale.fr
domainlafrance-debout.fr
domainlafrancesouveraine.fr
domainlareport.news
domainlatribunefrancaise.fr
domainle-choinfo.fr
domainlefilactualites.fr
domainlefilhexagonal.fr
domainlefocus-occitanie.fr
domainlejournalfrancophone.fr
domainlejournalnormand.fr
domainlepointnumerique.fr
domainlequotidienfrancais.fr
domainlinformateurdujour.fr
domainmagazinedusoir.fr
domainmeilleuresactus.fr
domainmetroreport.news
domainmidi-pyreneesactualite.fr
domainminutedinfo.fr
domainmiroirdelafrance.fr
domainnewsguard.tech
domainnordactuquotidien.fr
domainnormandie-actusinfos.fr
domainnouvelle-aquitaine-aujourdhui.fr
domainnouvelleperspective.fr
domainnouvelles-deshautsdefrance.fr
domainnouvelles-hexagonales.fr
domainnouvellesfrance24.fr
domainpanorama-info.fr
domainpartiroyaliste.fr
domainpatrimoineinfo.fr
domainpause-actus.fr
domainperspectives-francaises.fr
domainpointdevueactu.fr
domainport.com
domainreportagesinternationaux.fr
domainreseauavecactus.fr
domainrevelationdes-mensonges.fr
domainsavoirtout.fr
domainsfreport.news
domainsilvercity.news
domainskryty.com
domainskryty.ru
domainsteelcitydaily.com
domainsudouestdirect.fr
domaintorontojournal.ca
domaintruefact.news
domaintvfrance2.fr
domaintwincityreport.com
domaintxdaily.news
domainusatimes.news
domainveritecachee.fr
domainvisiondelafrance.fr
domainvisionfrancophone.fr
domainvivezlinfo.fr
domainvoix-francophone.fr
domainvoixdelafrance.fr
domainvosges-enligne.fr
domainwalx.news
domainwdmdtv.com
domainwindycitycrier.com
domainwindycitymirror.com
domainwindycitytimes.news
domainwktv.news
domainwtat.news
domainwval.news
domainxn--actu-auvergne-rhne-alpes-lnc.fr
domainactualitespourtous.fr.expressactus.fr
domainactuiledefrance.fr.nouvelle-aquitaine-aujourdhui.fr
domainactus-independantes.fr.meilleuresactus.fr
domainactus-sanscensure.fr.infos-encontinu.fr
domainactusetinfosdupays.fr.frmedialive.fr
domainafrica.truefact.news
domainame-nationale.fr.savoirtout.fr
domainanalyse-actus.fr.pause-actus.fr
domainardennesinfolive.fr.vosges-enligne.fr
domainbref-france24.fr.visiondelafrance.fr
domainchat.darkpulsar.ai
domainde.truefact.news
domaindirect-nouvelles.fr.meilleuresactus.fr
domaineditorialesactus.fr.francechronique.fr
domainevenementsetactus.fr.patrimoineinfo.fr
domainflash-actualites.fr.francechronique.fr
domainflash-bourgognefranchecomte.fr.nouvelle-aquitaine-aujourdhui.fr
domainfr.truefact.news
domainfrance-aujourdhui.fr.actus24.fr
domainfrance-droite.fr.patrimoineinfo.fr
domainfrance.truefact.news
domainfranceactuweb.fr.vivezlinfo.fr
domainfranceavanttout.fr.infosdupays.fr
domainfrancepatriotique.fr.chronoinfo.fr
domainfrancepourlesfrancais.fr.infosdupays.fr
domaingermany.truefact.news
domaininfohexagone.fr.actus24.fr
domaininfosinternationales.fr.visiondelafrance.fr
domainla-francegaullienne.fr.frmedialive.fr
domainlactualite-provencale.fr.info-grand-est.fr
domainlafrance-debout.fr.infos-encontinu.fr
domainlafrancesouveraine.fr.savoirtout.fr
domainlinformateurdujour.fraffichedujour.fr
domainmexico.truefact.news
domainmidi-pyreneesactualite.fr.vosges-enligne.fr
domainnordactuquotidien.fr.normandie-actusinfos.fr
domainnouvellesfrance24.fr.chronoinfo.fr
domainpanorama-info.fr.chroniquesfrancaises.fr
domainreg.skryty.ru
domainreportagesinternationaux.fr.pause-actus.fr
domainreseauavecactus.fr.lefilactualites.fr
domainrevelationdes-mensonges.fr.infosdupays.fr
domainspain.truefact.news
domainturkey.truefact.news
domainukraine.truefact.news
domainvideo.darkpulsar.ai
domainvisionfrancophone.fr.expressactus.fr
domainvoix-francophone.fr.lefilactualites.fr
domainxn--actu-auvergne-rhne-alpes-lnc.fr.normandie-actusinfos.fr

Threat ID: 68cbcd42c76bde0bbe9f97f2

Added to database: 9/18/2025, 9:13:38 AM

Last enriched: 9/18/2025, 9:17:16 AM

Last updated: 9/19/2025, 12:07:08 AM

Views: 5

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats