Insikt Group Telemetry: Mapping the CopyCop Network's Domain Infrastructure
The Architecture of Artificial Amplification
In March 2024, Recorded Future’s Insikt Group a sprawling network of inauthentic news sites they “CopyCop.” Unlike previous influence operations that relied on human troll farms to manually draft disinformation, CopyCop represented a methodological shift toward fully automated, AI-driven content laundering. Telemetry data from early 2024 indicates the network generated over 19, 000 unique articles in less than sixty days, a volume that physically the capacity of human-staffed newsrooms. The network’s primary function is not to create fake news to scrape legitimate reporting from mainstream outlets, including Al Jazeera, Fox News, and the BBC, and rewrite it using Large Language Models (LLMs) to inject specific partisan biases.
The infrastructure supporting CopyCop is built for resilience and rapid deployment. Network analysis reveals a distinct pattern of “batch registration,” where operators register dozens of domains simultaneously using specific registrars known for privacy protection. Between May 10 and May 12, 2024, the network registered 120 new domains in a single forty-eight-hour window, specifically pivoting focus from French and Ukrainian problem to the U. S. presidential election. This surge coincided with a tactical shift in hosting; while early iterations utilized European servers, the May expansion saw a migration to U. S.-based hosting providers, likely an attempt to evade foreign interference filters and appear as domestic American media entities.
The “Prompt Injection” Fingerprint
The most damning evidence linking these sites to a centralized AI operation lies in the “prompt injections” left visible in the published HTML. Because the operation is automated, the LLM outputs are frequently posted without human review. This absence of quality control led to the publication of raw system instructions within the articles themselves. Insikt Group analysts identified repeated instances of specific command prompts, such as: “Please rewrite this article taking a conservative stance against the liberal policies of the Macron administration in favor of working-class French citizens.”
Further forensic analysis of the network’s error logs revealed the specific limitations of the models used. Articles occasionally contained the standard refusal message from OpenAI’s models: “I cannot fulfill this request., I am committed to providing objective and unbiased translations.” These artifacts serve as a digital fingerprint, confirming that the network does not aggregate news actively processes it through generative filters designed to radicalize the tone. The prompts explicitly directed the AI to adopt a “cynical tone” when mentioning the U. S. government, NATO, or major corporations, while requesting positive framing for specific political figures aligned with Russian strategic interests.
Domain Infrastructure and Attribution
The CopyCop network relies heavily on obfuscated hosting to mask its origin. Approximately 97% of the identified domains are shielded behind Cloudflare, which acts as a reverse proxy to hide the true origin IP addresses. yet, historical DNS records and SSL certificate data allowed investigators to pierce this veil. A significant cluster of the network was traced to the IP address 72. 14. 185. 187, hosted by Akamai/Linode. This specific server acted as a nexus for the network, hosting multiple “local news” imposters simultaneously.
The domain registration strategy exhibits a clear preference for “trusted” nomenclature. The operators systematically purchase domains that mimic the naming conventions of defunct American local newspapers, using words like “Tribune,” “Gazette,” “Post,” and “Chronicle.” This is not random; it is a calculated attempt to exploit the “local news desert” emergency in the United States, where the closure of legitimate local papers has left a vacuum that these imposters fill. By appearing as The Houston Post or Chicago Chronicle, the network gains an unearned veneer of credibility among local audiences.
| Infrastructure Component | Identified Characteristic | Operational Significance |
|---|---|---|
| Primary Registrar | NameCheap (91% of domains) | Allows for anonymous registration with cryptocurrency payment options, reducing financial trails. |
| Hosting Provider | Cloudflare (Shield), Akamai/Linode (Origin) | Cloudflare provides DDoS protection and SSL encryption, making the sites appear secure and legitimate to browsers. |
| Content CMS | WordPress (Heavily modified) | Enables the use of automated plugins to fetch RSS feeds and pipe them directly into LLM APIs for rewriting. |
| Origin IP Address | 72. 14. 185. 187 | A serious failure in operational security (OPSEC) where multiple distinct “news outlets” resolved to a single server. |
| Target Regions | USA, UK, France, Ukraine | Shifted from broad anti-Western sentiment to specific electoral interference in the US (2024) and Germany (2025). |
Connection to John Mark Dougan
Telemetry data establishes a strong link between the CopyCop network and John Mark Dougan, a former Florida deputy sheriff and fugitive currently residing in Moscow. The digital architecture of CopyCop shares SSL certificates and unique tracking codes with DC Weekly, a known disinformation outlet previously attributed to Dougan. DC Weekly served as a prototype for the CopyCop model, demonstrating that AI-generated content could successfully infiltrate Western social media ecosystems. The expansion of CopyCop in 2024 industrialized Dougan’s tactics, moving from a single site to a fleet of hundreds.
In late 2024 and early 2025, the network evolved again, launching a cluster of sites under the “Truefact” brand (e. g., africa. truefact. news, ukraine. truefact. news). These sites purported to be fact-checking organizations, a meta-tactic designed to confuse the information environment further. By co-opting the language and aesthetics of fact-checkers, the network attempts to inoculate its audience against legitimate corrections. This “Truefact” cluster was hosted on the same 72. 14. 185. 187 infrastructure, confirming it as a direct continuation of the CopyCop operation.
Operational Velocity and Automation
The speed at which CopyCop operates distinguishes it from traditional state-backed media. Human-led propaganda outlets like RT or Sputnik operate on editorial pattern; CopyCop operates on computational pattern. The network can identify a trending article on a legitimate site, scrape it, rewrite it with a “conservative” or “cynical” bias, and publish it to dozens of domains within minutes. This velocity allows the network to “flood the zone,” saturating search engine results for specific keywords before legitimate journalists can verify or contextualize the breaking news.
This automation also creates a vulnerability. The sheer volume of content, frequently exceeding hundreds of articles per site per day, creates a distinct statistical noise. Legitimate local news sites rarely publish at such a cadence. Data scientists tracking the network use this “publication velocity” as a primary detection metric. When a supposedly small-town newspaper begins publishing 500 articles a day on geopolitical conflict in Eastern Europe, it triggers immediate red flags in threat intelligence dashboards.
The network’s reliance on NameCheap and Cloudflare also points to a commoditized method to infrastructure. Rather than building custom servers, the operators use off-the-shelf tools available to any digital marketer. This lowers the barrier to entry also creates a dependency on Western tech companies, who theoretically possess the power to the network by enforcing Terms of Service violations regarding inauthentic behavior. The persistence of the network through 2025 suggests that these enforcement method remain reactive rather than proactive, allowing CopyCop to simply register new domains as fast as the old ones are blacklisted.
The LLM Fingerprint: Forensic Analysis of Prompt Leaks and AI Hallucinations

The Mathematical Impossibility of Human Authorship
The betrayal of the CopyCop network was not linguistic, statistical. Between March and May 2024, the network’s telemetry data revealed a production rate that human capability. A single CopyCop domain, masquerading as a local news outlet like the Houston Post or London Crier, published an average of 19, 000 articles per month. For context, the New York Times, with a newsroom of 1, 700 journalists, publishes approximately 150 articles daily. CopyCop outlets were generating over 600 articles per day with zero documented staff. This volume is the primary forensic marker of Large Language Model (LLM) automation. The network operates on a “scrape-and-spin” architecture: automated scripts ingest RSS feeds from legitimate sources, including Al Jazeera, Fox News, and the BBC, and feed the text into self-hosted, uncensored versions of open-source models, specifically variants of Meta’s Llama-3-8b. The AI is instructed to rewrite the content to evade plagiarism detectors while injecting specific partisan biases.
Forensic Evidence: The Prompt Leak
The most damning evidence of AI orchestration appears when the automation fails. In a phenomenon known as a “prompt leak,” the LLM accidentally includes its instructions or its refusal to comply in the final published text. These artifacts serve as digital fingerprints, proving the content is synthetic. Recorded Future’s Insikt Group identified multiple instances where CopyCop articles contained the following raw model outputs left unedited by human operators:
“Please note that this rewrite aims to provide a clear and concise summary of the original text while maintaining key details.”
In other instances, the model’s safety guardrails, or the absence thereof, became visible. While standard models like ChatGPT might refuse to generate disinformation with a standard “I cannot fulfill this request,” the uncensored models used by CopyCop frequently output conversational confirmations before the article text, such as “Here is the rewritten article with a cynical tone as requested.” These slips reveal the specific “system prompts” used by the operators: instructions to adopt a “conservative slant,” “anti-Western perspective,” or “skeptical tone” regarding Ukraine or NATO.
Case Study: The Hallucination of Mary Bergland
Beyond simple rewriting, the LLMs frequently suffer from “hallucinations”, confidently stating facts that do not exist. A forensic review of a Houston Post article (a CopyCop asset) from June 2024 demonstrates this failure. The article attempted to rewrite a crime report conflated two distinct individuals from separate source texts. The AI combined “Mary Bergland,” a figure from a 2011 case, with “Madison Bergman,” a subject in a 2024 report. The resulting narrative was a fictional hybrid, attributing actions to a woman who had been dead for over a decade. This type of error is distinct to statistical prediction models, which associate similar-sounding tokens (Bergland/Bergman) without understanding the temporal or factual separation of the entities.
Synthetic Staff: The “Hector Payne” Anomaly
The network attempts to mask its automation with human-sounding bylines. One prolific author, “Hector Payne,” appeared across multiple French and English language sites, including Media Alternative. A background check on this persona reveals the depth of the fabrication: * Digital Footprint: Zero. No LinkedIn, no previous journalism history, no social media presence prior to 2024. * Photo Forensics: The profile image associated with Payne exhibits classic GAN (Generative Adversarial Network) artifacts, such as asymmetrical earrings, undefined background textures, and hair that blends into the skin, telltale signs of ThisPersonDoesNotExist-style generation. * Verification: When French outlet France 24 contacted the publications listed in Payne’s bio, they confirmed no such person had ever worked there.
Table: The Anatomy of an AI Rewrite
The following table breaks down the transformation process observed in a recovered CopyCop article from May 2024.
| Feature | Original Source (e. g., BBC) | CopyCop Rewrite (AI Output) | Forensic Flag |
|---|---|---|---|
| Headline | “US announces new aid package for Ukraine” | “Washington Fuels Conflict with More Cash for Kiev” | Sentiment Shift: Neutral to highly negative/cynical. |
| Attribution | “According to Secretary Blinken…” | “As the regime’s mouthpiece Blinken claims…” | Loaded Language: Substitution of neutral verbs with emotionally charged descriptors. |
| Error Type | Factual reporting of $400m value. | “The $400 billion handout…” | Hallucination: The AI confused “million” with “billion,” a common numerical token error. |
| Artifacts | None. | “Here is the rewrite focusing on the corruption angle:” | Prompt Leak: The model’s conversational preamble was pasted into the final HTML. |
Infrastructure of Deception
The technical implementation of these hallucinations points to a high degree of automation low quality control. The sites run on standardized WordPress templates where the AI output is injected directly into the `post_content` database field via API. The absence of a “human in the loop” to catch errors like “” confirms that speed and volume are prioritized over credibility. The goal is not to convince a careful reader, to flood search engine results and social media feeds with enough noise that the synthetic narrative becomes unavoidable.
Storm-1516 Intersection: Cross-Referencing Microsoft Threat Data with CopyCop Activity
The Convergence of Actor and Infrastructure
The intersection of Microsoft’s “Storm-1516” designation and Recorded Future’s “CopyCop” network represents a serious evolution in automated influence operations. While the two terms are frequently used interchangeably in general reporting, distinct telemetry reveals a functional separation: Storm-1516 acts as the narrative architect, while CopyCop serves as the technical distribution infrastructure. Intelligence reports from late 2024 and throughout 2025 indicate that the Storm-1516 actor set, linked to the Russian Presidential Administration, systematically commandeered the CopyCop network to “launder” disinformation through a veneer of algorithmic legitimacy.
Microsoft Threat Intelligence officially categorized Storm-1516 as a Kremlin-aligned entity specialized in “content laundering”, a technique where fabricated stories are planted on fringe sites and gradually elevated into mainstream discourse. By mid-2024, this actor began exclusively using the CopyCop network, a sprawling web of AI-generated news sites operated by former Florida deputy sheriff John Mark Dougan, to inject these narratives. The operational handshake is precise: Storm-1516 produces the “seed” material, frequently a staged whistleblower video or a forged document, and CopyCop sites instantly ingest, rewrite, and republish this content across hundreds of domains to create a false consensus.
method of the “Hall of Mirrors”
The collaboration relies on a specific technical workflow that defeats traditional moderation. Unlike human troll farms that require shifts of workers to type comments, the Storm-1516/CopyCop hybrid uses Large Language Models (LLMs) to industrialize the “spin.” When Storm-1516 releases a fabrication, such as the debunked claim that Ukrainian officials bought luxury yachts with U. S. aid, the core CopyCop node (frequently DC Weekly or a localized mimic like The Boston Chronicle) publishes the initial “investigation.”
Within hours, the broader CopyCop network scrapes this initial article. Telemetry from the 2024 election pattern showed that the network’s LLMs, specifically uncensored versions of Llama-3 identified by Insikt Group, rewrote the seed article into thousands of unique variations. These permutations alter headlines, sentence structures, and metadata, blinding duplicate content detection algorithms used by social media platforms. The result is a “hall of mirrors” where a single lie appears to be reported by dozens of independent outlets simultaneously.
Table: Storm-1516 Seed Narratives vs. CopyCop Amplification (2024-2025)
| Seed Narrative (Storm-1516) | Primary Injection Site | CopyCop Network Volume | Target Audience |
|---|---|---|---|
| “Olena Zelenska Cartier Shopping Spree” | The Nation (Nigeria) / DC Weekly | ~12, 000 rewritten articles | US/EU Taxpayers |
| “Kamala Harris 2011 Hit-and-Run” | KBSF-TV (Fake SF Outlet) | ~8, 500 rewritten articles | US Voters (Swing States) |
| “Zelensky High-End Yacht Purchase” | The Miami Chronicle | ~15, 000 rewritten articles | Global South / US Conservatives |
| “French Election Panic / Bedbugs” | La Vedette (Fake French Outlet) | ~4, 200 rewritten articles | French Electorate |
The 2024 Election Surge
During the lead-up to the November 2024 U. S. Presidential Election, the synchronization between Storm-1516 and CopyCop reached peak efficiency. Microsoft identified a pivot in August 2024, where the network shifted focus from attacking President Biden to targeting Vice President Kamala Harris. A specific operation involved a staged video featuring a paid actor claiming to be a victim of a hit-and-run accident involving Harris in 2011. This video was not posted to social media; it was in a fabricated news report on a CopyCop website designed to mimic a defunct San Francisco television station, KBSF-TV.
The site was registered only days before the story broke, yet it contained thousands of AI-generated articles about local San Francisco weather, sports, and crime to establish a “pattern of life.” Once the fake hit-and-run story was live, the CopyCop network amplified it, with secondary sites citing the KBSF-TV report as a primary source. This cross-citation method creates a circular verification loop, making it difficult for fact-checkers to identify the original source of the falsehood. By the time the story was debunked, the AI-rewritten versions had already generated millions of impressions on X (formerly Twitter) and Telegram.
Infrastructure Expansion and Resilience
Following the 2024 election, the network did not; it expanded. In September 2025, Recorded Future reported a significant surge in CopyCop infrastructure, identifying over 200 new domains targeting France, Germany, and Moldova. This expansion included a new tactic: “Truefact,” a network of fake fact-checking organizations in multiple languages (Turkish, Ukrainian, Swahili) designed to “debunk” Western narratives using pro-Russian disinformation. The persistence of this infrastructure demonstrates that the Storm-1516/CopyCop intersection is not a temporary election tool a permanent, automated apparatus for information warfare.
“The network’s primary function is not to convince the audience of a specific lie, to exhaust the audience’s capacity to distinguish truth from fiction through sheer volume.” , Microsoft Threat Intelligence Assessment, late 2024.
Technical analysis of the hosting providers links these activities directly to servers previously associated with the Russian GRU. The use of shared SSL certificates and specific PHP configurations across the DC Weekly and London Crier clusters provided the digital fingerprint necessary to attribute the sites to a single operator. Even with public exposure, the low cost of domain registration and the zero-marginal cost of AI content generation allow the network to outpace takedown efforts. When one domain is seized, three more appear, pre-populated with thousands of AI-written articles, ready to receive the Storm-1516 payload.
Automated Radicalization: The Technical Pipeline from RSS Scraping to Partisan Rewrite

The Ingestion Engine: Industrial- RSS Scraping
The operational backbone of the CopyCop network is not a room of human writers, a relentless, automated ingestion engine designed to consume legitimate journalism at a that physically human capacity. Recorded Future’s Insikt Group identified that in less than sixty days following its March 2024 activation, the network generated over 19, 000 unique articles. This volume, averaging over 300 articles per day across its initial cluster, relies on a specific technical vulnerability in modern digital publishing: the RSS feed.
CopyCop’s scripts target the Really Simple Syndication (RSS) feeds of major international news organizations, including Al Jazeera, Fox News, the BBC, and French outlets like La Croix and TV5Monde. The choice of reveals a strategic bifurcation: the network ingests content from both left-leaning and right-leaning sources, not to amplify their original reporting, to use them as raw data for partisan re-contextualization. Unlike “pink slime” networks of the past, which frequently relied on press releases or low-quality original content, CopyCop parasitizes high-credibility journalism to lend a veneer of verisimilitude to its fabrications.
Technical analysis of the network’s traffic patterns suggests the use of commercial-grade scraping tools, likely variants of “CyberSEO Pro” or “WP Automatic”, plugins common in the WordPress ecosystem that allow for the automated fetching of full-text articles from truncated RSS feeds. Once the scraper detects a new URL in a target feed (e. g., a BBC report on Ukraine), it extracts the headline, body text, and featured image. This raw HTML is then stripped of its original metadata, canonical tags, and internal links, severing the digital chain of custody that would normally attribute the work to its original author.
The Transformation: Weaponized LLMs and Prompt Injection
The defining innovation of CopyCop is its “Transformation “, the stage where scraped content is passed through a Large Language Model (LLM) to undergo radicalization. Evidence collected by threat intelligence analysts indicates that the operators moved away from commercial APIs (like OpenAI’s GPT-4, which has strict safety filters) and toward self-hosted, uncensored open-source models. By May 2024, technical indicators pointed to the use of Meta’s Llama 3 or similar high-performance open weights models, hosted on private infrastructure (frequently Akamai/Linode servers) to evade content moderation policies.
The “rewrite” process is governed by system prompts, hidden instructions that tell the AI how to alter the text. These prompts are the “editorial voice” of the network. While the exact prompt strings are rarely visible to the public, the network’s automated nature led to serious failures where the LLM “leaked” its instructions into the published articles. In several instances documented by researchers, CopyCop articles appeared with introductory refusals or conversational artifacts, such as:
“Please note that this rewrite aims to provide a clear and concise summary of the original text while maintaining key details. The tone is objective and factual…”
These artifacts confirm that the pipeline operates without human review. The script sends the scraped text to the LLM with a command to “rewrite this article from a [specific political] perspective” or “summarize this with a focus on [divisive topic].” The LLM then hallucinates a new angle. A neutral report on UK migration policy, for example, is fed into the model and re-emerges with heightened emotional language, emphasizing “emergency,” “betrayal,” or “criminality” depending on the target audience.
Comparative Analysis: The Algorithmic Shift
The following table illustrates the observed transformation logic used by CopyCop’s algorithms to convert neutral reporting into partisan content. The “Output” column reflects the linguistic patterns found in domains like London Crier and DC Weekly.
| Component | Original Input (Legitimate Source) | CopyCop Output (AI Rewrite) | Technical method |
|---|---|---|---|
| Headline | “US Senate debates new aid package for Ukraine” | “Senate Democrats Betray Taxpayers with Another Blank Check for Kyiv” | Sentiment analysis inversion; insertion of emotive keywords (“Betray”, “Blank Check”). |
| Attribution | “By Sarah Jenkins, BBC News” | “By Editorial Staff” or “By PatriotEagle” | Metadata stripping; insertion of fake persona from a database of 1, 000+ names. |
| Sourcing | “According to a Pentagon report released Tuesday…” | “Sources indicate…” or removal of primary source links. | Link removal scripts; obfuscation of verifiable data points to prevent fact-checking. |
| Tone | Neutral, passive voice (“The bill was delayed…”) | Active, accusatory (“Corrupt officials stalled the bill…”) | Style transfer prompting (e. g., “Rewrite in the style of a populist op-ed”). |
Infrastructure Evasion: Hiding the Server Farms
To sustain this high-velocity output without being blocked by ISPs or registrars, CopyCop employs a “hide-in-plain-sight” infrastructure strategy. The network heavily utilizes Cloudflare to mask the true IP addresses of its origin servers. By sitting behind Cloudflare’s content delivery network (CDN), the operators obscure the hosting location, making it difficult for researchers to definitively attribute the servers to specific Russian hosting providers.
yet, DNS records reveal a pattern of bulk registration. Domains such as londoncrier. com, gbgeopolitics. com, and bbc-uk. news were registered in tight clusters, frequently using NameCheap as the registrar. The operators favor “typosquatting” or “camouflaging”, choosing domain names that sound like legitimate local news outlets (e. g., Houston Post or Chicago Chronicle). This naming convention exploits the “trust gap” in local news; readers are more likely to trust a site that sounds like their hometown paper than a known foreign entity.
The server logs also show a distinct absence of “human” behavior. A human editor posts articles at irregular intervals, with gaps for sleep or research. CopyCop sites publish in bursts, dozens of articles appearing within the same minute, indicating a cron job (a time-based job scheduler in Unix-like computer operating systems) that triggers the Scrape -> Rewrite -> Publish loop at set intervals. This mechanical heartbeat is one of the primary signals used by threat intelligence firms to identify new nodes in the network.
The “Hallucination” Vector: When the Pipeline Fails
The reliance on fully automated pipelines introduces a specific vulnerability: AI hallucination. Because there is no human in the loop to verify the rewrite, CopyCop articles frequently invent quotes or misinterpret the original text in ways that logic. In one case involving the Israel-Gaza conflict, the AI rewrote a report on a ceasefire negotiation inverted the parties involved, attributing the terms of one side to the other. These errors do not slow the operation; the goal is saturation, not accuracy.
also, the image generation pipeline, frequently integrated via APIs to tools like Midjourney or DALL-E (or open-source equivalents like Stable Diffusion), adds another of synthetic. Articles are frequently paired with AI-generated images that bear the tell-tale signs of synthetic media: malformed hands, nonsensical text in the background, or “glossy” textures. These images are generated based on the rewritten headline, meaning the visual content reinforces the radicalized narrative rather than the reality of the event.
The Persona Botnet
The final stage of the technical pipeline is the assignment of authorship. The network maintains a database of over 1, 000 fake journalist personas. These are not names; they are digital assets complete with AI-generated headshots (likely created using GANs, Generative Adversarial Networks) and short, generic biographies (e. g., “John is a political analyst with 10 years of experience in Washington”).
When an article is ready for publication, the CMS (Content Management System) randomly assigns one of these personas to the byline. This creates the illusion of a bustling newsroom. In reality, “John” might publish an article on US tax policy at 10: 00 AM and an article on French agricultural protests at 10: 01 AM, a physical impossibility for a human reporter. This “Persona Botnet” is integral to the deception, as it prevents the content from appearing as a faceless corporate feed, thereby increasing the likelihood of engagement on social media platforms where the links are eventually seeded.
The entire pipeline, from the initial RSS ping to the final WordPress publication, takes minutes. This speed allows CopyCop to “front-run” the narrative. By the time a legitimate news outlet publishes a follow-up or a correction, the CopyCop version has already been indexed, shared, and consumed by the target audience, establishing a false baseline of facts that is difficult to dislodge.
The 24-Hour Cycle: Quantifying Content Velocity and Publication Frequency Metrics
The Velocity of Automation: 19, 000 Articles in 60 Days
The defining characteristic of the CopyCop network is not the sophistication of its prose, the sheer, inhuman speed of its production. Telemetry data collected by Recorded Future’s Insikt Group between March and May 2024 indicates the network published over 19, 000 unique articles in a span of less than sixty days. This volume averages to approximately 316 articles per day, a rate that physically exceeds the capacity of even the largest human-staffed metropolitan newsrooms. Unlike traditional propaganda operations, which require human operators to draft and approve narratives, CopyCop operates on a “scrape-and-rewrite” loop that functions continuously, without shift changes, weekends, or sleep.
Temporal Analysis of the 24-Hour pattern
Analysis of server timestamps reveals a distinct absence of circadian rhythms in CopyCop’s publication schedule. Legitimate news outlets show a “heartbeat” pattern: activity spikes during business hours (08: 00 to 18: 00 local time) and drops significantly during overnight hours. CopyCop domains, yet, maintain a flatline of high-frequency output 24 hours a day. This relentless consistency serves a specific tactical purpose: it floods search engine indexes with fresh content, increasing the probability that a CopyCop article appear in “latest news” algorithms before legitimate corrections or fact-checks can gain traction.
The network’s latency, the time between the publication of a legitimate article and the appearance of its distorted clone, is consistently under 24 hours. In observed cases, the rewrite appears within 60 minutes of the source material. This tight feedback loop allows the network to “newsjack” breaking stories, inserting partisan spins into developing narratives while public interest is at its peak.
Comparative Metrics: Human vs. Algorithmic Output
To understand the of this operation, it is necessary to compare the output of CopyCop’s automated infrastructure against traditional media organizations. The following table contrasts the operational metrics of a standard mid-sized digital newsroom against the observed performance of the CopyCop network during its peak activity in mid-2024.
| Operational Metric | Traditional Digital Newsroom | CopyCop Network (Est.) |
|---|---|---|
| Daily Article Volume | 40, 60 articles | 300+ articles |
| Staffing Requirements | 25, 50 Journalists/Editors | 1, 3 Administrators |
| Production pattern | 16-hour active window | 24-hour continuous loop |
| Cost Per Article | $150, $500 (Salary/Overhead) | <$0. 01 (API/Compute Costs) |
| Verification Time | 30, 90 minutes | 0 minutes |
Infrastructure Bursts and Domain Expansion
The network’s velocity applies not only to content generation also to infrastructure deployment. Between May 10 and May 12, 2024, the operators registered 120 new websites in a single 48-hour window. This “infrastructure burst” coincided with a strategic pivot toward the U. S. presidential election. Domains such as The London Crier, New York News Daily, and the Lansing Tribune were brought online and immediately began populating with backdated or rapidly generated content to establish a veneer of legitimacy. By September 2025, the network had expanded to over 300 active domains, targeting audiences in the United States, France, and the United Kingdom.
Error Rates as Indicators of Unmonitored Speed
The prioritization of speed over quality results in a high frequency of “hallucination” errors and prompt injections, which serve as forensic evidence of the network’s automated nature. Because the system operates without human-in-the-loop verification, LLM refusal messages are frequently published directly as news headlines.
In several documented instances, articles on CopyCop domains contained the phrase “, I cannot rewrite this text,” or included the specific instructional prompt (e. g., “Please rewrite this article to take a cynical tone toward the US government”) within the body of the published text. These artifacts confirm that the ingestion-to-publication pipeline is fully automated. The system scrapes a target URL, feeds the text to an API (likely OpenAI’s GPT series or similar models based on the error syntax), and posts the response immediately to a WordPress CMS using the “Ascendor” theme, regardless of whether the output is a coherent news story or a chatbot error message.
Saturation Strategy and SEO Impact
The volume of content is not a byproduct of efficiency a core component of the “saturation” strategy. By generating thousands of articles per week, the network creates an artificial consensus effect. When a user searches for a specific long-tail political keyword, the sheer number of CopyCop articles increases the likelihood that one of the network’s domains capture the click. This method exploits the “freshness” signals used by search engines like Google and Bing, which frequently prioritize published content for news-related queries. The network’s ability to publish hundreds of variations of the same story across 300+ domains creates a “hall of mirrors” effect, where a single piece of disinformation appears to be widely reported by multiple independent local outlets.
Operational Convergence: Analyzing Overlaps Between CopyCop Sites and Storm-1516 Assets

The Symbiosis of Fabrication: Storm-1516 and the CopyCop Amplifier
Analysis of telemetry data from 2024 and 2025 reveals that CopyCop does not operate in a vacuum. While the network functions as an automated technical infrastructure, its editorial agenda is inextricably linked to Storm-1516, a Russian influence operation identified by researchers at Clemson University and the French state agency VIGINUM. The relationship is symbiotic: Storm-1516 manufactures the “evidence”, fake whistleblower videos, forged documents, and staged testimonies, while CopyCop provides the industrial- distribution method required to force these narratives into search engine results.
The John Mark Dougan Nexus
The primary between the two entities is John Mark Dougan, a former Florida deputy sheriff residing in Moscow. Recorded Future’s Insikt Group and other intelligence bodies have identified Dougan as a central operator within the Storm-1516 ecosystem. Unlike the Internet Research Agency (IRA), which relied on human troll farms, Dougan’s operations use CopyCop’s AI infrastructure to automate the “laundering” of disinformation. Evidence suggests that when a Storm-1516 asset, such as the -defunct DC Weekly or Clear Story News, publishes a fabricated exclusive, CopyCop nodes immediately scrape, rewrite, and republish the content. This process obscures the original Russian source, the narrative with hundreds of AI-generated variations that appear to be independent reporting from local American or European outlets.
Technical Convergence: The Linode Connection
Network analysis confirms a physical infrastructure overlap between known Storm-1516 assets and the broader CopyCop network. In late 2024 and throughout 2025, security researchers tracked a cluster of over 35 US-themed CopyCop websites hosted on the IP address `72. 14. 185. 187`. This server, owned by Akamai/Linode, also hosted domains directly attributed to Dougan’s operations. This shared hosting environment indicates that CopyCop is not a “customer” of Storm-1516 narratives likely functions as the dedicated amplification wing of the same apparatus. The convergence allows for near-instantaneous cross-pollination; a “breaking news” story on a Storm-1516 primary site triggers a cascade of reprints across CopyCop’s 300+ domains within hours.
The Disinformation Supply Chain
The operational workflow follows a rigid pattern designed to exploit search algorithms. The table details three specific instances where Storm-1516 fabrication was systematically processed through the CopyCop network between 2024 and 2025.
| Operation Phase | Storm-1516 Role (The Seed) | CopyCop Role (The Sprout) | Outcome |
|---|---|---|---|
| Origin | Produces a fake “whistleblower” video (e. g., “Olena Zelenska’s $1M Shopping Spree”). | Scrapes the initial article from a “burner” site like DC Weekly. | Establishes a false “primary source.” |
| Laundering | Publishes the story on a site designed to look like a US local news outlet. | AI rewrites the story 50-200 times, changing headlines and syntax keeping the core lie. | Floods Google News with “independent” corroboration. |
| Amplification | Russian embassy accounts and bots share the “Western” reports. | Sites like London Crier or Capital City Daily host the rewritten content to serve as citation points. | Mainstream users encounter the story via search, not social media direct links. |
Case Study: The “Macron Cocaine” Fabrication (May 2025)
A clear example of this operational convergence occurred in May 2025. Storm-1516 assets circulated a fabricated narrative claiming French President Emmanuel Macron and other European leaders used cocaine during a diplomatic train ride to Kyiv. The “evidence” was a deliberately misrepresented image of a tissue and a metal stirrer. Within 24 hours of the initial claim appearing on X (formerly Twitter) via Storm-1516 affiliated accounts, CopyCop nodes began publishing AI-generated articles treating the allegation as a serious controversy. Sites such as Capital City Daily and New York News Daily (both CopyCop assets) ran headlines framing the fabrication as a “viral question” or “diplomatic scandal,” stripping away the context of the debunking. This allowed the narrative to in search queries for “Macron Kyiv train” long after the original social media posts were flagged or removed.
Expansion into Fact-Checking Mimicry
In a disturbing evolution observed in mid-2025, the convergence expanded to include a network of fake fact-checking sites. Identified by Insikt Group, domains like truefact. news began hosting CopyCop content. These sites ostensibly “fact-checked” Storm-1516 narratives invariably concluded that the false claims were “true” or “plausible.” This tactic creates a closed loop: 1. Storm-1516 invents a lie. 2. CopyCop news sites report the lie. 3. CopyCop “fact-checkers” validate the lie. This self-referential ecosystem insulates the disinformation from external debunking, as the network generates its own verification. The Truefact network expanded operations to include subdomains targeting Turkey, Ukraine, and Spain, indicating that the Storm-1516/CopyCop merger is a global, rather than strictly anti-American, enterprise.
Strategic
The integration of Storm-1516’s creative deception with CopyCop’s automated represents a maturation of Russian information warfare. It solves the “reach” problem that plagued earlier operations. By using AI to rewrite content, the network avoids duplicate content penalties from search engines, allowing a single piece of fabricated evidence to generate thousands of unique web pages. This method “grooms” Large Language Models (LLMs) and search algorithms, ensuring that future AI queries about these specific topics retrieve the fabricated data as factual history.
Server-Side Forensics: IP Co-location and Shared SSL Certificates Among Fake Outlets
The Illusion of Independence: Server-Side Centralization
While CopyCop’s front-end interface mimics a diverse ecosystem of independent local news outlets, ranging from the San Francisco Chronicle lookalikes to neighborhood gazettes, the backend infrastructure reveals a monolithic, centralized operation. Network telemetry and server-side forensics the “grassroots” facade, exposing a rigid, automated architecture designed for rapid deployment rather than journalistic integrity. The following forensic indicators, verified by Insikt Group and other threat intelligence firms between 2024 and 2025, confirm that these hundreds of “distinct” outlets operate from a single digital command center.
1. The Linode Nexus (IP 72. 14. 185. 187)
The most damning evidence of coordination appeared in early 2025, when a configuration error momentarily exposed the origin servers behind the network’s Cloudflare shield. Investigators identified a single IP address, 72. 14. 185. 187, hosted by Akamai/Linode (AS63949), hosting over 35 ostensibly unrelated US-themed news sites. In a legitimate media environment, competing outlets do not share the same dedicated server IP. This “Linode Nexus” served as the primary staging ground for the network’s expansion into North American markets.
| Forensic Indicator | Details | Implication |
|---|---|---|
| Shared IP Address | 72. 14. 185. 187 (Akamai/Linode) | Proves physical centralization of “independent” outlets. |
| Registration Batch | Jan 29, 2025 (35+ domains) | Indicates automated, bulk acquisition rather than organic growth. |
| SSL Issuer | Let’s Encrypt (R3) | Automated, free certificate issuance at identical timestamps. |
| Naming Convention | [Region]. TrueFact. News | Standardized subdomain architecture for global scaling. |
2. The “TrueFact” Subdomain Architecture
Unlike legitimate news organizations that register unique domains for international branches, CopyCop used a cost- wildcard DNS strategy. Forensic analysis of the domain truefact. news revealed a sprawling subdomain network including africa. truefact. news, ukraine. truefact. news, and turkey. truefact. news. These subdomains resolved to the same server clusters and utilized identical CMS templates. This “cookie-cutter” deployment allows the operators to spin up a new “regional bureau” in seconds by simply adding a DNS record, a method inconsistent with genuine media expansion standard for server farms.
3. SSL Certificate Timestamping
Cryptographic evidence further the network’s cover. Security researchers analyzed the Not Before and Not After timestamps on the SSL/TLS certificates protecting these sites. In multiple instances, certificates for supposedly unconnected outlets (e. g., a “Chicago” political blog and a “Paris” fashion site) were issued within the same sixty-second window by Let’s Encrypt. This temporal synchronization confirms that a single automated script requested and deployed security credentials for the entire batch simultaneously.
4. The DCWeekly Fingerprint
analysis into the server headers linked the CopyCop infrastructure to John Mark Dougan, a Moscow-based US fugitive. The server configurations for the new CopyCop nodes mirrored the unique PHP settings and plugin distinctiveness found on DCWeekly, a known disinformation hub run by Dougan. These shared “fingerprints”, including specific caching plugins and WordPress theme version numbers, acted as a digital DNA match, connecting the new AI-driven swarm directly to established Russian influence operations.
5. Dormant Infrastructure and “Sleeper” Domains
Whois data reveals a pattern of “sleeper” domains. The network registers domains in batches of 50 to 100, frequently using privacy protection services to mask ownership. yet, these domains frequently sit on “parking” IPs provided by registrars like NameCheap or GoDaddy for months before activation. Once a political trigger event occurs (such as an election debate or a scandal), the DNS records are abruptly pointed to the active Linode infrastructure, and the site begins populating with AI-generated content immediately. This “just-in-time” infrastructure delivery minimizes the window for defenders to blacklist the domains before they go live.
Forensic Note: The use of Cloudflare as a reverse proxy is ubiquitous across the CopyCop network. While this hides the origin IP from casual browsing, the operators’ failure to consistently configure firewall rules allowed researchers to bypass the CDN and hit the origin server directly, confirming the 72. 14. 185. 187 centralization.
Narrative Injection: How AI Modifies Neutral Reporting into Polarized Propaganda

Narrative Injection: The Automated Mutation of Truth
The CopyCop network represents a fundamental shift in disinformation mechanics: the move from manual fabrication to automated “narrative injection.” Unlike traditional troll farms that employ humans to draft individual falsehoods, CopyCop uses Large Language Models (LLMs) to ingest legitimate news from reputable wire services, including Reuters, Al Jazeera, and the BBC, and algorithmically mutate it. This process preserves the skeletal facts of an event while replacing the connective tissue with partisan bias, emotive language, and fabricated details.
Forensic analysis by Recorded Future’s Insikt Group and Clemson University’s Media Forensics Hub identified a specific pivot point in this methodology. Prior to September 20, 2023, outlets like DCWeekly largely relied on copy-pasting content from Russian state media. After this date, the network integrated generative AI, specifically shifting to self-hosted, uncensored versions of Llama 3 models by 2025. This upgrade allowed the network to generate over 19, 000 unique articles in less than 60 days in early 2024, a volume that physically exceeds the capacity of any human-staffed newsroom.
The Anatomy of a Rewrite
The core of CopyCop’s strategy is “prompt engineering as editorial policy.” The system does not summarize; it is instructed to apply specific tonal filters based on the subject matter. Telemetry data reveals that prompts directed the AI to adopt a “cynical” or “negative” tone when covering the U. S. government, NATO, or Ukraine, while applying a “positive” or “sympathetic” frame to stories involving Russia or specific U. S. political candidates.
Researchers recovered “prompt artifacts”, accidental inclusions where the AI printed its instructions alongside the article. One such artifact found in a French-language Verité Cachée article explicitly commanded the model to “take a conservative stance against the liberal policies of the Macron administration.” Another artifact found in a Bayou City News article included the apologetic preamble: “Please note that this rewrite aims to provide a clear and concise summary of the original text while maintaining key details,” exposing the artificial origin of the text.
Case Study: The “London Crier” and the Highgrove Hoax
A primary example of narrative injection occurred in March 2024 involving the fake outlet The London Crier. The network took a neutral seed event, Ukrainian President Volodymyr Zelensky’s diplomatic relations with the UK, and injected a completely fabricated corruption narrative. The AI-generated story claimed Zelensky had purchased King Charles III’s Highgrove House estate for £20 million.
The story was “washed” through the London Crier to give it the veneer of a local British exclusive. It a “former butler” named Grant Harrold, who, when contacted by real journalists, confirmed he never made the statement. even with the fabrication, the story was amplified by the Russian Embassy in South Africa and viewed over 1. 3 million times on X (formerly Twitter) within days.
Table: From Wire News to Weaponized Fiction
The following table demonstrates how CopyCop’s AI modifies neutral “seed” events into polarized propaganda.
| Seed Event (Real) | CopyCop Outlet | Injected Narrative (Fake) | Linguistic Shift |
|---|---|---|---|
| Olena Zelenska visits New York Standard diplomatic trip during UN General Assembly. |
DCWeekly | “$1. 1 Million Cartier Spree” Claimed the Lady spent $1. 1M on jewelry while demanding US aid. |
Shifted focus from diplomatic mission to “elitist excess” and “misuse of taxpayer funds.” |
| Zelensky visits UK Meetings with UK officials regarding defense aid. |
The London Crier | “Highgrove House Purchase” Alleged Zelensky bought the Royal estate for £20M as a personal getaway. |
Replaced “defense cooperation” with “personal corruption” and “flight risk.” |
| Operation Spiderweb Ukraine launches drone strikes on Russian airfields. |
Silver City News | “Mass Desertions” Claimed the operation failed so badly it caused mutiny in Ukrainian ranks. |
Inverted the event’s outcome; changed “offensive strike” to “catastrophic failure.” |
| US Border Policy Update DHS releases new asylum processing statistics. |
Chicago Chronicle | “Invasion Facilitation Scheme” Framed routine stats as a deliberate plot to replace voters. |
Changed administrative terms (“processing,” “policy”) to militarized terms (“invasion,” “scheme”). |
The of Automated Bias
The danger of CopyCop lies not in the sophistication of a single article, in the industrial of its production. By late 2025, the network had expanded to over 300 domains, including San Francisco Chronicle (fake), Boston Times (fake), and Flagstaff Post. Each site operates on autopilot, scraping real local news to build credibility (weather, sports, traffic) before injecting the targeted political disinformation.
This “camouflage” technique makes the narrative injection harder to detect for casual readers. A user visiting DCWeekly sees 90% real news about Washington D. C., making the 10% of AI-poisoned content regarding Ukraine or U. S. elections appear as legitimate investigative reporting. The AI ensures the syntax and tone match the surrounding real news, creating a direct interface between reality and propaganda.
The Monetization Loop: Programmatic Advertising and Financial Incentives for AI Slop
The Programmatic Ad method
The financial engine of CopyCop relies on the automated nature of modern digital advertising. Unlike traditional media buying, where advertisers select specific publications, programmatic advertising uses algorithms to place ads based on user data rather than website quality.
This “blind” placement system creates a loophole that CopyCop exploits with industrial efficiency. Ad exchanges, primarily Google AdSense, serve as the intermediaries. According to a 2024 analysis by NewsGuard, over 90% of the ads found on AI-generated news sites, including those within the CopyCop sphere, were served by Google. The process operates on a simple loop:
| Stage | Action | Outcome |
|---|---|---|
| Ingestion | Bots scrape legitimate articles from outlets like Al Jazeera or Fox News. | Zero-cost raw material acquired. |
| Transformation | LLMs rewrite content to inject bias and evade plagiarism detectors. | Unique text generated for pennies. |
| Publication | Articles are posted to sites like London Crier or DC Weekly. | Inventory created for ad slots. |
| Monetization | Ad exchanges auction space to the highest bidder in milliseconds. | Revenue generated per impression. |
Inadvertent Funding by Blue-Chip Brands
The programmatic model means that major Western corporations are inadvertently subsidizing the very networks designed to destabilize their home markets. Reports from 2024 identified 141 major brands whose advertisements appeared on unreliable AI-generated news sites. These included top-tier financial services firms, luxury retailers, and broadband providers.
Because the ad tech ecosystem prioritizes audience targeting (retargeting a user who previously visited a shoe store) over contextual safety, a user reading a fabricated story about the war in Ukraine on a CopyCop site is shown ads for products they viewed. This “audience- ” logic decouples the ad from the content, allowing disinformation operators to monetize traffic without direct relationships with advertisers.
“The system is automated and works on algorithms… the company buying the advertising space may not know where its ad ends up. This reality explains why millions of dollars in advertising revenue end up on sites peddling disinformation.” , Recorded Future Analyst Note, 2024
The Economics of AI Slop
The shift from human troll farms to AI generation has fundamentally altered the cost-benefit analysis of disinformation. Previously, maintaining a network of writers to produce 19, 000 unique articles would require a massive payroll. With LLMs, the cost of generating this volume of text is negligible, frequently costing less than a few dollars in API fees or electricity for self-hosted models.
This collapse in production costs means that even low-quality traffic can yield a profit. If a CopyCop site generates $5 in ad revenue for every 1, 000 visitors (a conservative CPM), and the cost to produce the content is fractions of a cent, the operation becomes self-sustaining. This financial insulation makes the network resilient; even if individual domains are blacklisted, the low sunk costs allow operators to spin up new domains immediately without significant financial loss.
Brand Safety Failures
even with claims by major ad tech platforms that they enforce strict publisher policies, the sheer volume of CopyCop content overwhelms manual review processes. The network’s use of “spoofed” domains, such as bbc-uk. news, further complicates automated detection. These domains mimic trusted authorities, tricking both human readers and ad verification scripts into classifying the inventory as “safe news.”
The persistence of these ads suggests a widespread failure in the “Know Your Customer” (KYC) of ad exchanges. While legitimate publishers frequently face rigorous verification blocks, the CopyCop network successfully monetized hundreds of domains, suggesting that the speed of AI content generation has outpaced the defensive capabilities of the current digital advertising infrastructure.
2024 Election Vectors: Specific Targeting of Swing State Demographics and Issues

The May 2024 Pivot: Industrial- Election Interference
In May 2024, the operational cadence of the CopyCop network shifted abruptly. Telemetry data from Recorded Future’s Insikt Group captured the registration of over 120 new domain names between May 10 and May 12, 2024. This infrastructure expansion marked a strategic pivot from general anti-Western sentiment to a laser-focused disruption of the 2024 United States presidential election. Unlike previous iterations that targeted French or British audiences, this wave of “pink slime” sites, fake local news outlets designed to mimic legitimate community journalism, was engineered to penetrate the information ecosystems of key American battlegrounds.
The network’s output volume is mechanically impossible for human operators to sustain. In a single 60-day window, CopyCop assets generated over 19, 000 unique articles. This flood of content was not created ex nihilo; rather, the network employed a “launder-and-poison” strategy. Automated scrapers ingested reporting from mainstream sources such as Al Jazeera, Fox News, and the BBC. Large Language Models (LLMs) then rewrote these articles, stripping the original context and injecting specific partisan biases before republishing them under the guise of local news. The speed of this pattern, frequently less than 24 hours from original publication to distorted rewrite, allowed CopyCop to hijack breaking news pattern in swing states before verified facts could take hold.
Vector 1: The “Cynical Tone” Prompt Engineering
Forensic analysis of CopyCop’s HTML code and error logs revealed the specific prompt engineering used to radicalize content. Unlike generic “rewrite this” commands, the network’s operators fed LLMs highly specific tonal instructions. One exposed prompt, recovered from a server configuration error, explicitly instructed the AI to “highlight the cynical tone towards the US government, NATO, and US politicians” and to “emphasize the perception of Republicans.”
This automated cynicism weaponized voter apathy. By systematically rewriting neutral economic reports or foreign policy updates to sound hopeless or corrupt, the network aimed to depress turnout among specific demographics. The AI was directed to adopt the voice of a “knowledgeable insider” or a “concerned local citizen,” masking the foreign origin of the propaganda. This technique allowed the network to its operations across hundreds of sites without the need for a large staff of fluent English speakers, as the LLMs handled the linguistic nuance required to sound American.
Vector 2: The Michigan Wedge, Gaza and Ukraine Fatigue
Michigan, a serious swing state with a significant Arab-American population and a history of tight margins, became a primary testing ground for CopyCop’s “wedge” narratives. The network exploited the Israel-Gaza conflict to fracture the Democratic coalition. CopyCop sites ingested content from polarized sources and rewrote it to amplify specific emotional triggers.
Articles targeting Michigan demographics frequently reframed US aid to Israel not as a geopolitical stance as a direct theft of domestic resources. Simultaneously, the network pushed “Ukraine fatigue” narratives, rewriting stories about corruption in Kyiv to suggest that American tax dollars were funding foreign oligarchs while Michigan’s infrastructure crumbled. The goal was not necessarily to convert voters to the Republican ticket, to induce “double-hating”, a state where voters despise both options and choose to stay home.
Targeted Narrative Clusters in Michigan
| Original Source Topic | CopyCop Rewrite Angle | Target Demographic | Primary Emotion Trigger |
|---|---|---|---|
| US Aid Package to Ukraine | “Money Laundering Scheme for Elites” | Working Class / Union Voters | Economic Resentment |
| Humanitarian Aid to Gaza | “Biden Ignores Domestic emergency for Foreign Wars” | Arab-American / Progressive | Betrayal / Apathy |
| Inflation / CPI Reports | “The Dollar is Collapsing: Prepare “ | Suburban Families | Financial Panic |
| Local Crime Statistics | “Migrant Crime Wave Hits Midwest” | Rural / Exurban Voters | Safety / Fear |
Vector 3: The Arizona and Nevada “Invasion” Narrative
In the distinct political environments of Arizona and Nevada, CopyCop’s algorithms adjusted to focus on immigration and border security. The network’s “pink slime” sites, frequently bearing names that sounded like legitimate regional outlets (e. g., The Phoenix Chronicle or similar variants), flooded local social media groups with rewritten stories about the southern border.
The AI rewriting process here was specifically tuned to replace neutral terminology with alarmist vocabulary. “Migrants” became “invaders”; “border crossings” became “assaults on sovereignty.” By scraping right-wing commentary and blending it with rewritten mainstream news, the network created a “truth sandwich” where factual events were encased in of fabricated context. This content was specifically designed to trigger engagement algorithms on platforms like X (formerly Twitter) and Facebook, ensuring that the most inflammatory versions of a story reached low-information voters in Maricopa and Clark counties.
Vector 4: The “DC Weekly” Corruption Hub
While CopyCop sites operated in obscurity, DC Weekly emerged as a central hub for high-impact disinformation that filtered down to swing state voters. Linked to John Mark Dougan, a former Florida deputy sheriff residing in Moscow, DC Weekly served as the launchpad for complex narrative attacks.
The site specialized in the “fake whistleblower” tactic. It would publish videos featuring actors posing as insiders, such as the debunked claim that Olena Zelenska, the Lady of Ukraine, spent $1. 1 million on Cartier jewelry in New York City. Once published on DC Weekly, the CopyCop network’s automated bots would cite this “investigation” across hundreds of other fake local sites. For a voter in Pennsylvania or Wisconsin, the story would appear to be corroborated by multiple independent sources, creating an illusion of validity through sheer repetition. This specific vector was designed to trust in foreign aid, a key problem for the 2024 election pattern.
Vector 5: Economic Anxiety in the Rust Belt
For the industrial battlegrounds of Pennsylvania and Wisconsin, CopyCop’s prompt engineers focused on economic despair. The network scraped legitimate financial news, reports on interest rates, manufacturing output, or energy prices, and rewrote them to forecast imminent societal collapse.
These articles frequently employed a “populist” frame, positioning the reader as the victim of a rigged system. The AI was instructed to link global economic trends directly to the current administration’s incompetence. For example, a standard report on oil prices would be rewritten to blame “Green Energy mandates” for high gas prices in rural Pennsylvania, directly targeting the fracking vote. By localizing global economic pain, CopyCop attempted to turn general economic anxiety into specific electoral anger.
The Infrastructure of Evasion
To maintain this bombardment of swing states, CopyCop evolved its infrastructure to evade detection. In mid-2024, the network began moving its hosting from known Russian servers to US-based residential IP addresses. This “infrastructure laundering” made the sites appear domestic to automated threat detection systems. also, the network began using “typosquatting” domains, URLs that closely resemble legitimate news outlets (e. g., WashingtonPost. pm or FoxNews. ltd), to trick casual readers.
The use of generative AI also allowed the network to defeat traditional plagiarism checkers. Because the LLMs generated unique text for every article, even when covering the same topic, the content did not trigger duplicate content filters. This allowed CopyCop to flood the zone with thousands of variations of the same narrative, overwhelming the capacity of fact-checkers to debunk them one by one.
Attribution Layers: Tracing the Russian Links Behind the Influence Operation
The Moscow Nexus: From Florida Fugitive to GRU Asset
While the CopyCop network operates with the speed of automated algorithms, its command structure leads directly to human operators in Moscow. Forensic analysis by Recorded Future’s Insikt Group and subsequent confirmation by the U. S. Department of the Treasury has stripped away the network’s anonymity, revealing a tiered architecture of attribution that ascends from a rogue American fugitive to the highest levels of Russian military intelligence.
1: The Operator , John Mark Dougan
The operational hub of CopyCop is John Mark Dougan, a former deputy sheriff from Palm Beach County, Florida, who fled the United States in 2016 to evade hacking and extortion charges. residing in Moscow under the protection of the Russian state, Dougan has reinvented himself as a “journalist” and key node in the Kremlin’s information warfare machine.
Technical evidence links Dougan directly to the network’s flagship domains. Registration data and IP history connect DC Weekly, the network’s most successful asset, to Dougan’s personal digital footprint. In early 2024, investigators traced the hosting of DC Weekly and the Chicago Chronicle to a server cluster at 89. 31. 82. 185, an IP address located in Russia that also hosts Dougan’s personal projects, including darkpulsar. ai and skryty. ru. Unlike previous operations that attempted to mask their origin through complex VPNs, CopyCop’s initial infrastructure was brazenly Russian, relying on domestic hosting providers that do not cooperate with Western law enforcement.
2: The Ideologues , Center for Geopolitical Expertise (CGE)
Dougan does not operate in a vacuum. Financial and strategic support flows through the Center for Geopolitical Expertise (CGE), a Moscow-based think tank founded by the ultranationalist philosopher Aleksandr Dugin. The CGE is directed by Valery Korovin, a Dugin acolyte who has long advocated for the use of “network-centric warfare” to destabilize Western societies.
On December 31, 2024, the U. S. Department of the Treasury sanctioned the CGE and Korovin, explicitly identifying them as the architects behind the network’s expansion. Treasury findings revealed that the CGE used generative AI to “quickly create disinformation that would be distributed across a massive network of websites designed to imitate legitimate news outlets.” This designation confirmed that CopyCop (referred to in intelligence circles as Storm-1516) was not a nuisance a formalized state asset tasked with interfering in the 2024 U. S. election.
| Entity | Role | Evidence of Link |
|---|---|---|
| John Mark Dougan | Primary Operator / Administrator | Shared IP addresses (89. 31. 82. 185), domain registration records, self-identification in interviews. |
| Center for Geopolitical Expertise (CGE) | Strategic Direction / Funding | U. S. Treasury sanctions (Dec 2024), coordination with Dougan on specific narratives. |
| Valery Korovin | Director of CGE | Direct oversight of AI-driven influence operations; sanctioned for election interference. |
| GRU (Unit 29155) | State Intelligence Oversight | Intelligence reports linking CGE activities to GRU directives; provision of funding for server infrastructure. |
3: The State , GRU Connection
The attribution trail terminates at the Main Intelligence Directorate of the Russian General Staff (GRU). Intelligence assessments released in late 2024 indicate that the CGE operates under the direct supervision of the GRU, specifically units associated with psychological operations and sabotage. The GRU reportedly provided the funding necessary for CopyCop to transition from using commercial AI APIs (like OpenAI’s) to self-hosted Large Language Models (LLMs).
This technical shift was serious. By mid-2024, CopyCop began running uncensored versions of Meta’s Llama-3-8b model on its own Russian servers. This allowed the network to bypass the safety guardrails of Western AI companies, which had begun blocking Dougan’s accounts. The ability to host and fine-tune these models requires significant computational resources, further corroborating state-level sponsorship.
The “Doppelganger” Overlap
CopyCop shares tactical DNA with the “Doppelganger” operation (associated with the Russian firm Social Design Agency), yet it remains distinct in its reliance on automation. While Doppelganger focuses on cloning legitimate government and media sites (e. g., creating a fake Washington Post URL), CopyCop invents entirely new “local” outlets. yet, the two networks cross-pollinate; narratives seeded by Dougan’s DC Weekly are frequently amplified by Doppelganger bot networks on X (formerly Twitter) and Telegram, creating a self-reinforcing echo chamber.
The Foundation to Battle Injustice (FBI), an organization originally financed by the late oligarch Yevgeny Prigozhin, also plays a serious amplification role. even with Prigozhin’s death in 2023, the Foundation continues to promote CopyCop’s “investigations,” lending a veneer of institutional credibility to fabricated stories about Ukrainian corruption or U. S. border crises.
“The infrastructure supporting CopyCop is not just a collection of websites; it is a weapon system. The integration of American fugitives, Duginist ideologues, and GRU technical resources represents the full maturation of hybrid warfare.” , Insikt Group Threat Assessment, September 2025.
Algorithmic Distribution: The Role of Botnets in Amplifying Rewritten Content
The Distribution Engine: Industrial- Amplification
The operational logic of the CopyCop network relies on a distinct division of labor: AI generates the narrative, botnets provide the velocity. While the network’s ability to churn out 19, 000 unique articles in under sixty days established a new benchmark for automated content generation, the distribution method reveals a more insidious integration with established Russian influence infrastructure. Telemetry data from Recorded Future and the European External Action Service (EEAS) indicates that CopyCop did not operate in a vacuum. Instead, it functioned as a content reservoir for existing botnet architectures, most notably the “Doppelgänger” and “Portal Kombat” networks, decoupling the creation of disinformation from its dissemination.
This decoupling allowed for a “firehose” strategy where the volume of content overwhelmed traditional moderation queues. In early 2024, the network’s primary distribution vector shifted from direct social sharing to a “parasitic” model. Rather than building a new audience from scratch, CopyCop sites, masquerading as local outlets like The Houston Post or DC Weekly, seeded their links into the reply threads of high-engagement posts on X (formerly Twitter). This tactic, known as “reply-guying,” exploited the platform’s algorithmic prioritization of verified or high-activity accounts to insert partisan narratives into unrelated viral conversations.
Network Topology and Cross-Pollination
The architecture of this amplification system is hierarchical. At the top sit the “Source Nodes”, the 300+ CopyCop websites hosted on US-based infrastructure (frequently Akamai/Linode) to evade geo-blocking. them operates a of “Synthetic Personas.” Investigations identified over 1, 000 distinct fake journalist profiles within these sites. These personas, equipped with AI-generated headshots and fabricated biographies, serve as the initial injection point. They share articles not as faceless bots, as “concerned reporters,” creating a veneer of legitimacy that bypasses basic spam filters.
The third consists of the “Amplification Swarm.” This involves thousands of low-quality bot accounts that do not post original content programmatically retweet, like, and quote-tweet the synthetic personas. Data from the 2024 US election pattern showed a correlation between CopyCop publication times and spikes in bot activity. Specifically, articles attacking Western support for Ukraine frequently saw a 400% engagement spike within 15 minutes of publication, a velocity unattainable by organic human behavior. This coordinated “inauthentic behavior” signals a programmatic link between the content management systems (CMS) of the websites and the command-and-control (C2) servers of the botnets.
Table 12. 1: Botnet Amplification Metrics (March, September 2024)
| Metric | Observed Value | Significance |
|---|---|---|
| Article Volume | 19, 000+ (60 days) | Exceeds output of major wire services; saturates keyword searches. |
| Synthetic Personas | 1, 000+ | Provides “human” masking for automated distribution. |
| Amplification Latency | < 15 minutes | Indicates automated API-level integration between sites and bots. |
| Cross-Network Links | Doppelgänger, Portal Kombat | Content is shared across multiple distinct Russian influence networks. |
| Target Geographies | US, France, Germany, Ukraine | Localized content (local news spoofs) tailored for specific electorates. |
Algorithmic Exploitation and “Information Voids”
A serious component of the botnet’s success lies in its exploitation of “data voids” or “information voids.” Search engines and social media algorithms prioritize freshness and relevance. When a breaking news event occurs, such as a specific political gaffe or a localized emergency, there is frequently a deficit of verified information. CopyCop’s bots flood this void. By rapidly generating hundreds of rewritten articles with slight variations in headlines and keywords, and then blasting them via botnets, the network tricks algorithms into perceiving a “trending” topic.
For instance, during the 2024 French snap elections, the network activated a cluster of sites targeting French audiences. These sites did not post links; they utilized bots to tag French political figures and journalists directly. This technique forces the content into the notifications of influential users, increasing the likelihood of a reaction, even a negative one, which the algorithm interprets as engagement. Once a real user interacts with the bot content, the platform’s recommendation engine begins serving it to their followers, laundering the disinformation through organic networks.
“The danger is not just that the bots exist, that they are armed with infinite content. Previous botnets had to repeat the same three phrases. CopyCop bots can post 10, 000 unique variations of the same lie, making detection by repetition filters nearly impossible.” , Cybersecurity Analyst, Recorded Future (Insikt Group Report, May 2024)
The “Influencer” Pivot and Evasion Tactics
As platforms like Meta and X improved their detection of coordinated inauthentic behavior (CIB) in late 2024, CopyCop adapted. The network began to move away from pure bot-driven amplification toward a hybrid model involving “rented” accounts. Investigations revealed that the operators, likely linked to John Mark Dougan and the GRU, began paying fringe influencers and “blue-check” verified accounts to share CopyCop links. This transition from botnet to “influencernet” complicates attribution. A verified account sharing a link to The Boston Chronicle (a fake CopyCop site) looks like organic discourse, not a bot operation.
also, the botnets began using “link masking.” Instead of linking directly to the CopyCop domain (which might be blacklisted), bots would post links to intermediate “burner” sites or legitimate-looking forums that then redirected to the disinformation article. This “referral laundering” technique obscures the origin of the traffic and defeats simple domain-blocking countermeasures. The bots also employed “visual obfuscation,” posting screenshots of the articles rather than clickable links, forcing users to search for the headline manually. This action, searching for the headline, signals high intent to search algorithms, further boosting the ranking of the fake news site in Google results.
Poisoning the AI Well
The final and perhaps most long-term role of the botnets is the poisoning of Large Language Models (LLMs). By generating massive volumes of text and using bots to simulate high engagement, CopyCop attempts to force its narratives into the training datasets of future AI models. When an LLM scrapes the web for information on “US aid to Ukraine 2024,” it encounters thousands of CopyCop articles that appear to be from diverse, “local” sources. The bot activity validates these sources as “popular” and “relevant.”
This creates a feedback loop: AI generates the lies, bots spread the lies, search engines index the lies, and new AI models learn the lies as facts. In tests conducted by NewsGuard in mid-2024, leading chatbots frequently CopyCop websites as authoritative sources for current events. This indicates that the botnets successfully elevated the “authority score” of these fake domains to a level where they contaminated the knowledge base of trusted AI tools.
Conclusion of Investigation
The CopyCop network represents a mature convergence of generative AI and automated distribution. It is not a propaganda campaign a self-sustaining ecosystem designed to the distinction between authentic journalism and algorithmic fiction. The botnets serve as the circulatory system, ensuring that the toxic content generated by the AI heart reaches the extremities of the public discourse. As these networks evolve to use more sophisticated evasion tactics and hybrid human-bot amplification, the challenge for information integrity shifts from simple content moderation to a fundamental defense of the digital reality.


































