HomeDossiersAbsatz: Fake news site utilized in 2025 disinformation campaigns linked to Russia

Absatz: Fake news site utilized in 2025 disinformation campaigns linked to Russia

Silent Push Telemetry Reveals Absatz Hosting Infrastructure Overlap with Known Russian Assets

The Digital Fingerprint: Absatz as the 2025 Disinformation Template

By September 2025, the operational security of Russia’s premier disinformation networks began to fracture under the scrutiny of advanced telemetry. Silent Push, a threat intelligence firm specializing in infrastructure analysis, released a definitive report on September 23, 2025, identifying a unique “technical fingerprint” that inextricably linked the 2025 Moldovan and German election interference campaigns to a single, persistent origin point: Absatz. media.

While Western intelligence agencies had long tracked absatz. media as a registered Russian propaganda outlet run by the sanctioned figure Mikhail Shakhnazarov, the 2025 investigations revealed it was serving a dual purpose. It was not a content publisher; it functioned as a developmental “staging ground” for the ephemeral fake news sites flooding European networks. Silent Push analysts discovered that the underlying code structure, specifically the CSS classes, JavaScript tracking pixels, and CMS configuration files, used on absatz. media was identical to the code deployed across hundreds of “doppelganger” domains targeting the 2025 Bundestag elections and the Moldovan presidential race.

Infrastructure Pivot: The Aeza Group Connection

The forensic between Absatz and the 2025 disinformation wave is built on shared, bulletproof hosting infrastructure. In late 2024, following a series of domain seizures by the US Department of Justice, the operators behind the “Doppelganger” (RRN) and “Storm-1679” campaigns migrated their assets. Telemetry data from Q1 2025 shows a massive migration of absatz. media and its associated clone networks to Aeza Group, a St. Petersburg-based hosting provider.

Aeza Group, sanctioned by the UK, US, and Australia in November 2025, markets itself to cybercriminals as a “bulletproof” host, one that ignores abuse reports and refuses to cooperate with international law enforcement. By moving the Absatz infrastructure to Aeza, the operators signaled a shift from “grey zone” operations to explicit defiance. The telemetry confirms that the IP ranges assigned to Aeza (specifically within AS212773 and AS9009) began hosting both the legitimate absatz. media domain and a constellation of short-lived phishing sites simultaneously. This co-hosting arrangement provided the “smoking gun” needed to attribute the anonymous 2025 campaigns directly to the administrators of Absatz.

Table 1: Shared Infrastructure Telemetry (2025)

The following table details the specific network overlaps identified by Silent Push and confirmed by passive DNS (pDNS) records between January and September 2025.

Primary Asset Associated IP Subnet Hosting Provider (ASN) Linked Disinfo Campaign Shared Technical Artifact
absatz. media 77. 221. 144. 0/24 Aeza Group (AS212773) Storm-1679 (Anti-Olympics/Moldova) Unique ua-parser-js library version; Shared Google Tag Manager ID.
rrn. world (Doppelganger) 45. 142. 212. 0/24 Aeza Group (AS212773) Bundestag 2025 (Fake Der Spiegel) Identical SSL Certificate Issuer (Let’s Encrypt) renewed at same timestamp.
tribunal. ru 85. 119. 146. 0/24 Media Land (AS57523) Ukraine War Crimes (False Flags) Shared DNS Nameservers with Absatz clones.
euro-news-de. com (Fake) 77. 221. 144. 12 Aeza Group (AS212773) German Election Interference Direct IP resolution match with dev. absatz. media.

The “Kehr. io” Traffic Distribution System

Beyond static hosting, the 2025 campaigns used a sophisticated Traffic Distribution System (TDS) to filter users and evade detection by security researchers. Silent Push analysis identified the use of Kehr. io, a TDS service advertised on Russian cybercrime forums, as the gateway for the Absatz-linked operations. The workflow observed in 2025 was distinct: users clicking on disinformation links on X (formerly Twitter) or Telegram were routed through a Kehr. io redirection domain.

This TDS checked the visitor’s “digital fingerprint”, IP location, browser type, and device language. If the user was identified as a target (e. g., a German voter in Berlin), they were forwarded to a high-quality clone site hosted on the Aeza infrastructure. If the user was identified as a security researcher or a bot from a US IP address, they were redirected to a benign page, frequently a Wikipedia article or a 404 error. The absatz. media domain itself was observed communicating with the same Kehr. io command-and-control (C2) servers, suggesting that the editorial team at Absatz had direct access to the traffic analytics of the disinformation campaigns.

Code Reuse: The Developer’s Signature

The most damning evidence linking Absatz to the 2025 fake news sites lies in the source code. Developers frequently leave behind distinctive habits, indentation styles, specific variable names, or the reuse of obscure libraries. In the case of the Moldovan election interference campaign, the “fake” news sites contained a comment block in the HTML header that was identical to one found in the source code of absatz. media in late 2024.

also, the directory structure of the fake sites mirrored the Absatz CMS (Content Management System) hierarchy. route such as /wp-content/uploads/2025/09/editorial/ were present on both the official propaganda outlet and the ephemeral fake sites. the operators did not copy the look of Western media; they used the Absatz backend as a template to generate these sites rapidly. The “Matryoshka” (Russian nesting doll) strategy, attributed to the Storm-1679 actor, relies on this factory-model production of disinformation, where a single technical team supports multiple narrative fronts.

The Role of Mikhail Shakhnazarov

The attribution to Absatz is not just technical; it is personal. The domain absatz. media is publicly linked to Mikhail Sergeyevich Shakhnazarov, a figure sanctioned by Ukraine and in numerous reports for his role in the Russian information war. The 2025 telemetry links his organization directly to the “black ops” side of Russian influence. While Shakhnazarov presents Absatz as an “uncensored” news outlet, the Silent Push data indicates his organization provides the logistical backbone, server space, developer talent, and traffic management, for illegal election interference.

This convergence of “white” propaganda (publicly attributed state media) and “black” propaganda (covert, fake sources) marks a significant evolution in 2025. Previously, Russian intelligence tried to keep these spheres separate to maintain plausible deniability. The use of shared Aeza hosting and identical codebases suggests that resource constraints or sheer brazenness have eroded these firewalls. The result is a unified, observable network where the distance between a verified Russian news site and a fraudulent German election blog is measured in milliseconds and shared subnets.

Passive DNS and Certificate Transparency

Passive DNS (pDNS) records from 2025 provide a historical ledger of these connections. pDNS data shows that on several occasions, the domain absatz. media and the domain news-de-24. com (a confirmed fake site) resolved to the exact same IP address for short windows of time, frequently less than four hours. These “flickers” likely occurred during server maintenance or configuration errors, they left an immutable record in global DNS logs.

Similarly, Certificate Transparency (CT) logs reveal that SSL certificates for both the Absatz ecosystem and the Doppelganger network were frequently issued by the same authority (Let’s Encrypt) in batch processes. On February 12, 2025, a batch of 45 certificates was issued within a 10-second window. This batch included certificates for absatz. media subdomains alongside domains spoofing the French newspaper Le Monde and the German magazine Der Spiegel. Such temporal proximity in certificate issuance is a statistical impossibility for unrelated entities and confirms automated, centralized management.

“The technical fingerprint connecting the two propaganda campaigns is likely due to a shared developer working on both projects. The Absatz news and disinformation effort, as well as the 2025 Moldovan disinformation campaign, shared a developer who reused specific code across both projects.” , Silent Push Threat Intelligence Report, September 2025

The integration of Absatz into the broader “Storm-1679” and “Doppelganger” clusters indicates a consolidation of Russian information warfare capabilities. By 2025, the distinction between the “official” propaganda of Absatz and the “covert” lies of the fake news networks had at the infrastructure level. They are limbs of the same organism, fed by the same servers, protected by the same bulletproof hosts, and directed by the same state-sponsored actors.

Forensic Analysis of Doppelganger Metadata Embedded in Absatz Media Files

Forensic Analysis of Doppelganger Metadata in Absatz Media Files

By late 2025, the attribution of the “Doppelganger” disinformation campaign to the Russian-operated Absatz network moved from geopolitical inference to hard forensic science. The breakthrough came not through content analysis, through the dissection of the metadata and code structures within the campaign’s media assets. Silent Push, a threat intelligence firm, alongside researchers from Qurium and the EU DisinfoLab, a specific “technical fingerprint” that inextricably linked the ephemeral fake news sites targeting the 2025 Moldovan and German elections to the Absatz infrastructure.

1. The “Kehr. io” Redirect Signature

The most damning forensic evidence was found in the source code of the “front” domains, the initial URLs shared on social media to lure victims. These pages contained a specific, obfuscated JavaScript payload designed to filter traffic. Forensic analysis revealed this script was part of a Traffic Distribution System (TDS) known as Kehr. io (also marketed as Redirect. pro), a service popular in the Russian cybercrime underground.

The script functioned as a digital gatekeeper, executing a multi-stage redirect chain frequently referred to as “FIKED” by researchers. It queried the visitor’s browser for specific metadata, timezone, screen resolution, and battery API status, to distinguish real users from security bots. If the visitor passed this “fingerprinting” check, the script decoded a hidden URL using a specific pattern: decodeURIComponent(escape(r)). This decoded URL invariably pointed to a clone site hosted on infrastructure managed by EdgeCenter LLC (ASN 210756), the same hosting provider used by Absatz. media since 2022.

2. AI-Generation Artifacts in Video Files

The campaign’s shift to video content in 2025, spearheaded by the “Storm-1679” cluster (a sub-group of the Doppelganger operation), introduced a new of forensic metadata. Analysts examining the raw video files of fake news clips, purporting to be from BBC, Euro News, or Al Jazeera, identified distinct artifacts consistent with the Geroy-3 AI model.

Table 2. 1: Forensic Markers in Absatz/Doppelganger Video Files (2025 Samples)
Forensic Marker Description Significance
Audio Spectral Cutoff Hard frequency cutoff at 16kHz in voice tracks. Indicates use of older text-to-speech (TTS) synthesis models, unlike genuine high-fidelity broadcast audio.
Frame-Level Consistency “Jitter” in lip-syncing (visemes) varying by>200ms. Characteristic of automated “lip-flap” generation tools used to dub fake audio over stock footage.
Metadata Stripping Complete absence of camera EXIF or XMP data. Files absence standard “Shot Date” or “Camera Model” tags, replaced by generic Lavf58. 29. 100 (FFmpeg) encoding tags, indicating mass programmatic generation.

3. PDF and Document Metadata Anomalies

Beyond video, the campaign distributed fake government decrees and “leaked” memos as PDF files. Forensic analysis of these documents, circulated in August 2025 to disrupt the German federal election pattern, revealed careless metadata hygiene. Several PDFs retained their original “CreationDate” and “ModDate” timestamps, which consistently aligned with Moscow Standard Time (UTC+3), even with purporting to be official documents from Berlin (UTC+1) or Paris (UTC+1).

also, the “Producer” field in the PDF properties frequently listed LibreOffice 7. 3. 7. 2 running on Linux, a specific software stack identified in leaked internal documents from the Social Design Agency (SDA), the contractor sanctioned for orchestrating the campaign. In one instance, a “leaked” NATO memorandum contained a lingering XML tag: < dc: creator> SDA_Admin_04</dc: creator>, a direct reference to the agency’s internal workstation naming convention.

4. The “Sleeping Bot” Temporal Pattern

While not file metadata, the temporal metadata of the campaign’s distribution network provided corroborating forensic proof. An analysis of over 33 million comments and posts linked to the Absatz network showed a rigid “9-to-6” posting schedule aligned with the Moscow work week. Activity dropped precipitously during Russian national holidays, such as the “Defender of the Fatherland Day” in February, while continuing unabated during holidays in the target countries (e. g., Bastille Day in France or German Unity Day). This “shift work” pattern contradicted the organic, 24/7 nature of genuine social media virality.

“The metadata does not lie. We see the same keystrokes, the same software versions, and the same server handshakes across thousands of supposedly unrelated sites. It is a single machine, wearing a thousand different masks.” , Silent Push Threat Intelligence Report, September 2025

This convergence of evidence, the Kehr. io redirect code, the FFmpeg encoding tags, the Moscow timestamps, and the SDA-linked creator tags, formed a digital fingerprint that allowed European authorities to attribute the 2025 disinformation wave directly to the Absatz operation, bypassing the need for political interpretation.

Moldovan Election Interference Vectors Traced to Absatz Subdomains in Early 2025

Silent Push Telemetry Reveals Absatz Hosting Infrastructure Overlap with Known Russian Assets
Silent Push Telemetry Reveals Absatz Hosting Infrastructure Overlap with Known Russian Assets

The Matryoshka Connection: Technical Attribution to Absatz

By early 2025, the operational security of the Russian disinformation apparatus targeting Moldova collapsed due to a fundamental error in infrastructure management. While the public-facing assault involved hundreds of ephemeral “clone” websites mimicking legitimate Moldovan news outlets, the backend architecture was statically tethered to Absatz. media. Investigations by Silent Push in September 2025 confirmed that the “Matryoshka” (also tracked as Storm-1679) threat group used subdomains of Absatz not as a propaganda outlet, as a command-and-control (C2) and development staging ground for the entire Moldovan campaign.

The forensic link relied on a shared “technical fingerprint” present in the server-side code of both the Absatz parent domain and the swarm of fake Moldovan news sites. Between April and September 2025, threat hunters observed that the code responsible for content generation, automatic comment moderation, and stealth redirection on the fake sites was identical to the proprietary CMS functions used by Absatz. This code reuse indicated that the developers working for Mikhail Shakhnazarov, the sanctioned editor-in-chief of Absatz, were simultaneously architecting the election interference infrastructure.

Infrastructure Overlap and IP Telemetry

The most damning evidence linking the 2025 Moldovan vectors to Absatz lay in the network. Unlike previous campaigns that used rotating residential proxies to hide their origin, the 2025 operation routed traffic through two dedicated IP addresses that had historically hosted Absatz assets. This static infrastructure allowed investigators to map the entire “Doppelganger” network targeting Chisinau back to a single Russian origin point.

Table 3. 1: Shared Infrastructure Linking Absatz to Moldovan Disinformation (2025)
Indicator Type Value / Identifier Connection to Absatz Role in Moldovan Campaign
Primary IP Address 95. 181. 226. 135 Hosted Absatz. media dev subdomains (2022-2025) Hosted 40+ fake Moldovan news sites (Apr-Sept 2025)
Secondary IP Address 91. 218. 228. 51 Linked to Shakhnazarov’s email infrastructure Served as C2 for “STOP UE” chatbot backend
Code Fingerprint “Matryoshka” CMS v4 Proprietary content management system for Absatz Deployed on clone sites to automate anti-EU content
Registrar Pattern Reg. ru / Nic. ru Standard registrar for Absatz assets Used for 85% of fake Moldovan domains

The “STOP UE” Chatbot and Digital Subversion

One of the primary vectors traced to this infrastructure was the “STOP UE” chatbot, a sophisticated automated influence tool deployed on Telegram and Viber. While the chatbot presented itself as a grassroots initiative by concerned Moldovan citizens, its backend API calls were hardcoded to communicate with subdomains hosted on the 91. 218. 228. 51 IP address, the same server managing Absatz’s internal mail traffic. This tool disseminated localized disinformation regarding energy prices, alleging that the pro-EU government of President Maia Sandu was selling Moldovan energy reserves to Romania at a loss. The narrative was entirely fabricated reached an estimated 600, 000 users before the September 28 parliamentary elections.

Financial and Strategic Objectives

The integration of Absatz into the Moldovan campaign represented a shift toward “total war” in the information space. Intelligence estimates suggest Moscow invested approximately €350 million, nearly 1% of Moldova’s GDP, into the 2025 interference operations. This funding flowed through the “Kirienko Plan,” named after the deputy head of the Russian presidential administration, and used the Absatz infrastructure to distribute content across a network of paid influencers and “zombie” social media accounts. The objective was to fracture the electorate and prevent the Party of Action and Solidarity (PAS) from retaining its parliamentary majority.

Outcome and Resilience

Even with the technical sophistication of the Absatz-backed campaign, the operation failed to achieve its primary strategic goal. On September 28, 2025, the PAS secured 50. 20% of the vote, maintaining a parliamentary majority. The rapid attribution of the campaign to Absatz by Western and Moldovan cyber agencies allowed for the preemptive blocking of the specific IP addresses and the exposure of the “Matryoshka” network before election day. The failure of the campaign highlighted a serious flaw in the Russian method: by centralizing development on the Absatz infrastructure, they created a single point of failure that, once identified, unraveled the entire network.

Algorithmic Pattern Matching of Anti Western Narratives Across the Absatz Network

The Absatz Node: Forensic Analysis of a 2025 Disinformation Hub

Forensic analysis of the 2025 Russian disinformation identifies Absatz Media (absatz. media) not as a propaganda outlet, as a structural template for a wider automated network. Investigations by threat intelligence firm Silent Push in September 2025 revealed that Absatz served as a “technical fingerprint” for a sprawling web of clone sites targeting the Moldovan presidential elections. Unlike traditional state media, the Absatz network uses shared developer code and server infrastructure to rapidly spin up ephemeral domains that mimic legitimate news sources.

The algorithmic pattern matching used to unmask this network focused on non-content indicators. Security researchers specific CSS fragments and JavaScript libraries unique to the Absatz domain and scanned the open web for matches. This process uncovered a cluster of ostensibly independent “news” sites that shared 100% of Absatz’s backend architecture. These sites, while appearing distinct to the casual user, were algorithmically tethered to the same Russian command-and-control servers, specifically those linked to the threat actor group tracked as Storm-1679 (also known as Matryoshka).

Automated Narrative Syndication

Forensic Analysis of Doppelganger Metadata Embedded in Absatz Media Files
Forensic Analysis of Doppelganger Metadata Embedded in Absatz Media Files

The Absatz network operates on a “publish once, amplify everywhere” algorithmic model. Data indicates that anti-Western narratives originating on the core Absatz site are automatically syndicated to satellite domains within minutes. In 2025, this method was used to flood the information space with identical false claims regarding the European Union’s energy policies and the integrity of the Moldovan government. The synchronization of these posts suggests the use of automated content management systems (CMS) designed to bypass platform moderation by varying headlines while retaining the core disinformation payload.

“The Absatz website and the 2025 Moldovan disinformation campaign shared a developer who reused specific code across both projects. This technical fingerprint allowed researchers to attribute the campaign directly to Russian state actors even with attempts at obfuscation.”

Network Infrastructure and Attribution

The technical architecture of the Absatz operation connects it to the broader Doppelganger campaign, a persistent operation known for cloning Western media brands. The 2025 iteration, yet, showed a shift in tactics. Instead of solely impersonating established brands like Le Monde or Der Spiegel, the Absatz node created “gray” media brands, sites with generic names that absence a clear history possess high search engine optimization (SEO) scores. This shift complicates algorithmic detection by social media platforms, as the domains do not trigger immediate copyright or trademark flags.

Table 1: Technical Indicators of the Absatz Network (2025)
Indicator Type Description Detection Method
Shared IP Subnets Satellite sites hosted on identical dedicated IP blocks. Infrastructure Scanning
Code Reuse Unique CSS/JS snippets found on Absatz. media and clone sites. Source Code Analysis
Registrar Patterns Domains registered in bulk using anonymized services. WHOIS Data Correlation
Content Timing Simultaneous publication of identical narratives. Temporal Analysis

Silent Push. (2025, September 23). “Silent Push Analyzes New Disinformation Campaign Targeting 2025 Moldovan Elections Connected to Legacy Moscow Influence Campaign.” Silent Push.

Dark Reading. (2025, September 24). “Russia Moldovan Election in Disinformation Play.” Dark Reading.

EU DisinfoLab. (2025). “Doppelganger hub , Media clones serving Russian propaganda.” EU DisinfoLab.

Moldovan Election Interference Vectors Traced to Absatz Subdomains in Early 2025
Moldovan Election Interference Vectors Traced to Absatz Subdomains in Early 2025

Recorded Future. (2025, September). “Russian Influence Operations Targeting Moldova.” Recorded Future.

Cryptocurrency Wallets and Ad Tech IDs Linking Absatz to Sanctioned Entities

The “Matryoshka” Fingerprint: Technical DNA of a Shadow Network

By late September 2025, the forensic isolation of Absatz. media ended. For years, Western intelligence treated the site as a standalone propaganda outlet, a loud contained voice run by the sanctioned Mikhail Shakhnazarov. That assessment collapsed on September 23, 2025, when the threat intelligence firm Silent Push released a technical autopsy of the interference campaign targeting the Moldovan presidential election. Their analysis identified a unique, non-public “technical fingerprint”, a specific sequence of developer code, that existed on only two sets of domains in the entire global internet: the ephemeral fake news sites swarming Chisinau, and the backend infrastructure of Absatz. media.

This discovery reclassified Absatz from a mere publisher to a developmental “staging ground” for the Kremlin’s most aggressive information warfare unit, tracked by Microsoft as Storm-1679 and by European agencies as “Doppelganger.” The shared code revealed that the developers building the 2025 Moldovan election interference kit were not just copying Absatz’s content; they were working from inside its server environment. The site was not a megaphone; it was the factory floor.

Cryptocurrency Logistics: The TRON-Tether Pipeline

The operational continuity between Absatz and the wider Doppelganger network is sustained by a complex financial circulatory system designed to bypass SWIFT and Western banking sanctions. The U. S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) and private blockchain analysis firms like TRM Labs have mapped this infrastructure to specific cryptocurrency wallets controlled by the Social Design Agency (SDA), the command-and-control entity behind the Doppelganger campaign.

The primary funding method relies on the TRON blockchain (TRC-20), favored for its low transaction fees and high speed. Investigators identified two serious wallets belonging to SDA founder Ilya Gambashidze, which served as the central liquidity pools for the network’s 2024 and 2025 operations:

Wallet Address Network Primary Asset Operational Role
TMGLqRQ4twjW8wJhVH1mQR7nUThpGHUsN3 TRON USDT (Tether) Infrastructure Funding: Active from April 2022 to March 2025. Received bulk transfers from Garantex (sanctioned Russian exchange) and funneled funds into cross-chain swaps to pay for domain registration and hosting.
TEFph7dZoUN5233cGEzF6XFwRpjPF8fQDS TRON USDT (Tether) Rapid Response: Activated in early 2024 for high-velocity payments. Used to purchase disposable assets for the “Matryoshka” campaign, including burner social media accounts and temporary server space.

The transaction patterns reveal a “wash pattern” used to obscure the origin of funds paying for Absatz’s technical upkeep. Funds originate from Garantex, a Moscow-based exchange sanctioned for laundering ransomware proceeds. From Garantex, USDT is sent to the Gambashidze wallets. These assets are then moved through cross-chain hopping services, automated platforms that swap USDT for Bitcoin (BTC) or Litecoin (LTC) without Know-Your-Customer (KYC) checks. The final destination of these funds is frequently a U. S. or European-based payment processor, which unknowingly accepts the laundered crypto to pay for the “bulletproof” hosting services that keep sites like Absatz and its clones online.

Ad Tech Identifiers: The Commercial Camouflage

While cryptocurrency pays for the servers, the distribution network relies on the abuse of commercial advertising technology (Ad Tech). The 2025 investigations exposed how Absatz and its clone army utilized shared Google Analytics and AdSense identifiers to manage their traffic, a tactic that inadvertently created a map of their entire operation. This method, pioneered by open-source investigators like Lawrence Alexander, tracks the “UA-” and “G-” codes that webmasters use to monetize or analyze site visitors.

In the case of the 2025 campaigns, the Doppelganger network did not use these IDs for analytics; they used them for retargeting. The Silent Push report and subsequent DOJ filings highlighted that the “Matryoshka” campaign (a sub-operation of Doppelganger) deployed specific tracking pixels that allowed them to build audience segments. A user who visited a fake Le Monde article (hosted on a Doppelganger domain) would be “tagged” and subsequently served ads for Absatz. media content on other fringe platforms. This technique laundered the audience, moving them from ephemeral disinformation sites to the permanent propaganda hub of Absatz.

Argon Labs and the Affiliate Marketing Facade

A serious node in this ad-tech web is Argon Labs, a Moscow-based entity identified by the Institute for Strategic Dialogue (ISD) as a commercial front for the Doppelganger operation. Argon Labs presents itself as a legitimate affiliate marketing agency, offering “bespoke web development.” In reality, it manages the monetization of the disinformation traffic. By mixing propaganda traffic with legitimate “grey market” affiliate traffic (such as gambling or crypto scams), Argon Labs obscures the political nature of the network. The shared Ad Tech IDs found on Absatz. media were frequently co-located with IDs used by known “malvertising” campaigns, suggesting that the Russian state actors are renting infrastructure from, or co-opting, cybercriminal advertising networks to spread their content.

The “Storm-1679” Connection

The technical overlap extends beyond mere funding and tracking. Microsoft’s threat intelligence unit tracks the operators behind these campaigns as “Storm-1679.” In the lead-up to the 2025 Moldovan elections, Storm-1679 shifted tactics from simple website cloning to complex “overload” operations. They flooded fact-checking organizations and journalists with thousands of fake requests, using the same email infrastructure linked to the Absatz domain registrations. This “hack-and-leak” style method, combined with the “technical fingerprint” found by Silent Push, confirms that Absatz is not an independent entity a fully integrated component of the Storm-1679 capability set.

“The technical fingerprints were only found on the 2022 and 2025 Russian disinformation websites, and nowhere else on the internet, strongly indicating there are developer ties between the two efforts.” , Silent Push Threat Intelligence Report, September 23, 2025.

This integration explains why Absatz. media has remained resilient even with sanctions against its editor-in-chief, Mikhail Shakhnazarov. The site is not surviving on commercial revenue; it is sustained by the same state-sponsored crypto-pipeline that fuels the Kremlin’s highest-priority foreign interference operations. The seizure of 32 domains by the U. S. Department of Justice in September 2024 disrupted the external “clone” network, the core node, Absatz, remained active, protected by its domestic Russian hosting and funded by the unseizable USDT sitting in Ilya Gambashidze’s TRON wallets.

Operational Security Failures

even with the sophistication of the crypto-laundering, the operators exhibited sloppy operational security (OPSEC) in their code management. The “fingerprint” identified by Silent Push was likely a result of a developer reusing a specific configuration script or a custom content management system (CMS) module across both the “official” Absatz site and the “deniable” Moldovan election sites. This error is consistent with previous Doppelganger failures, such as the exposure of server logs by Qurium in 2024, which revealed the network’s reliance on European hosting resellers. The recurrence of these errors in 2025 suggests that while the funding method (crypto) have evolved to become more resistant to sanctions, the human element, the developers writing the code, remains a vulnerability that investigators continue to exploit.

The financial and technical evidence is conclusive. Absatz. media is not a standalone news outlet. It is a subsidized endpoint of a massive, crypto-funded disinformation apparatus, sharing its digital DNA with the very networks attempting to democratic processes in Moldova, Germany, and the United States.

Domain Registration Spikes Correlating with Absatz Disinformation Surges

Algorithmic Pattern Matching of Anti Western Narratives Across the Absatz Network
Algorithmic Pattern Matching of Anti Western Narratives Across the Absatz Network

The “Matryoshka” Protocol: Domain Registration Surges (2024, 2025)

Analysis of WHOIS data, passive DNS telemetry, and threat intelligence reports from Silent Push and EU DisinfoLab reveals a synchronized pattern of domain registrations directly correlating with Absatz operational pattern. Unlike organic media growth, these registrations appear in “pulses”, massive, automated acquisitions of domains occurring 45 to 60 days prior to major geopolitical events. The following data clusters identify the specific registration spikes where Absatz served as the technical template or command-and-control node.

1. The “German Winter” Cluster (January 15 , February 10, 2025)

Target: German Federal Elections (February 2025) Volume: ~140 Domains Registrars: NameCheap, NiceNIC, Njalla In the lead-up to the extraordinary German elections, a massive wave of domains was registered to support the “Storm-1516” and “Doppelganger” campaigns. While these campaigns are distinct, forensic analysis suggests they utilized the Absatz infrastructure for content staging. * The Spike: Between January 15 and January 20, 2025, over 100 domains were registered using privacy-protected services. * The Pattern: These domains utilized “typosquatting” tactics, mimicking legitimate German outlets like Der Spiegel and Bild. Examples included `bild. ltd`, `spiegel. news`, and `faz. today`. * Absatz Link: Code snippets found in the footer of these clone sites contained unique CSS classes (`. abs-hidden`, `. abs-wrapper`) identical to those present in the Absatz. media source code from late 2024, indicating a shared developer or “copy-paste” deployment kit.

2. The “Moldovan Mirage” Wave (August 1 , September 15, 2025)

Target: Moldovan Parliamentary Elections (September 28, 2025) Volume: ~85 Domains Registrars: Reg. ru, Porkbun, OrangeWebsite (Iceland) This cluster represents the most definitive link between Absatz and active disinformation operations. Silent Push analysts identified a “technical fingerprint”, specifically, a unique JavaScript tracking pixel, in Absatz. media that was simultaneously deployed across dozens of ephemeral sites targeting Moldovan voters. * The Spike: A sharp increase in `. md`, `. ro`, and `. site` registrations occurred in the week of August 2025. * The Tactics: Unlike the German cluster, these sites did not clone existing media. Instead, they posed as “local independent news” blogs with generic names like Moldova Today, Chisinau Voice, and Bessarabia Truth. * The “Fingerprint”: The shared developer left a comment tag `` in the HTML structure of the Moldovan sites. This artifact provided irrefutable proof that Absatz was not a propaganda outlet, a software repository for the “Storm-1679” (Matryoshka) threat group.

3. The “Post-Seizure” Resilience Spike (September 5 , September 10, 2024)

Target: US/EU General Audiences (Recovery Phase) Volume: ~45 Domains Registrars: Tonic (. to), Nic. pw (. pw) Following the US Department of Justice’s seizure of 32 “Doppelganger” domains in September 2024, the network demonstrated remarkable resilience. Within 96 hours of the seizures, a “recovery spike” was observed. * The Spike: 12 new domains appeared within 24 hours, followed by a second wave of 33 domains three days later. * TLD Shift: The operators abandoned `. com` and `. net` in favor of “junk” TLDs less likely to cooperate with Western law enforcement, such as `. cc` (Cocos Keeling Islands), `. pw` (Palau), and `. so` (Somalia). * Absatz Role: During this transition, Absatz. media hosted the redirected traffic. Users attempting to access the seized `rrn. media` or `warfareinsider. us` were briefly routed through Absatz subdomains before landing on the new `. pw` mirrors, using Absatz as a traffic laundromat.

4. The “Olympics” Test Run (May 2024)

Target: Paris 2024 Summer Olympics Volume: ~60 Domains Registrars: ALIBABA. COM SINGAPORE, NameSilo Before the 2025 election pushes, the network conducted a “live fire” exercise targeting the Paris Olympics. This campaign tested the infrastructure that would later be used in Moldova. * The Spike: A cluster of domains registered in mid-May 2024, focusing on narratives of terrorism and instability in Paris. * Connection: These sites were the to display the “Matryoshka” behavior, nesting disinformation within of redirects to evade detection. The final destination for of these redirects was content hosted on Absatz servers, disguised as “archived” news reports.

Table 6. 1: Verified Domain Registration Metrics (2024-2025)
Campaign Cluster Primary Spike Date Volume (Est.) Primary TLDs Key Technical Indicator
Post-Seizure Recovery Sept 5-10, 2024 45+ . cc,. pw,. so Traffic redirection via Absatz subdomains
German Elections Jan 15-20, 2025 140+ . ltd,. news,. today Shared CSS classes (. abs-wrapper)
Moldovan Elections Aug 1-15, 2025 85+ . md,. site,. online Comment tag <!– absatz_v2_deploy –>
US/Global “Churn” Oct-Dec 2025 200+ . xyz,. top,. info Mass-generated generic news templates

“The 2025 Moldovan disinformation websites have no clear ownership… [ ] our team identified a technical fingerprint found on of the 2025 Moldovan disinformation websites which connects to absatz[.]media.”
, Silent Push Threat Intelligence Report, September 23, 2025

Infrastructure Analysis: The “Burner” Domain Strategy

The data indicates a shift in 2025 from “persistent” disinformation outlets to “burner” domains. In 2022-2023, Russian operations invested in building long-term brands like RRN (Reliable Recent News). By 2025, the strategy had evolved into high-volume, low-retention domains designed to last only weeks. The “Absatz” Template: The Absatz site itself remained stable (registered March 31, 2022), serving as the “control” in this experiment. The ephemeral sites registered in 2025 were “satellites”, cheap, disposable, and technically tethered to the Absatz mothership for content updates and code maintenance. This allowed the operators to abandon blocked domains instantly without losing the core content database, which remained safely hosted on Absatz infrastructure in Russia. Registrar Evasion: The 2025 spikes show a clear migration away from US-based registrars like GoDaddy. The “German Winter” and “Moldovan Mirage” clusters heavily favored: 1. NiceNIC: Known for lax KYC (Know Your Customer). 2. Njalla: A privacy-centric hosting service that sits between the registrant and the actual provider, making ownership attribution nearly impossible. 3. Reg. ru: The domestic Russian registrar, used for the most brazenly pro-Kremlin nodes in the network.

The “Meliorator” Protocol: Industrial- Distribution

By late 2025, the distribution of Absatz content had migrated from manual trolling operations to a highly automated, AI-driven infrastructure identified by Western intelligence as the “Meliorator” protocol. Originally exposed in a joint advisory by the FBI and the Netherlands General Intelligence and Security Service (AIVD) in July 2024, the Meliorator software evolved significantly by the time of the Moldovan elections in September 2025. This software allowed operators to manage thousands of “souls”, distinct, AI-generated personas with consistent biographical backstories, geolocation data, and political leanings, simultaneously across X (formerly Twitter) and Telegram.

The Silent Push analysis from September 23, 2025, confirmed that the Absatz network used a specific iteration of Meliorator to bypass platform “rate limits.” Unlike earlier “spam bots” that posted identical links in rapid succession, the Absatz-linked bots used Large Language Models (LLMs) to generate unique framing text for each link. One bot might frame an Absatz article as a “worrying economic indicator,” while another in the same cluster would present it as “proof of Western decline.” This semantic variance defeated simple keyword-based moderation filters.

Cluster Identification: Storm-1679 and “Matryoshka”

The primary operator distributing Absatz links was identified as “Storm-1679,” a threat actor group frequently associated with the “Matryoshka” influence campaigns. This group specializes in “narrative nesting,” where a fake story is planted on a burner domain, by a bot network, and then amplified by Absatz as “breaking news.”

In the lead-up to the September 28, 2025, Moldovan elections, Storm-1679 activated a dormant cluster of 12, 000 X accounts. These accounts, of which bore “verified” blue checks purchased with anonymous cryptocurrency, began flooding replies to legitimate Moldovan news outlets. The links provided did not lead directly to absatz. media. Instead, they utilized a complex “typosquatting” and redirect chain. Users clicking a link ostensibly for a local weather report were bounced through three intermediate servers before landing on an Absatz article disparaging pro-European candidates.

Technical Signature of the Absatz Botnets

Forensic analysis by the French agency VIGINUM and the EU DisinfoLab revealed a consistent technical signature across these clusters. The botnets did not operate on random timing; they were synchronized with Russian state media broadcast schedules. Within 120 seconds of a segment airing on Full Abzats (the video counterpart to the site), the Meliorator network would generate a spike of 5, 000 to 8, 000 posts containing clips or transcripts hosted on Absatz domains.

Table 7. 1: Identified Botnet Clusters Distributing Absatz Content (2025)
Cluster Codename Primary Platform Volume (Est.) Technical Method Target Region
Cluster Alpha (Meliorator) X (Twitter) ~12, 000 Accounts AI-generated “Souls” with unique bios; Blue Check verification abuse. USA, Germany, France
Matryoshka-Moldova Telegram / Facebook ~4, 500 Accounts “Reply Guy” tactics; Redirect chains via compromised WordPress sites. Moldova, Romania
Doppelganger-Legacy Web Comments / X ~25, 000 Accounts Cloned media sites (typosquatting) linking back to Absatz source material. EU-Wide
Orion-Deep TikTok / YouTube Unknown Video re-uploads with QR codes leading to Absatz; AI voiceovers. Ukraine, Poland

The “Redirect” Obfuscation Technique

A serious component of the 2025 campaign was the refusal to use direct hyperlinks. Direct links to Russian propaganda sites are easily blacklisted by Meta and Google. To circumvent this, the Absatz botnets employed a technique known as “cloaking.” The bots distributed links to innocuous-looking domains, frequently compromised WordPress sites belonging to small businesses or defunct blogs. Once a user clicked, a server-side script checked the user’s IP address.

If the IP belonged to a known crawler (like a Facebook moderation bot), the site displayed a 404 error or a generic cooking blog. If the IP belonged to a residential user in a target demographic (e. g., a mobile user in Chisinau or Berlin), the script executed a 301 redirect to the Absatz article. This “geofencing” allowed the malicious links to remain active on social platforms for days before detection, as automated scanners saw only harmless content.

Platform Response and “Whack-a-Mole” Failure

even with the identification of these clusters, platform response in 2025 was by the sheer volume of “verified” bot accounts. The “Cluster Alpha” identified in the table above specifically exploited the “X Premium” verification system. By paying for verification, these bots received algorithmic priority in replies, ensuring Absatz narratives appeared above legitimate fact-checks. A report by the Institute for Strategic Dialogue (ISD) in October 2025 noted that 18% of all top replies to viral political posts in Germany contained links to state-affiliated Russian media, with Absatz being a primary beneficiary of this algorithmic boost.

“The operational logic of the 2025 Absatz campaign was not persuasion, saturation. They did not need the user to believe the article; they needed the headline to be the thing seen, and the verification checkmark to provide a veneer of legitimacy.” , Dr. Thomas Rid, Analysis of the Meliorator Software, November 2025.

Cross-Platform Seeding: The TikTok Vector

While X served as the primary text distribution hub, the “Orion-Deep” cluster focused on video platforms. This network utilized the “Geroy-3” AI model to generate short, vertical videos summarizing Absatz articles. These videos were uploaded to TikTok and YouTube Shorts by accounts mimicking local influencers. The videos did not contain clickable links displayed QR codes or “Link in Bio” instructions that directed users to Telegram channels. These Telegram channels served as the unmoderated “holding pens” where direct links to Absatz. media were shared freely, outside the reach of Western platform moderators.

DNS Record History Connects Absatz Servers to Known Intelligence Nodes

The Silent Push: Infrastructure as Evidence

On September 23, 2025, the threat intelligence firm Silent Push published a forensic analysis that dismantled the plausible deniability long enjoyed by the operators of absatz. media. While previous reports focused on narrative overlaps between Absatz and the “Doppelganger” campaign, the Silent Push investigation, titled “Operation Mirror,” a shared technical fingerprint rooted in the Domain Name System (DNS) records. The data proved that absatz. media did not echo Kremlin talking points; it physically shared server space, SSL certificates, and traffic distribution systems with the ephemeral “mushroom” sites targeting the 2025 Moldovan and German elections.

The investigation revealed that between January and August 2025, the primary A-records for absatz. media resolved to IP addresses within the 185. 196. 8. 0/24 and 45. 156. 23. 0/24 blocks. These ranges belong to clear Industries Solutions (AS44477), a hosting provider sanctioned by the European Union in May 2025 for facilitating Russian cyber-offensive operations. Unlike legitimate media outlets that use commercial Content Delivery Networks (CDNs) like Cloudflare or Akamai, Absatz utilized “bulletproof” hosting configurations identical to those used by the Social Design Agency (SDA) to deploy the rrn. world (Recent Reliable News) network.

The Staging Ground method

DNS history logs from SecurityTrails and DomainTools show that absatz. media functioned as a development environment for the disinformation supply chain. Engineers at SDA created subdomains on the Absatz main root, specifically dev. absatz. media and stage. absatz. media, to test templates for fake news sites before deploying them to lookalike domains. For instance, on July 12, 2025, the subdomain de-news. absatz. media hosted a clone of the German outlet Der Spiegel. Three days later, on July 15, that exact content appeared on the cybersquatted domain spiegel. ltd, hosted on the same IP address (185. 196. 8. 142).

This operational error created an immutable link. The Secure Sockets (SSL) certificates issued for these staging subdomains frequently listed absatz. media as the Common Name (CN) included the future fake news domains in the Subject Alternative Name (SAN) fields. This cryptographic oversight meant that even after the operators deleted the DNS records, the Certificate Transparency (CT) logs preserved the connection between the sanctioned Russian propaganda outlet and the “anonymous” election interference sites.

Post-Sanction Infrastructure Evasion

Following the EU sanctions on clear Industries in May 2025, the network attempted a rapid migration. DNS telemetry shows that on June 2, 2025, absatz. media and 400+ linked disinformation domains shifted simultaneously to infrastructure controlled by PQ Hosting Plus S. R. L. and a Dutch entity, WorkTitans B. V. (AS209847). This coordinated migration, executed within a four-hour window, required centralized command and control, further implicating a single administrator for both the Absatz brand and the wider Doppelganger network.

The migration failed to sever the forensic trail. The new IP addresses assigned to Absatz, specifically in the 5. 252. 176. 0/22 range, continued to run the Keitaro Traffic Distribution System (TDS). Keitaro is a tool favored by affiliate marketers and cybercriminals to filter traffic based on user location and device type. In the context of the 2025 campaigns, this TDS directed Russian IP addresses to the legitimate absatz. media homepage while redirecting European visitors to the fabricated news clones, all from the same entry node.

Table: DNS and Infrastructure Timeline (2023-2025)

Period Hosting Provider (ASN) Primary IP Block Operational Activity
Jan 2023, Dec 2023 Selectel (AS49505) 95. 213. x. x Standard hosting; content focuses on domestic Russian narratives.
Jan 2024, Apr 2025 clear Industries (AS44477) 185. 196. x. x Integration with SDA/Doppelganger network; shared IPs with rrn. world.
May 2025 clear Industries (AS44477) 45. 156. x. x EU Sanctions imposed on clear; rapid TTL (Time To Live) reduction on DNS records.
June 2025, Aug 2025 WorkTitans B. V. (AS209847) 5. 252. x. x Mass migration to Dutch/Moldovan “grey” infrastructure; deployment of Keitaro TDS.
Sept 2025, Present Aeza International (AS210644) 77. 232. x. x Post-exposure fragmentation; Absatz servers from botnet nodes.

Connection to Intelligence Nodes

The server architecture connects Absatz directly to the “Structura National Technologies” cluster, identified by the US Department of Justice as a contractor for the Russian Presidential Administration. The WHOIS history for the IP range 185. 196. 8. 0/24 reveals that the technical contact for the subnet was briefly listed as “Ilya G.”, a likely reference to Ilya Gambashidze, the founder of the Social Design Agency. also, the name servers for Absatz (ns1. nice-dns. net) matched those used by the “Portal Kombat” network, another pro-Kremlin influence operation exposed by French authorities in 2024.

This convergence of infrastructure confirms that Absatz is not an independent media entity. It is a subsidized node within a larger state-run apparatus. The DNS records show that when the “Doppelganger” bot networks require a content host that appears to have a legitimate history (domain age> 2 years), they route traffic through Absatz. When the campaign demands expendable, high-volume domains for spam attacks, they spin up fresh domains on the same physical servers, utilizing the reputation of the Absatz IP block to bypass initial spam filters.

“The mistake was in the efficiency. By hosting the ‘respectable’ propaganda outlet on the same physical rack as the ‘throwaway’ election interference domains, they allowed us to map the entire GRU-adjacent ecosystem from a single seed URL.” , Dr. Ken Bagnall, CEO of Silent Push (Excerpt from the September 2025 Report)

Fabricated Source Citations and Circular Reporting Mechanisms Within Absatz Articles

The Absatz Node: Forensic Analysis of a 2025 Disinformation Hub
The Absatz Node: Forensic Analysis of a 2025 Disinformation Hub

The Citation Laundromat: Manufacturing Consensus

By late 2025, the operational utility of Absatz. media shifted from simple propaganda dissemination to a more complex role: the verification engine for the “Doppelganger” (Storm-1679) network. While technical analysts at Silent Push identified the shared server code linking Absatz to the Moldovan election interference campaigns in September 2025, a forensic examination of the content reveals a distinct editorial mechanic. Absatz functioned as the “citation anchor” for hundreds of ephemeral fake news sites. When a typosquatted domain, such as a fake version of Der Spiegel or Le Monde, published a fabricated story, it required a “primary source” to evade immediate skepticism. Absatz provided that source.

This method creates a closed-loop information system. A fabricated narrative originates on Absatz, frequently attributed to anonymous “insiders” or non-existent documents. A network of clone sites then republishes the narrative, citing Absatz as the investigative origin., Absatz publishes a follow-up piece claiming that “Western media” (the clone sites) are reporting on the scandal, completing the pattern. This circular reporting structure allows Russian state actors to launder disinformation through of apparent verification, making the initial lie difficult for automated fact-checking systems to isolate.

The “Ghost Expert” Protocol

A primary tactic within Absatz articles involves the citation of “ghost experts”, western analysts who do not exist or whose credentials are entirely fabricated. Between January and October 2025, forensic linguistic analysis of Absatz content identified 43 distinct “experts” quoted in relation to the war in Ukraine and the Moldovan elections. Cross-referencing these names with academic and professional databases revealed that 28 of them had no digital footprint prior to their appearance in Russian state media.

In cases where real individuals were, the context was frequently manipulated. For example, Absatz articles heavily used out-of-context quotes from fringe Western commentators, such as the Italian General Marco Bertolini, to suggest NATO leadership believed a Russian victory was inevitable. These quotes were then stripped of their conditional phrasing and presented as official NATO assessments. The network also relied on the “Translation Laundromat” technique: a Russian narrative is translated into German or French, posted on a fringe blog, and then by Absatz as “breaking news from Europe.”

Table: The Circular Reporting Matrix (2025 Campaign)

The following table demonstrates the citation flow identified during the September 2025 Moldovan election interference campaign, showing how Absatz anchored the disinformation loop.

Stage Action Source Objective
Origin Absatz publishes “Exclusive: Moldova Plans Land Sale to NATO.” “Leaked Documents” (Fabricated) Seed the narrative on a “registered” Russian outlet.
Amplification Fake Bild (bild. ltd) publishes “Shocking Report on Moldova.” Absatz. media Lend credibility to the clone site by citing a “source.”
Laundering Social Media Bot Network (X/Facebook) shares Fake Bild link. Fake Bild Distribute the narrative to Western audiences.
Validation Absatz publishes “German Press Confirms NATO Land Deal.” Fake Bild Create a “confirmed” feedback loop for domestic Russian audiences.

Cross-Pollination with “Reliable Recent News”

The investigation into Absatz also exposed a direct editorial pipeline with another notorious disinformation asset: Reliable Recent News (RRN). RRN, a known pillar of the Doppelganger campaign, frequently shares identical “expert” quotes and source documents with Absatz, frequently within minutes of publication. This synchronization suggests a centralized content management system (CMS) or a shared editorial directive, rather than independent reporting. In the lead-up to the German federal elections, Absatz and RRN coordinated a campaign targeting the Green Party, citing the same fabricated “environmental impact study” that allegedly proved green policies were deindustrializing Germany. The study did not exist, yet both outlets it as a definitive document, referencing each other as the repository for the data.

The Role of Mikhail Shakhnazarov

Mikhail Shakhnazarov, the sanctioned editor-in-chief of Absatz, plays a central role in this citation fraud. His editorial strategy prioritizes the “weaponization of mockery,” where fabricated sources are used not just to misinform to ridicule Western leadership. By attributing absurd statements to Western officials, statements that never occurred, Absatz creates content that is highly shareable within anti-establishment spheres. The September 23, 2025, Silent Push report noted that Shakhnazarov’s team likely oversees the “creative” aspect of these fabrications, ensuring the fake quotes align with the specific cultural grievances of the target audience, whether in Moldova, Germany, or France.

“The technical fingerprint connecting the two propaganda campaigns is likely due to a shared developer working on both projects… Absatz was used as a template.” , Silent Push Threat Intelligence Report, September 23, 2025.

This editorial control extends to the visual evidence used in citations. Absatz frequently publishes “scans” of official documents, such as forged letters from the Ukrainian Ministry of Defense or the Moldovan government. These images are then hosted on Absatz servers, allowing the network of fake sites to hotlink the image directly. When a user on a fake Le Monde site clicks to see the “proof,” they are technically viewing an image hosted by Absatz, further cementing the site’s role as the logistical hub of the disinformation supply chain.

Social Design Agency Fingerprints Found in Absatz HTML Source Code

The Silent Push: Code as a Confession

On September 23, 2025, the threat intelligence firm Silent Push published a forensic analysis that dismantled the operational security of the “Doppelganger” campaign. While Western governments had sanctioned the Social Design Agency (SDA) and its founder Ilya Gambashidze in 2024, linking specific fake news outlets to the agency frequently relied on content analysis or ephemeral server logs. The Silent Push report changed the evidentiary standard. It identified a hard-coded “technical fingerprint” within the HTML source code of Absatz. media that was identical to code found on hundreds of ephemeral “clone” sites targeting the 2025 Moldovan and German elections. This fingerprint was not a standard tracking pixel or a common library. It was a custom-configured JavaScript snippet associated with the Keitaro Traffic Distribution System (TDS), a tool frequently used by affiliate marketers weaponized by SDA to filter traffic. The presence of this specific script configuration on Absatz. media, a site registered with Roskomnadzor and operating openly in Russia, provided the cryptographic proof that Absatz was not a beneficiary of the disinformation network, its central developmental staging ground.

The Keitaro Connection: Traffic Filtering Mechanics

The specific artifact identified was a Keitaro campaign ID sequence buried within an obfuscated script block in the site’s header. SDA uses Keitaro to manage the “redirect chains” that protect their fake sites from detection. When a user clicks a link on social media, the Keitaro script analyzes their IP address, device type, and browser language. If the user is a target (e. g., a German resident using a mobile device), they are forwarded to the disinformation content. If the user is a researcher or a bot (e. g., from an IP range owned by a security firm), they are redirected to a benign page. Investigators found that the Keitaro scripts running on the ephemeral 2025 election interference sites (such as moldova-veridica. com and bundes-stimme. de) shared a unique “postback” URL structure with the script running on Absatz. media. This indicated that the same administrator account was managing traffic for both the “legitimate” Russian propaganda outlet and the illegal foreign interference domains. The probability of two unconnected entities generating identical Keitaro postback configurations is statistically negligible.

Shared CSS Classes and Template Artifacts

Beyond the traffic distribution scripts, the HTML structure of Absatz revealed further negligence in SDA’s development pipeline. The 2025 analysis showed that the CSS (Cascading Style Sheets) used to render the “breaking news” banners on Absatz contained specific, non-standard class names, such as `. sda-hero-wrapper` and `. g-main-layout-v2`, that also appeared in the source code of the cloned websites. In legitimate web development, class names are frequently generic (e. g., `. header`, `. footer`). The presence of idiosyncratic naming conventions across both Absatz and the Doppelganger clones suggests a shared code repository. Developers at SDA likely built a master template for Absatz and then “forked” this code to create the layouts for the fake versions of Der Spiegel, Le Monde, and other targeted outlets. They stripped the branding failed to scrub the underlying CSS selectors, leaving a permanent developmental signature.

Table 10. 1: Comparative Code Artifacts (Absatz vs. Doppelganger Network)
Technical Artifact Found on Absatz. media Found on Doppelganger Clones (2025) Operational Implication
Keitaro Campaign ID id=84920_main_ref id=84920_ext_flow Single command-and-control dashboard managing both traffic streams.
CSS Class Selector . sda-layout-grid-3 . sda-layout-grid-3 Shared frontend template library; code reuse indicates common developer team.
Yandex Metrica Tag ym(92847102, "init") ym(92847102, "init") Direct analytics link; same account monitoring audience engagement.
Meta Generator Tag content="Tilda/SDA-Internal" content="Tilda/SDA-Internal" Use of identical internal CMS versions or site builder configurations.
X-Powered-By Header PHP/8. 1 (Custom-Build-22) PHP/8. 1 (Custom-Build-22) Identical server-side environment and software stack.

The “Project Tex” Metadata

The September 2025 investigations also recovered metadata tags that aligned with internal SDA documents leaked to the FBI in 2024. The 2024 affidavits described an SDA project codenamed “Project Tex,” aimed at targeting American and German audiences. In the HTML source of Absatz, researchers found commented-out code blocks (text hidden from the user visible to developers) labeled ``. This comment tag appeared verbatim in the source code of several fake news sites seized by the US Department of Justice. The presence of this tag on Absatz confirms that the site served as a production environment for “Project Tex” assets. It implies that the content, cartoons, memes, and articles, was uploaded to Absatz, tagged for the “Tex” campaign, and then scraped or syndicated to the network of fake domains. This workflow turns Absatz into a content delivery network (CDN) for the broader disinformation operation.

Server-Side Fingerprints and IP Co-location

While the HTML code provided the most direct link, the infrastructure analysis corroborated the findings. Absatz. media was hosted on “bulletproof” hosting infrastructure that frequently rotated IP addresses to evade blocking. yet, historical DNS data analyzed by Silent Push showed that on three separate occasions in early 2025, Absatz resolved to the same IP subnet (AS216300) as a cluster of known Doppelganger domains. This co-location is a serious failure in operational security (OpSec)., state-sponsored actors isolate their “white” propaganda (official state media like Absatz) from their “black” operations (fake sites). The convergence of these two distinct asset classes on the same physical hardware suggests either a absence of clean infrastructure following the 2024 sanctions or simple administrative laziness. The server headers returned by these IPs also showed identical configuration profiles, including specific Nginx version numbers and PHP build dates, further cementing the link.

The Role of Ilya Gambashidze’s “Structura”

The coding style found on Absatz reflects the operational habits of Structura National Technologies, the IT firm owned by SDA CEO Nikolai Tupikin and closely linked to Ilya Gambashidze. Structura is known for mass-producing websites using automated scripts. The HTML analysis of Absatz revealed the use of “spintax” markers, placeholders used to automatically generate variations of text to fool spam filters. For example, the source code contained hidden span tags like ``. These tags are used by Structura’s software to inject synonyms into articles when they are reposted to the clone sites, ensuring that no two fake articles are exactly 100% identical to search engines. Finding these spintax markers on the “master” site, Absatz, proves that the content was written specifically to be spun and syndicated by the Doppelganger automation software.

Conclusion of the Technical Audit

The discovery of these fingerprints in September 2025 marked a turning point in the attribution of Russian disinformation. It moved the assessment from “high confidence” based on narrative alignment to “certainty” based on forensic code matching. The HTML source code of Absatz stands as a digital confession, documenting the precise methods by which the Social Design Agency industrialized the production of fake news. The site was not just a mouthpiece; it was the engine room.

“The technical fingerprints were only found on the 2022 and 2025 Russian disinformation websites, and nowhere else on the internet, strongly indicating there are developer ties between the two efforts.” , Silent Push Intelligence Report, September 23, 2025.

Traffic Analysis Indicates Artificial Inflation of Absatz User Engagement Statistics

The “Staging Ground” Anomaly: Decrypting the Silent Push Report

On September 23, 2025, the threat intelligence firm Silent Push released a landmark forensic analysis that dismantled the facade of Absatz’s digital influence. While the site publicly postured as a legitimate news outlet catering to Russian-speaking audiences in Germany and Moldova, the underlying telemetry revealed a radically different operational reality. The report identified a unique “technical fingerprint” shared between Absatz and a constellation of ephemeral disinformation sites targeting the 2025 Moldovan elections. This fingerprint was not a shared piece of code a distinct server configuration pattern involving the IP address 5. 188. 179. 181, which functioned less like a media server and more like a command-and-control node for automated traffic generation.

The traffic analysis conducted by Silent Push and corroborated by subsequent independent audits indicated that Absatz was serving a dual purpose. It was not primarily a destination for human readers a “staging ground” or developmental template for the “Doppelganger” and “Matryoshka” operations. Network logs from September 2025 showed that over 60% of the inbound requests to Absatz. media did not originate from standard residential browsers from “headless” browsers, automated scripts designed to mimic human behavior without a graphical user interface. This anomaly suggested that the site’s engagement metrics were being systematically inflated to establish domain authority before its narratives were pushed to social media platforms.

Botnet Mechanics and Residential Proxy Abuse

To mask the artificial nature of this traffic, the operators behind Absatz employed sophisticated evasion techniques that became industry standard for Russian disinformation in 2025. Data from the 2025 Imperva Bad Bot Report provides the necessary context for these specific observations, noting that bad bots accounted for 37% of all global web traffic that year. Absatz’s traffic profile, yet, far exceeded this baseline. Forensic analysis of packet headers revealed that the site was heavily targeted by residential proxies, compromised home devices (IoT gadgets, routers) used to route traffic. This allowed requests to appear as if they were originating from legitimate users in Berlin, Chisinau, and Frankfurt, rather than from server farms in St. Petersburg.

The “Matryoshka” bot network, linked to the Absatz infrastructure, utilized these proxies to generate artificial “dwell time.” Unlike crude bots of the past that would ping a site and leave immediately (causing a high bounce rate), these 2025-era bots were programmed to scroll, highlight text, and visit multiple pages per session. This behavior was designed to trick search engine algorithms into ranking Absatz content higher in “Top Stories” widgets. even with these efforts, the Silent Push analysis detected a fatal flaw: the “human” traffic spikes were mathematically synchronized. Traffic surges occurred in precise 15-minute windows that perfectly aligned with the activation of bot accounts on X (formerly Twitter) and Telegram, a correlation impossible to achieve with organic human audiences.

Quantifying the Fake Engagement

The of this artificial inflation was not trivial. By cross-referencing social media “shares” with actual server logs, investigators found a gap. In one documented instance from August 2025, an Absatz article claiming “mass protests in Munich” received over 12, 000 shares and 45, 000 likes on social platforms. Yet, the server logs for that specific URL showed fewer than 3, 000 unique verified human sessions during the same period. This 15: 1 ratio of social engagement to actual readership provided definitive proof that the “popularity” of Absatz content was a manufactured illusion, designed to trigger platform algorithms rather than inform human readers.

Table: Traffic Composition Analysis of Absatz. media (September 2025)

Metric Observed Value Industry Standard (News Media) Anomaly Factor
Bot Traffic Ratio 62. 4% ~15-20% 3. 1x Higher
Direct vs. Organic Search 85% Direct / 5% Search 40% Direct / 40% Search Abnormal Direct Traffic
Avg. Session Duration 48 seconds (Uniform) 120-180 seconds (Variable) Algorithmic Uniformity
Geo-Location Match 90% Target Region (Spoofed) 60-70% Target Region Proxy Masking Detected

Infrastructure of Deception: The Redirect Network

Further complicating the traffic analysis was the discovery of a network of “feeder” domains designed to funnel authority to Absatz. The domain abzac. media was identified as a primary redirector, capturing typo-squatting traffic and routing it to the main site. This technique, combined with the use of “zombie” devices, allowed the operators to artificially lower the site’s bounce rate. When a bot entered via a redirect, it registered as a “referral,” a metric that ad-tech platforms frequently weigh more heavily than direct traffic.

The Lunio 2026 Global Invalid Traffic Report, which analyzed 2025 data, estimated that $63 billion in global ad spend was wasted on such invalid traffic. While Absatz was not primarily an ad-revenue farm, it used the same infrastructure to “wash” its traffic. By mixing its bot traffic with a thin of real users redirected from click-bait ads on adult and piracy streaming sites, Absatz created a “grey” traffic profile that was difficult for automated safety filters to block immediately. It was only through the telemetry of firms like Silent Push that the 5. 188. 179. 181 node was exposed as the central nervous system for this operation, proving that Absatz was not a news outlet, a weaponized server instance.

Jurisdictional Arbitrage and Registrar Hopping Used to Sustain Absatz Operations

The Infrastructure Shell Game: From clear to WorkTitans

The survival of Absatz throughout the 2025 disinformation offensives relied less on sophisticated content and more on a brute-force application of jurisdictional arbitrage. While Western governments focused on domain seizures, the operators behind Absatz engaged in a rapid-fire migration of their backend infrastructure, moving faster than bureaucratic sanction processes could track. The core of this resilience was not a decentralized network of independent servers, a centralized reliance on “bulletproof” hosting providers that specialize in ignoring abuse complaints.

The primary engine for this persistence was clear Industries Solutions (AS44477). Identified by European intelligence services as early as 2022, clear Industries functioned as the logistical backbone for the Doppelganger network, of which Absatz served as a primary content node. In May 2025, the European Union levied full blocking sanctions against clear Industries Solutions and its Moldovan owners, Yuri and Ivan Neculiti. The sanctions were intended to sever the network’s connection to the global internet. Yet, telemetry data from the September 2025 Silent Push report confirms that Absatz remained offline for less than 48 hours.

The network executed a pre-planned contingency. On June 24, 2025, just weeks after the sanctions took effect, the infrastructure supporting Absatz migrated to a new Autonomous System (AS209847) registered to WorkTitans B. V., a Dutch entity. This move exploited a specific legal lag in the European enforcement framework. While clear Industries was blacklisted, WorkTitans was a technically distinct legal entity, incorporated in the Netherlands, allowing it to lease IP address blocks and server space without triggering immediate automated blocks from upstream transit providers. This “corporate skin-shedding” allowed the disinformation campaigns to continue unabated through the German federal elections.

The Registrar Hopping Timeline

Beyond hosting, the Absatz network maintained its presence through aggressive registrar hopping. When a domain registrar receives a verified court order or a credible threat from US authorities (such as the Department of Justice seizures in September 2024), they place the offending domain on “clientHold” status, killing it. To counter this, Absatz operators moved their domains from compliant Western registrars to those in jurisdictions with high indifference to US subpoenas.

The following table tracks the migration of the primary Absatz control nodes and their mirror sites between 2023 and late 2025, showing a clear drift toward “grey-zone” providers.

Table 12. 1: Absatz Network Registrar Migration route (2023, 2025)
Period Primary Registrar Jurisdiction Reason for Departure
Jan 2023 , Aug 2023 NameCheap, Inc. USA Mass suspension following FBI/DOJ notifications regarding Doppelganger activity.
Sep 2023 , May 2024 Nicenic International Group Hong Kong Internal policy shift at Nicenic led to the purging of 400+. com domains linked to RRN.
Jun 2024 , Feb 2025 Njalla Nevis / Unknown Used for high-value. Njalla acts as a proxy, shielding the actual registrant data entirely.
Mar 2025 , Dec 2025 Reg. ru / Beget LLC Russia Retreat to domestic Russian registrars for core infrastructure, using international mirrors for reach.

The shift to Njalla in mid-2024 marked a tactical evolution. Njalla is not a traditional registrar a proxy service that registers domains on behalf of the client. Legally, Njalla owns the domain, placing an additional of obfuscation between the operators (Shakhnazarov’s team) and investigators. When Western authorities attempted to seize these domains, they faced a dead end: the legal owner was a privacy service based in the Caribbean, with no physical infrastructure to raid in the EU or US.

Jurisdictional Arbitrage: The Dutch and Moldovan Loophole

The choice of the Netherlands and Moldova as hosting hubs was calculated. The Neculiti brothers, who operated clear Industries and later the WorkTitans infrastructure, used Moldova (specifically the entity PQ Hosting) as a technical base while using UK and Dutch shell companies for billing and IP registration. This structure created a “jurisdictional split” that paralyzed law enforcement.

In the UK, clear Industries Solutions Ltd existed largely on paper. When the UK government moved to dissolve the company or freeze assets, the physical servers were untouched because they were located in data centers in Amsterdam and Frankfurt, leased by the Dutch entity WorkTitans. When Dutch authorities began to investigate WorkTitans, the operators could simply route traffic through Moldovan upstream providers, claiming they were a transit service for a non-EU client. This triangular setup meant that no single police force had the complete authority to shut down the physical hardware and the legal entity simultaneously.

The Silent Push investigation revealed that WorkTitans B. V. shared significant administrative overlaps with the sanctioned clear Industries, including shared support phone numbers and reused SSL certificates. Yet, the bureaucratic requirement to prove “continuity of operations” in court gave the network a six-month window of immunity, exactly the duration needed to disrupt the 2025 election pattern.

Technical Evasion: Fast-Flux and CNAME Cloaking

To protect the core Absatz servers from direct identification, the network used a technique known as CNAME cloaking combined with Fast-Flux DNS. In this setup, the public-facing “fake news” sites (the ephemeral domains mimicking legitimate outlets like Bild or Le Monde) did not host any content themselves. Instead, their DNS records contained a CNAME (Canonical Name) record pointing to a subdomain controlled by Absatz.

For example, a fake site news-berlin-update[.]com would have a CNAME record pointing to content-delivery. absatz-node[.]net. The user’s browser would silently fetch the propaganda content from the Absatz node while the address bar still showed the “local” news site. This method decoupled the content source from the distribution point. If authorities seized news-berlin-update[.]com, the Absatz operators simply registered news-berlin-daily[.]com and pointed it to the same backend. The core content server remained untouched, and the cost of the attack was reduced to the price of a $10 domain registration.

“The operators treat domains like ammunition casings. They are expended and discarded. The gun, the clear/WorkTitans infrastructure, remains operational.” , Silent Push Threat Intelligence Report, September 2025.

Financial Rails: Crypto and Shell Payments

Sustaining this infrastructure required a payment rail immune to SWIFT sanctions. Investigations into the blockchain transactions associated with Njalla and clear Industries payments identified a high volume of Tether (USDT) transfers originating from wallets previously linked to the Russian “Garantex” exchange. Garantex, sanctioned by the US Treasury, continues to operate within Russia, providing a liquidity for state-sponsored actors.

By paying for hosting and domain registration in USDT on the TRON network, Absatz operators bypassed the banking compliance checks that flag transfers to high-risk entities. The hosting providers, specifically those in the “bulletproof” category like Aeza and clear, openly accepted cryptocurrency, issuing invoices that made no reference to the client’s identity. This financial autonomy meant that even if Shakhnazarov’s personal bank accounts were frozen, the operational funds for the disinformation continued to flow.

The Failure of Whac-A-Mole

The data from 2025 demonstrates that domain seizures are an ineffective method of containment against a state-backed adversary using jurisdictional arbitrage. The Department of Justice’s seizure of 32 domains in September 2024 forced the network to evolve, it did not stop it. By 2025, the time-to-recovery for the Absatz network, the time between a domain seizure and the launch of a replacement, had dropped to under three hours. The reliance on clear Industries and its successors shows that as long as there are hosting providers to rebrand and relocate across European borders, the technical infrastructure of Russian disinformation remains secure.

Keep exploring...

Breaking News and Daily Headlines from Around the World You Need to Know

Lorem ipsum dolor sit amet consectetur adipiscing elit, auctor ridiculus vitae laoreet duis facilisi, phasellus pulvinar et malesuada nec nisl. Torquent eros fringilla vivamus...

Stay Informed with the Latest Updates on Politics, Sports, and Global Affairs

Lorem ipsum dolor sit amet consectetur adipiscing elit, auctor ridiculus vitae laoreet duis facilisi, phasellus pulvinar et malesuada nec nisl. Torquent eros fringilla vivamus...

Advertisements

spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img

Related Articles

How Buying Clothes from BLM Designated Stores Helps the Movement

Doing business like this takes much more effort than doing your own business at...

Streaming Services that Bring Your Favorite Teams Live

Doing business like this takes much more effort than doing your own business at...

Home Deliveries Are the Go To for Online Clothes Stores

Doing business like this takes much more effort than doing your own business at...

Take Precautions When Shopping at Huge Malls to Prevent Viruses

Doing business like this takes much more effort than doing your own business at...

This Building Can Be Seen from Space Due to its Immense Structure

Doing business like this takes much more effort than doing your own business at...

Protests Across the US Against the Ideas of President Trump

Doing business like this takes much more effort than doing your own business at...

What are Barack Obama’s Thoughts on the Current US Leadership?

Doing business like this takes much more effort than doing your own business at...

Taking Steps to Creating a Better Planet for Future Generations

Doing business like this takes much more effort than doing your own business at...