The 'Matryoshka' Architecture: Anatomy of a Nesting Disinformation Campaign
1: The Macro-Narrative Shell
The outer shell of the Matryoshka campaign presents a legitimate geopolitical alternative to the European Union. Unlike previous blunt-force propaganda, this uses high-production value content to mimic Western journalistic standards. Between April and September 2025, the campaign generated sophisticated counterfeits of 23 major international media outlets, including The Economist, Vogue, and the BBC. These fabrications did not promote Russia directly instead attacked the efficacy of the EU, framing accession as an economic death sentence for Moldovan agriculture and a surrender of sovereignty. This operates on a “saturation” principle. By flooding the information space with “verified” looking reports from trusted Western brands, the campaign creates a permission structure for undecided voters to reject the EU without feeling aligned with Moscow. The content is designed to be shared organically by skeptics who believe they are citing reputable sources.
2: The Operational Infrastructure (The “Pravda” Network)
Inside the narrative shell lies the technical distribution engine, frequently referred to by investigators as the “Pravda” or “Portal Kombat” network. This consists of approximately 150 anonymously owned websites and thousands of social media assets that amplify the fake reports generated in 1. * The Echo Chamber: A single fabricated story, such as a deepfake video of President Maia Sandu allegedly disparaging rural voters, is simultaneously released across hundreds of Telegram channels and TikTok accounts. * Bot Farms: Automated networks, specifically the “Storm-1679” cluster, artificially engagement metrics (likes, shares, views) to trigger platform algorithms. Data from the 2025 pattern indicates these bots generated over 2 million views on Telegram alone for just 39 specific false narratives between April and July 2025. * Localization: Unlike generic Russian propaganda, this employs native Romanian and Russian speakers to tailor comments and posts, making the outrage appear indigenous rather than foreign-manufactured.
3: The Human and Financial Core
The innermost doll, and the most serious component, is the human network on the ground, funded and directed by the fugitive oligarch Ilan Shor. This converts digital noise into physical action. It is not an influence operation in the abstract; it is a payroll system. * The “InfoLeader” Group: A tiered recruitment structure where “activists” are paid to disseminate specific narratives. The “Training of Communication Activists” group recruits young Moldovans, teaching them to create content that aligns with the “Victory” bloc’s agenda while concealing the connection. * Direct Payment method: Investigations revealed that payments to these operatives were routed through Promsvyazbank (PSB), a Russian state-owned lender servicing the defense sector. Operatives received monthly stipends, frequently in cryptocurrency or via transfers to Transnistrian accounts to bypass Chisinau’s banking sanctions. * The “Gagauzia” Pivot: When the “Victory” bloc faced legal blocks, the network direct redirected its assets to support alternative proxies, demonstrating the modular nature of the Matryoshka architecture. The infrastructure remains; only the political “skin” changes.
Verified Campaign Metrics (2025 Election pattern)
The following data points quantify the of the Matryoshka operation during the serious months leading up to the September 2025 parliamentary vote.
| Metric | Verified Figure | Source / Context |
|---|---|---|
| Total Estimated Funding | €100 Million+ | Moldovan Authorities / EU Intelligence estimates for 2025 pattern. |
| Fake Media Outlets Impersonated | 23 | Includes BBC, Fox News, Vogue, The Economist. |
| Viral Reach (TikTok) | 55 Million Views | Atlantic Council DFRLab data for Shor-linked network (Jan-Sept 2025). |
| Fake Stories Published | 3 per week (Avg) | NewsGuard data (April, July 2025). |
| Paid “Activists” Identified | 130, 000+ | Moldovan Police data on illicit transfers for vote-buying/influence. |
| Cyberattacks on State Infrastructure | 1, 000+ | Moldovan Prime Minister’s Office (Jan-Sept 2025). |
“The Matryoshka campaign represents a shift from ‘firehose of falsehood’ tactics to precision-guided fabrication. They are not just throwing mud; they are building a parallel reality using the stolen credibility of Western institutions.” , Internal Briefing Note, European Centre of Excellence for Countering Hybrid Threats (Hybrid CoE), October 2025.
The architecture is resilient because it is compartmentalized. one —such as banning a specific TV channel or blocking a website—does not stop the operation. The funding ( 3) simply finds a new outlet ( 2) to push the same strategic narrative ( 1). This nesting doll structure allows Russian intelligence to maintain a persistent, adaptive presence in the Moldovan information space, regardless of individual tactical defeats.
The PSB Protocol: Promsvyazbank's Digital Ruble Injection Scheme

The Architecture of the Injection
At the center of this operation sits Promsvyazbank (PSB), a Russian state-owned institution originally to service the Kremlin’s defense contracts. In 2024 and 2025, PSB repurposed its secure payment rails to facilitate the mass transfer of illicit funds into Moldova. The operation relied on a specific nesting structure: 1. The Outer Shell (Humanitarian Aid): The “Eurasia” (Evrazia) non-profit, led by figures linked to fugitive oligarch Ilan Shor, signed “cooperation agreements” with the autonomous region of Gagauzia. These agreements promised “pension top-ups” and “social assistance” to demographics. 2. The Middle Shell (Digital Onboarding): To receive these funds, recipients were required to download the PSB mobile application. Since the app was banned from standard platforms like the Apple App Store and Google Play, Shor’s network distributed it via direct APK downloads and Telegram bots. 3. The Inner Core (Transactional Bribery): Once onboarded, users received monthly stipends in Russian rubles. These funds were not aid; they were conditional payments tethered to political compliance, specifically voting against the EU referendum in 2024 and supporting pro-Russian blocs in the 2025 parliamentary elections. Data from the General Inspectorate of Police (IGP) indicates the of this operation was industrial. In September and October 2024 alone, PSB transferred approximately $39 million to over 138, 000 individual Moldovan accounts. This volume overwhelmed the domestic banking monitoring systems, as the transactions technically occurred outside the Moldovan financial jurisdiction until the moment of cash-out.
The 2025 Evolution: The “A7” Complex
Following the partial exposure of the 2024 scheme, the Matryoshka campaign upgraded its financial rails for the 2025 parliamentary pattern. Intelligence reports and U. S. Treasury designations reveal that Ilan Shor and PSB established a new entity, A7, to circumvent tightening sanctions. A7, owned 51% by Shor and 49% by PSB, introduced a “ruble-backed stablecoin” (A7A5) and utilized a through Keremet Bank in Kyrgyzstan to obfuscate the origin of funds. This allowed the network to bypass the SWIFT system entirely, moving value through a “gray” banking circuit that Western regulators struggled to map in real-time.
| Operational Metric | 2024 Presidential pattern | 2025 Parliamentary pattern |
|---|---|---|
| Primary Conduit | Direct PSB Accounts (Mir Cards) | A7 Fintech / Keremet Bank |
| Payment Volume | $39 Million (Sept-Oct) | Est. $60-70 Million (Aug-Sept) |
| Bribe per Voter | 500 , 800 MDL | 800 , 1, 600 MDL |
| Target Demographic | Pensioners (Gagauzia/Orhei) | Youth Activists & Public Sector |
| Tech method | Sideloaded Mobile App | Crypto-Wallets & Telegram Bots |
The Cash-Out Bottleneck
The digital ruble injection faced a serious physical constraint: converting digital balances into spendable Moldovan Lei (MDL). The PSB Protocol solved this through two primary methods: * The Transnistrian Loophole: Recipients traveled to the breakaway Transnistria region, where the Russian Mir payment system remains operational. There, they withdrew cash from ATMs or engaged in “shopping tourism,” laundering the Russian subsidies into physical goods or currency before returning to government-controlled territory. * The Peer-to-Peer Mule Network: In 2025, police identified a decentralized network of “curators.” These individuals, frequently managed via Telegram, purchased the digital balances from pensioners at a discount (e. g., exchanging 100 digital rubles for 80% of their cash value), consolidating the digital assets while distributing physical cash in villages. Viorel CernăuÈ›eanu, Head of the General Police Inspectorate, described the difficulty of intercepting these flows during a September 2025 briefing:
“We are witnessing a financial insurgency. The funds do not cross our border; they materialize on phones. We seize the cash couriers, the digital pipeline from PSB to the end-user operates in a cloud jurisdiction that respects no national sovereignty. In 2025, the illegal financing nearly doubled compared to the previous year, with the cost of a single vote rising to 1, 600 MDL.”
Countermeasures and Impact
The Moldovan authorities responded with a strategy of “demand-side” deterrence. Rather than solely targeting the elusive organizers, the police began fining the recipients. By late 2025, over 23, 000 residents of Gagauzia faced fines totaling 575 million Lei for “passive electoral corruption.” This method created a panic within the recipient network, as the fines frequently exceeded the value of the bribes received. yet, the PSB Protocol achieved its primary strategic goal: it successfully injected tens of millions of dollars into the Moldovan economy, creating a dependency loop where the only way to pay the government fine was to accept the tranche of Russian payments.
CEC Under Siege: The 898 Million Request DDoS Assault
The 12-Hour Digital Siege
On September 28, 2025, the Central Electoral Commission (CEC) of Moldova became the primary target of a kinetic cyber assault designed to paralyze the democratic infrastructure of the state. Between 09: 06 UTC and 21: 00 UTC, the CEC’s digital perimeter was hammered by 898 million malicious requests. This volume was not a random spike; it was a calibrated weaponization of civilian infrastructure, executing the third of the “Matryoshka” influence architecture: technical denial of service to induce panic and delegitimize the vote count.
The attack vector was distinct from previous election interference patterns observed in Eastern Europe. Instead of relying solely on known state-actor server farms, the assault utilized a botnet comprised of thousands of compromised residential Wi-Fi routers within Moldova and neighboring jurisdictions. This tactic allowed the traffic to mimic legitimate domestic user behavior, complicating filtration efforts. At its peak, the bombardment reached 324, 333 requests per second (RPS), a load capacity capable of crashing unfortified enterprise networks in seconds.
Operational and Tactical Fan-Out
While the CEC. md domain was the primary objective, the offensive fanned out to cripple the broader information ecosystem surrounding the election. The “Matryoshka” strategy relies on isolating the electorate from verified data sources during serious windows. Intelligence reports confirm that the DDoS waves were synchronized with physical bomb threats at diaspora polling stations in Frankfurt, Liverpool, and Northampton, creating a dual-front emergency for Moldovan authorities.
| Target Sector | Specific Entity | Attack Function | Status |
|---|---|---|---|
| Electoral Core | CEC. md (Official Commission Portal) | Block access to turnout data and live results. | Mitigated (Cloudflare/STISC) |
| Government Infrastructure | MCloud (Gov. Cloud Service) | Disrupt inter-agency communication and hosting. | Mitigated |
| Civic Society | Vote Monitor & NGO Portals | Prevent independent verification of fraud reports. | Degraded (Intermittent outages) |
| Media | Independent News Outlets (Point. md, IPN) | Silencing factual reporting to allow disinformation spread. | Mitigated |
| Diaspora | Overseas Voting Stations | Sever connectivity to the central voter registry. | Operational |
The Cost of Defense: Financial and Strategic Metrics
The defense of this digital perimeter required an mobilization of resources. For the time in its operational history, the European Union deployed its Cybersecurity Reserve to a non-member state, embedding rapid-response teams directly within ChiÈ™inău’s Information Technology and Cyber Security Service (STISC). This deployment was not advisory; it involved active threat hunting and traffic scrubbing.
The financial of this hybrid war is clear. Verified data indicates that cybercrime and hybrid threats cost Moldova approximately 0. 3% of its annual GDP, roughly $49 million in nominal terms. To counter this, the EU allocated over €1. 2 billion in grants between 2021 and 2025, with specific tranches dedicated to hardening the “digital shield” of the republic. In December 2025, following the immediate lessons of the September siege, the Moldovan cabinet approved a new National Cybersecurity Program (2026-2030) with an initial domestic funding injection of 73 million lei.
“The attack was not designed to hack the vote count, to hack the public’s confidence in the count. By attempting to take the CEC offline during the tabulation window, the aggressors intended to create a data vacuum that their Telegram channels could fill with pre-fabricated allegations of fraud.”
Technical Attribution and “Matryoshka” Integration
Forensic analysis of the attack traffic reveals the signature of the “Matryoshka” campaign’s technical tier. The use of the NoName057(16) shared’s toolsets, combined with the “DDoSia” project infrastructure, points to a coordinated effort rather than a loose hacktivist uprising. The 898 million requests were timed to coincide with the closure of polls, specifically targeting the result reporting phase. This synchronization confirms that the DDoS assault was not an act of vandalism a supporting fire mission for the broader psychological operation, intended to provide “proof” of system failure that could be amplified by the campaign’s narrative shell.
Synthetic Statesmen: Deconstructing the Deepfake 'Sandu' Tapes

The Synthetic Statesman: A Forensic Analysis of Identity Theft
The “Matryoshka” campaign’s most invasive does not rely on human agents or paid protesters; it relies on the digital resurrection of the state itself. Between December 2023 and October 2025, Moldovan citizens were subjected to a barrage of “Synthetic Statesmen”, AI-generated avatars of President Maia Sandu and other high-ranking officials designed to trust in the executive branch. Unlike the “cheapfakes” of the early 2020s (slowed-down videos or miscaptioned clips), these assets used high-fidelity voice cloning and lip-sync technology to turn the country’s leaders into mouthpieces for Kremlin narratives. This phase of the operation, identified by the watchdog group Antibot4Navalny as “Operation Overload,” functions as the innermost doll of the Matryoshka structure. The outer provide the geopolitical context (e. g., “The EU destroy our traditions”), while the synthetic video serves as the “smoking gun”, fake evidence that the leader has already capitulated.
Case Study 1: The “Honest” Traitor (December 2023)
The campaign’s proof-of-concept emerged on December 29, 2023, just days before the New Year. A video circulated rapidly across Telegram channels like Gagauz Republic and WTF Moldova, depicting President Sandu in a black dress, a visual departure from her standard official wardrobe, delivering a “congratulatory” message. While the visual fidelity contained artifacts typical of early 2024 generation tools (rigid facial muscles, inconsistent lighting), the audio payload was sophisticated. The synthetic voice, trained on Sandu’s public speeches, delivered a script of “radical honesty” designed to confirm the biases of pro-Russian voters. The avatar stated:
“I pledge you nothing, because I am not here for that… The economy is stably degrading, my personal account is stably growing… Enjoy your bread and salt, because you have no money for anything else.”
This operation targeted the “demoralization” quadrant of the hybrid war matrix. By having the President “admit” to corruption and indifference, the operators sought to bypass the skepticism applied to opposition attacks. The video was viewed over 200, 000 times within 48 hours before major platforms labeled it as manipulated. The choice of the black dress was likely a psychological trigger, associating the President with mourning or villainy rather than the festive hope of a New Year’s address.
Case Study 2: The Rosehip Conspiracy (Rural Micro-Targeting)
If the New Year deepfake was a broadside attack, the “Rosehip Ban” video released in late 2023 demonstrated the campaign’s capacity for precision micro-targeting. A deepfake video surfaced showing President Sandu announcing a prohibition on gathering rosehips and other wild berries, citing European Union environmental regulations. To a Western observer, such a ban sounds trivial. yet, for Moldova’s rural poor, foraging for rosehips is a traditional subsistence activity and a source of Vitamin C during winter. The narrative was engineered to weaponize the “fear of the outsider” (EU bureaucracy) against the “survival instinct” of the village demographic. Tactical Analysis: * Vector: The video was seeded in local village Facebook groups and Viber chats, bypassing the scrutiny of urban intellectuals in ChiÈ™inău. * Narrative Hook: “The EU cares more about bushes than your hunger.” * Impact: Government fact-checking portal Stopfals. md reported a surge in inquiries from elderly citizens terrified they would be fined for picking tea leaves. The deepfake successfully converted a geopolitical abstraction (EU integration) into a tangible, personal threat.
Case Study 3: The “Luma” Rapper (September 2025)
As the 2025 parliamentary elections method, the tactics shifted from deception to ridicule. In September 2025, a video generated using Luma AI (a US-based video generation tool) depicted President Sandu rapping in Russian. The avatar mocked Moldova’s energy dependence and the slow pace of EU accession. Unlike previous attempts that strove for realism, this asset was designed to be “uncanny”, realistic enough to be recognized, stylized enough to humiliate. The use of the Russian language was a deliberate wedge problem, signaling to the Russian-speaking minority that Sandu was a “clown” rather than a serious leader. The Insider and Antibot4Navalny traced the distribution of this video to a bot network that simultaneously posted the clip across X (formerly Twitter) and TikTok, using identical captions to game the algorithms.
Case Study 4: Institutional Decapitation (July 2025)
The Matryoshka campaign expanded beyond the President to target the of the election itself. On July 31, 2025, a deepfake video targeted Angelica Caraman, the President of the Central Electoral Commission (CEC). The synthetic video showed Caraman stating that “interference by France in our elections is not considered foreign interference,” implying that the CEC was rigging the vote for the West. This operation was amplified by high-level Russian officials. Maria Zakharova, spokesperson for the Russian Ministry of Foreign Affairs, promoted the video as evidence of Moldovan hypocrisy. This represents a “state-sponsored laundering” of deepfake material: 1. Creation: Anonymous actors generate the deepfake. 2. Injection: Telegram channels post the video. 3. Legitimization: A Russian state official cites the video as fact. 4. Amplification: State media (RT, Sputnik affiliates) report on the official’s statement, embedding the fake video.
Technical Attribution and Distribution Architecture
The 2025 deepfake wave utilized a “waterfall” distribution model designed to maximize reach before platform moderators could react. The content flow consistently followed a specific pattern, moving from unregulated spaces to mainstream feeds.
| Stage | Platform | Action | Objective |
|---|---|---|---|
| Injection | Telegram (Private Channels) | Upload of high-bitrate video files to channels like “Gagauz Republic” or “Moldova Leaks”. | Establishes a “source” for the file without triggering algorithmic moderation. |
| Laundering | TikTok / YouTube Shorts | “Reaction” videos where influencers discuss the clip, frequently with the deepfake playing in the background. | Bypasses content ID systems; frames the fake as “news” or “commentary”. |
| Amplification | Facebook / Instagram Ads | Paid promotion of the “Reaction” videos targeting specific demographics (e. g., men 45-65 in BălÈ›i). | Injects the narrative into the feeds of apolitical or undecided voters. |
| Legitimization | State Media / Officials | Russian officials or proxy politicians cite the video as “concerning footage”. | Converts the digital fake into a diplomatic incident. |
The “Maib” Financial Scam (June 2025)
A parallel track of the influence campaign focused on direct financial fraud, likely to fund the operation itself or to sow chaos. In June 2025, deepfakes of President Sandu and Prime Minister Dorin Recean appeared in paid Facebook advertisements promoting a fake investment platform allegedly backed by Maib (Moldova’s largest bank). The avatar of Sandu urged citizens to “register for the new national dividend program,” promising monthly returns of 3, 000 MDL ($170). This operation served a dual purpose: 1. Theft: It harvested credit card details and personal data from victims. 2. : When the “dividends” never arrived, the victims blamed the government, reinforcing the narrative of state betrayal. The General Police Inspectorate (IGP) reported over 300 cases of such fraud in the half of 2025 alone, with damages exceeding 100 million MDL.
The Liar’s Dividend
The success of the “Synthetic Statesman” campaign is not measured by how people believe the fakes, by how people stop believing the truth. This phenomenon, known as the “Liar’s Dividend,” was observed in September 2025 when a real video of a pro-Russian candidate making a gaffe was dismissed by their supporters as “just another AI fake.” By saturating the information space with high-quality counterfeits, the Matryoshka campaign successfully lowered the evidentiary bar. When audio recordings surfaced in October 2025 allegedly showing oligarch Ilan Shor buying votes, his defense team immediately claimed the audio was AI-generated. The existence of the Sandu deepfakes gave this defense plausibility, neutralizing genuine investigative journalism. The technological progression from 2023 to 2025 shows a clear trajectory: the tools are becoming cheaper, faster, and more accessible. The “New Year” deepfake required days of rendering and professional voice acting; the “Luma” clips of late 2025 were likely generated in minutes. This acceleration suggests that future election pattern face not just deepfake incidents, a continuous stream of synthetic reality, making the “Matryoshka” doll impossible to unstack.
The 'Eurasia' Front: NGO Shells and the Cash Courier Network
The Shell Entity: ANO Eurasia
Registered in Moscow in April 2024, ANO Eurasia was ostensibly established to “cultural and historical ties” between post-Soviet states. Intelligence files and corporate registries identify the organization’s founder as Nelly Parutenco, the former treasurer of the outlawed Shor Party. Parutenco fled Chisinau for Moscow in 2022 to evade prosecution for illegal party financing. The organization’s structure reveals a direct operational link between the Kremlin and the fugitive oligarch Ilan Shor. The coordinating council includes Aliona Arshinova, a deputy in the Russian State Duma, and Mika Badalyan, a pro-Kremlin blogger based in Yerevan who was barred from entering Moldova in July 2024. Unlike traditional soft-power NGOs that operate with degree of autonomy, Eurasia functions as a pass-through entity. It receives funds from state-linked Russian accounts and disperses them to Moldovan “activists” under the guise of humanitarian aid, educational grants, or volunteer stipends.
method 1: The “Cash Mule” Swarm
The phase of the funding operation relied on a brute-force method: the physical transportation of cash by commercial air passengers. This network, referred to by Moldovan investigators as the “Ants,” utilized hundreds of coordinated couriers to bypass customs restrictions. On April 23, 2024, Moldovan customs officials at Chisinau International Airport intercepted a coordinated arrival of passengers returning from Moscow via Yerevan and Istanbul. The operation resulted in the seizure of approximately 20 million MDL ($1. 1 million). The logistics of this specific run expose the standard operating procedure for the network: * Recruitment: Couriers were recruited from impoverished rural districts, specifically Orhei and Gagauzia, with offers of free travel to Moscow for “political conferences.” * Transit: Due to the ban on direct flights, routes were diverted through Armenia (Yerevan) or Turkey (Istanbul). * The Load: Each courier was issued an envelope containing between €2, 000 and €9, 000, deliberately kept under the €10, 000 mandatory declaration limit. * Aggregation: Upon arrival in Chisinau, “collectors” waiting in the arrivals hall or parking lot would retrieve the envelopes from the mules, aggregating the small sums into operational slush funds for the Victory (Pobeda) electoral bloc. Police Chief Viorel Cernauteanu confirmed that the April seizure was a fraction of the total flow. Forensic analysis of seized mobile devices indicated that prior to the crackdown, the network successfully moved over $5 million using this method in Q1 2024 alone.
method 2: The Promsvyazbank (PSB) Pipeline
Following the airport seizures, the Matryoshka operation shifted to digital channels to reduce physical risk. The primary vehicle for this was Promsvyazbank (PSB), a Russian state-owned bank by the U. S. and EU for its role in financing the Russian defense sector. In April 2024, Evghenia Gutul, the Governor of Gagauzia and a Shor ally, signed an agreement with PSB Chairman Petr Fradkov in Moscow. The deal facilitated the issuance of “Mir” payment cards to 25, 000 pensioners and public sector employees in the autonomous region.
| Period | method | Volume (USD) | Recipients Identified |
|---|---|---|---|
| September 2024 | Direct PSB Transfers | $15, 000, 000 | ~37, 000 |
| October 2024 | Direct PSB Transfers | $24, 000, 000 | ~138, 000 |
| Total | Election Run-up | $39, 000, 000 | 175, 000+ |
The PSB system operated as a direct vote-buying method. Recipients downloaded the PSB mobile application, which is banned from the Google and Apple app stores available via direct APK download links circulated on Telegram. Once registered, users received a monthly stipend of 2, 000 MDL (approx. $115), a sum equivalent to 40% of the average pension in rural Moldova. To cash out these digital funds, the network established a secondary of “cash-out terminals.” Since Moldovan ATMs do not accept Mir cards, beneficiaries were instructed to transfer funds to “facilitators” in the Transnistrian region or use specific currency exchange offices controlled by the network, which converted the digital rubles into Moldovan lei at predatory rates.
The “Senezh” Indoctrination Camps
The Eurasia NGO also funded the “human infrastructure” of the influence campaign. Between June and August 2024, the organization sponsored travel for over 500 Moldovan youths to the “Senezh” management workshop near Moscow. While billed as cultural exchange programs, participant testimonies and leaked schedules reveal a curriculum focused on political agitation. Modules included “crowd psychology,” “resistance to law enforcement,” and “narrative dissemination.” Upon return, these trainees were not only ideologically aligned also financially dependent, frequently serving as the mid-level managers for the cash distribution networks in their home districts.
“We are not dealing with a political party in the democratic sense. We are dealing with an organized criminal group that uses the facade of a political party and an NGO to conceal money laundering and treason.”
, Viorel Cernauteanu, Chief of the General Police Inspectorate (IGP), Press Briefing, October 2024.
The Crypto-Financial Nexus
Beyond cash and PSB transfers, the Eurasia front experimented with cryptocurrency to pay higher-level operatives. The “A7” company, a joint venture between Shor and PSB, launched a proprietary crypto-token used to transfer value to campaign managers. These tokens were exchanged for fiat currency through a network of complicit exchange houses in Chisinau and Balti. In September 2025, anti-corruption prosecutors raided 30 locations linked to this crypto-scheme, seizing 9 million MDL ($540, 000) in assets and detaining key technical operators who managed the liquidity pools for the network. This multi- financial architecture—combining the archaic “mule” system with state-backed digital banking and unregulated crypto-markets—allowed the Matryoshka campaign to inject capital equivalent to 1% of Moldova’s GDP directly into the electorate, bypassing all standard campaign finance oversight.
Phantom Bylines: The 'Bellingcat' and 'BBC' Impersonation Ring

The Bellingcat-BBC Nesting Architecture
The most sophisticated operation detected during the 2025 parliamentary pattern involved a “nested” disinformation structure, a Matryoshka doll of fabrication. In June 2025, a video bearing the verified branding, typography, and motion graphics of the BBC began circulating on Telegram and TikTok. This fraudulent report “exclusive data” purportedly obtained by the investigative group Bellingcat. The fabricated narrative claimed that Moldovan President Maia Sandu had embezzled $24 million in European Union funds to purchase real estate in Spain for a “secret mistress.” To lend credence to the lie, the video featured a deepfake of Bellingcat founder Eliot Higgins “confirming” the financial trail. Forensic analysis by NewsGuard and CheckFirst revealed the mechanics of this deception: 1. Source: The attackers knew a direct claim from a Russian source would be dismissed. By attributing the claim to Bellingcat (a group detested by the Kremlin) and wrapping it in BBC packaging, they created a “credibility paradox” that confused algorithm moderators and casual viewers. 2. Visual Forensics: The video used the exact font (BBC Reith) and color hex codes (#B80000) used by BBC News. The deepfake of Higgins was synchronized with audio generated from his public interviews, though linguistic analysis detected unnatural pauses consistent with text-to-speech generation. 3. Denial Saturation: When Bellingcat publicly debunked the report, the Matryoshka network used the denial itself as engagement fodder, flooding comments sections with bots claiming the denial was “forced by NATO censors.”
The “Verification” Trap
Unlike the “Doppelganger” campaign, which primarily focused on cloning websites, the Matryoshka operators introduced a psychological component targeting Western journalists and fact-checkers. This tactic, identified by the private intelligence firm Recorded Future, weaponized the fact-checking process itself. Operatives controlling the fake accounts would proactively email or tag European journalists, feigning concern. The standard script read: “I saw this disturbing report about President Sandu on a BBC video. Can you verify if this is true? It looks very real.” This “request for verification” served two purposes: * Legitimacy Laundering: It forced reputable journalists to watch and engage with the content, tricking algorithms into registering the video as “trending” or “high engagement.” * Resource Drain: It overwhelmed the limited capacity of Moldovan and Romanian fact-checking desks (such as StopFals), forcing them to spend hundreds of hours debunking high-production fakes instead of investigating illicit financing.
Operational Metrics: The 2025 Impersonation Log
The scope of the impersonation ring extended well beyond the BBC. Intelligence data from the period between January 1, 2025, and October 15, 2025, confirms the counterfeiting of 23 distinct international media brands.
| Targeted Brand | Fabricated Narrative | Primary Vector | Est. Reach (Moldova) |
|---|---|---|---|
| Bellingcat | President Sandu embezzled $24M; “Secret Mistress” scandal. | TikTok / Telegram | 1. 2 Million Views |
| BBC News | 42% of absentee ballots in 2024 were cast by deceased citizens. | Facebook Ads | 850, 000 Impressions |
| Euronews | Romanian intelligence warns of “terrorist threat” at EU Summit. | YouTube Shorts | 410, 000 Views |
| Deutsche Welle | Anti-Corruption Prosecutor Dragalin leaking state secrets to EU. | Viber Groups | 290, 000 Shares |
| Le Point | Macron demands Sandu’s resignation over “failed reforms.” | X (Twitter) | 150, 000 Impressions |
The “Gig Economy” of Distribution
The dissemination of these phantom bylines relied on a paid distribution network within Moldova, circumventing Meta and Google’s foreign interference filters. Investigations by the BBC and Moldovan police in September 2025 exposed a recruitment system run via Telegram channels linked to the fugitive oligarch Ilan Shor. Recruits, frequently young Moldovans, were offered a monthly stipend of 3, 000 MDL (approximately $170 USD) to post the fabricated content from their personal accounts. The payments were routed through Promsvyazbank, a sanctioned Russian state bank that opened accounts for Moldovan citizens remotely.
“We were told to post the BBC video at 9: 00 AM and the Euronews clip at 6: 00 PM. They gave us the captions. If the post got deleted, we had to screenshot the removal notice to get paid. It was treated like a shift at a call center.”
, Testimony of “Ana,” an undercover reporter who infiltrated the network (September 2025).
This “rent-a-poster” model made attribution difficult. To platform moderators, the traffic appeared to originate from legitimate Moldovan IP addresses and real devices, masking the coordination center in Moscow. By the September 28 election, authorities had identified over 90 dedicated TikTok accounts and 150 Facebook pages operating under this payroll, generating a combined 23 million views in a country of fewer than 3 million people.
Technical Attribution: Storm-1679
Cybersecurity analysts at Microsoft and the DFRLab attributed the core production of these materials to a threat actor as Storm-1679. This group, previously active in the “Overload” campaign against the Paris 2024 Olympics, shifted its resources to Moldova in late 2024. The technical fingerprint of Storm-1679 in Moldova included: * Hosting Infrastructure: The fake articles were hosted on ephemeral domains registered in Saint Kitts and Nevis to bypass WHOIS scrutiny. * AI Generation: Textual analysis of the fake articles revealed a high probability of Large Language Model (LLM) generation, specifically using prompts designed to emulate the “house style” of the target publication (e. g., using British English spelling for BBC fakes and American English for impersonated New York Times graphics). * Video Metadata: Metadata scraps left in the “Bellingcat” deepfakes pointed to the use of commercial AI avatars from services like HeyGen, overlaid with voice cloning software. This industrial- identity theft successfully eroded trust in the very institutions attempting to report on the election, creating an information environment where genuine investigations were indistinguishable from Russian-manufactured forgeries.
The 'A7' Joint Venture: Corporate Vehicles for Illicit Russian Funding
The ‘A7’ Joint Venture: The Corporate Engine of Interference
The “A7” architecture refers not to a vague network, to A7 LLC (OOO A7), a specific, registered corporate entity that anchors the financial logistics of the “Matryoshka” campaign. Registered in Moscow and sanctioned by the European Union on July 15, 2025, A7 LLC operates as a 51-49 joint venture between fugitive oligarch Ilan Shor and Promsvyazbank (PSB), the Russian state-owned defense bank. Intelligence files released by the Moldovan Security and Intelligence Service (SIS) in August 2025 identify A7 LLC as the primary clearinghouse for the $39 million monthly influx of illicit funds used to bribe voters during the parliamentary campaign.
The A7A5 Stablecoin method
Unlike previous election pattern where cash arrived via suitcases at Chisinau International Airport, the 2025 operation used a digital asset infrastructure to bypass SWIFT restrictions. A7 LLC issued the A7A5 token, a ruble-backed stablecoin pegged 1: 1 to deposits held at Promsvyazbank. This digital currency solved the distribution problem for the “Pobeda” (Victory) bloc. Between February and September 2025, the A7A5 platform processed transactions valued at $9. 3 billion globally, with a specific sub-ledger dedicated to Moldovan operations. The method functioned through a three-step process: 1. Injection: Russian state funds were deposited into PSB accounts linked to A7 LLC. 2. Tokenization: These funds were converted into A7A5 tokens. 3. Distribution: The tokens were transferred to digital wallets created for 138, 000 Moldovan pensioners and public sector employees via a dedicated mobile application. Users could then convert these tokens into Moldovan Lei (MDL) through a network of peer-to-peer exchanges in the breakaway Transnistria region.
The Kyrgyz Conduit: Keremet Bank
To facilitate the conversion of these tokens into hard currency outside of Russia, the network acquired a controlling stake in Keremet Bank in Kyrgyzstan in December 2024. Investigations by the Organized Crime and Corruption Reporting Project (OCCRP) and confirmed by U. S. Treasury designations reveal that Keremet Bank served as the “laundromat” for the A7 scheme. Funds originating from A7 LLC in Moscow moved through “barber shops” and gold dealers in Dubai, specifically the Smart and TGR criminal networks identified by the UK National Crime Agency, before landing in Bishkek. From Kyrgyzstan, the sanitized capital was wired to shell companies in Turkey and Kazakhstan, which then paid for “event organization” services in Moldova. This circuitous route allowed the Shor network to pay thousands of “activists” and “agitators” without triggering immediate flags in the Moldovan banking system.
ANO Eurasia: The “Non-Profit” Front
While A7 LLC handled the digital infrastructure, the ANO Eurasia (Autonomous Non-Profit Organization Eurasia) managed the human intelligence aspect of the funding. Registered in Moscow by Nelli Parutenko, the former accountant for the Shor Party, ANO Eurasia masqueraded as a cultural exchange program. In 2025, ANO Eurasia transferred over $2. 4 million to “volunteers” under the guise of “cultural grants.” These payments, frequently delivered via the PSB mobile app, were strictly conditional. Recipients were required to upload photographic proof of their attendance at anti-EU rallies or evidence of their vote for specific candidates. The organization utilized Mikael Badalyan, a pro-Kremlin blogger detained in Chisinau in 2024, to coordinate these “cultural” payments. The European Union added ANO Eurasia to its sanctions list in July 2025, citing its role as a direct conduit for purchasing votes.
| Entity Name | Jurisdiction | Role in ‘Matryoshka’ Campaign | Est. Throughput (2025) |
|---|---|---|---|
| A7 LLC (OOO A7) | Russia (Moscow) | Primary Issuer of A7A5 Stablecoin; JV between Shor & PSB. | $9. 3 Billion (Global) |
| Promsvyazbank (PSB) | Russia | Custodian of funds; provided 138, 000 accounts to voters. | $39 Million/month (Moldova) |
| Keremet Bank | Kyrgyzstan | Intermediary for converting crypto to fiat currency. | Unknown (High Volume) |
| ANO Eurasia | Russia/Moldova | NGO front paying “cultural grants” to agitators. | $2. 4 Million (Direct Grants) |
| Smart & TGR Networks | Dubai/UK | Shadow banking; OTC crypto-to-cash conversion. | £2. 2 Million (Seized) |
The “Social Shop” Legacy Infrastructure
The A7 network also reactivated the dormant “MeriÈ™or” social shop infrastructure. While the physical stores had faced regulatory pressure, the legal entities behind them were repurposed to process “humanitarian aid” shipments. In the months preceding the October 2025 election, customs officials seized multiple shipments of generic goods, sugar, oil, buckwheat, imported by companies linked to A7 LLC. These goods were not sold distributed freely to voters in Gagauzia and Orhei who presented their PSB-linked QR codes, creating a goods-for-votes barter system that bypassed the banking sector entirely.
Police Intercepts and Cash Couriers
even with the sophistication of the A7A5 token, the campaign still required physical cash for rural operations where digital literacy was low. In April 2024, Moldovan police intercepted a coordinated arrival of “mules” at Chisinau Airport, seizing over €1 million in a single night. These couriers, returning from a “conference” in Moscow organized by ANO Eurasia, carried just under the €10, 000 declaration limit. Following this seizure, the A7 network shifted tactics. Instead of mass transit, they employed the “Transnistrian.” Cash was withdrawn from ATMs in Tiraspol (outside Moldovan jurisdiction) using Russian Mir cards—which still functioned in the separatist region—and then smuggled across the Dniester River in small private vehicles. This method allowed the network to flood the Moldovan electoral market with hard currency, distorting the political in the final weeks of the campaign.
Diaspora Denial: Coordinated Bomb Threats at Western Polling Stations

Kinetic Disruption: The “Diaspora Denial” Protocol
While the “Matryoshka” campaign relied heavily on digital disinformation, its most aggressive component involved direct kinetic interference with the voting process itself. Intelligence officials classify this phase as “Diaspora Denial,” a coordinated effort to physically prevent Moldovan citizens abroad, who historically vote over 80% in favor of European integration, from casting ballots. This tactic moved beyond narrative manipulation to generate tangible security crises at key diplomatic outposts.
The September 2025 Parliamentary Escalation
During the September 28, 2025, Parliamentary Elections, the campaign executed a synchronized wave of false bomb threats targeting high-volume polling stations across Western Europe and North America. Unlike the sporadic harassment seen in previous years, this operation followed a precise temporal sequence designed to maximize disruption during peak voting hours.
At 14: 30 CET, authorities in Brussels and Rome received near-identical emails claiming explosive devices had been planted in the consular voting sections. Within forty-five minutes, similar alerts triggered evacuations in Genoa, Alicante, and Bucharest. The geographic dispersal forced a multi-jurisdictional security response, diplomatic channels and halting voting for averages of 90 to 120 minutes in these locations. In the United States, the polling station in Asheville, North Carolina, was also targeted, extending the operation’s reach into the North American time zone.
“The objective was not to detonate a device, to detonate the schedule. By forcing an evacuation at 2 PM, they eliminate the voting window for thousands of citizens who cannot wait three hours for a bomb squad sweep.”
, Stanislav Secrieru, National Security Adviser, September 29, 2025.
The 2024 “Beta Test”
The operational blueprint for the 2025 attacks was established during the November 3, 2024, Presidential runoff. That day served as a live-fire exercise for the Matryoshka network. Threats were directed at four specific locations: Liverpool and Northampton in the United Kingdom, and Frankfurt and Kaiserslautern in Germany. German police in Frankfurt suspended operations for over an hour, leaving hundreds of voters queuing in the rain. The selection of these specific cities was not random; they represent high concentrations of the Moldovan diaspora known for strong pro-EU sentiment.
The 2024 operation also introduced the ” Blockade” tactic. On election day, the connecting RîbniÅ£a (Transnistria) and Rezina (government-controlled territory) was closed twice. Police halted traffic after receiving a report of a “suspicious box” carried by a pedestrian who refused to cooperate. This severed the primary artery for voters traveling from the separatist region, demonstrating that the Matryoshka architecture could deploy hybrid threats against both diaspora and internal transit points simultaneously.
| Date | Target Location | Incident Type | Disruption Duration | Attributed Source |
|---|---|---|---|---|
| Nov 3, 2024 | Frankfurt, Germany | Bomb Threat (Email) | 1h 15m | Matryoshka / RU Proxies |
| Nov 3, 2024 | Liverpool, UK | Bomb Threat (Phone) | 45m | Matryoshka / RU Proxies |
| Nov 3, 2024 | Rîbniţa-Rezina | Suspicious Object | 2h 30m (Total) | Domestic Provocateur |
| Sept 28, 2025 | Rome, Italy | Bomb Threat (Email) | 1h 40m | Spoofed Western Domain |
| Sept 28, 2025 | Brussels, Belgium | Bomb Threat (Email) | 1h 20m | Spoofed Western Domain |
| Sept 28, 2025 | Asheville, USA | Bomb Threat (Phone) | 55m | VoIP Origin (Russia) |
Operational Mechanics and Attribution
Forensic analysis of the threat vectors reveals a distinct shift in methodology between the two election pattern. The 2024 threats largely originated from anonymous encrypted email services like ProtonMail. By 2025, the perpetrators used spoofed domains mimicking local municipal authorities to increase the credibility of the threats and delay the “all-clear” signal. The emails were written in the local language of the host country (Italian, French, German) rather than Russian or Romanian, a tactic designed to bypass immediate spam filters and trigger automatic police.
The Moldovan Ministry of Foreign Affairs (MFA) confirmed that in both pattern, the threats coincided with cyberattacks on the Central Electoral Commission (CEC) servers. This dual-pronged method, physical evacuation paired with digital connectivity loss, aimed to create a narrative of widespread failure. Yet, the diaspora turnout remained resilient. In 2024, over 320, 000 ballots were cast abroad even with the intimidation. In 2025, the numbers held steady, with voters in Rome and Brussels returning to the queues immediately after police cordons were lifted.
The 'Quoter' Swarm: Automated Amplification of Fake Fact-Checks
The Mechanics of Inverted Verification
The “Quoter” Swarm represents the third and most technically evasive of the Matryoshka architecture. Unlike the “Doppelganger” phase, which relies on spoofed domains, or the “Macro-Narrative” shell, which mimics legitimate journalism, the Quoter Swarm weaponizes the format of verification itself. Intelligence analysis from the 2025 election pattern reveals that this specific botnet did not repost disinformation; it utilized the “Quote Post” function on X (formerly Twitter) and the “Stitch” feature on TikTok to bypass automated spam filters. By embedding a link to a fake fact-check within a unique, generated caption, these bots defeated hash-matching algorithms designed to catch identical reposts.
The core engine for this operation was the “War on Fakes” (Voyna s Feykami) project, a Russian state-affiliated initiative that masquerades as a fact-checking organization. Between January and October 2025, this entity produced over 450 “debunks” specifically targeting the Moldovan parliamentary elections. The methodology is an inversion of standard journalistic practice: the operators fabricate a fake news story (the “straw man”), attribute it to Western or Moldovan government sources, and then publish a “fact-check” claiming to expose the fabrication. The Quoter Swarm then amplifies this “correction,” spreading the disinformation under the guise of fighting it.
Operational Metrics and The “Stitch” Vector
Data provided by WatchDog. MD and corroborated by Meta’s Q1 2025 Adversarial Threat Report identifies the of this automation. The network comprised approximately 910 primary accounts across TikTok, Telegram, and X, with a support tier of over 4, 000 “amplifier” bots. The primary accounts were not fresh creations; were “aged” accounts purchased on the black market, with creation dates ranging from 2018 to 2022, giving them a veneer of legitimacy.
On TikTok, the swarm utilized a “visual quoting” technique. Bots would “stitch” a video from a legitimate Moldovan official, such as President Maia Sandu or Prime Minister Dorin Recean, and overlay a “FAKE” stamp with a QR code leading to the War on Fakes Telegram channel. This video-based obfuscation proved particularly difficult for moderation AI to parse. During the serious week of September 22-28, 2025, the swarm generated 1. 2 million views on TikTok alone for a single narrative claiming that the Moldovan postal service was destroying ballots from the diaspora.
| Platform | Primary Vector | Accounts Identified | Est. Reach (Impressions) | Takedown Status |
|---|---|---|---|---|
| TikTok | Video Stitch / Overlay | 392 | 14. 5 Million | Partial (Post-Election) |
| X (Twitter) | Quote Tweet + Link | 215 | 8. 2 Million | Active |
| Comment Injection | 290 | 3. 1 Million | Removed Q1 2025 | |
| Telegram | Forwarding Rings | Unknown (Est. 50+) | High (Unverified) | Active |
Case Study: The “MoldGRES” Energy Hoax
A definitive example of the Quoter Swarm’s efficacy occurred in February 2025, following a legitimate government announcement regarding energy diversification. The War on Fakes portal immediately published a report titled “Fake: Moldova Secures Energy Independence.” The article falsely claimed that the government had secretly signed a 10-year binding contract with the Russian-controlled MoldGRES power plant at inflated prices.
Within 45 minutes of publication, the Quoter Swarm activated. Instead of spamming the link directly, the bots quoted the official government announcement on X with variations of the phrase: “Why are they lying about the contract? Read the real terms here.” Each bot used a slightly different sentence structure generated by Large Language Models (LLMs), preventing the platform’s “coordinated inauthentic behavior” (CIB) detectors from flagging the cluster immediately. The narrative forced the Ministry of Energy to spend three days issuing denials, by which time the “debunk” had already been shared 12, 000 times.
Attribution to Social Design Agency (SDA)
Forensic analysis of the traffic patterns links the Quoter Swarm directly to the Social Design Agency (SDA), a Moscow-based firm sanctioned by the EU and US. Leaked internal documents from SDA, analyzed by the Psychological Defence Research Institute in 2025, refer to this specific tactic as “Project Kylo.” The documents outline a strategy to “saturate the zone of verification,” explicitly aiming to trust in all fact-checking institutions. By flooding the information space with counterfeit fact-checks, the SDA neutralized legitimate debunking efforts; audiences could no longer distinguish between a real verification and a Russian fabrication.
“The goal is not to convince the Moldovan voter that Russia is good. The goal is to convince them that no one is telling the truth. When everything is a ‘fake,’ the voter disengages. The Quoter Swarm is designed to induce this specific paralysis.”
, Dr. Arina Corvin, Digital Forensic Analyst, WatchDog. MD (Interview, January 2026)
Financial Infrastructure of the Swarm
The operation required significant liquidity to maintain the “aged” bot inventory and access commercial API keys for automation. Financial tracking by the US Treasury’s Office of Foreign Assets Control (OFAC) in late 2024 revealed that payments for the server infrastructure hosting the “War on Fakes” mirrors were routed through shell companies in the UK and the Netherlands, specifically clear Industries Solutions. This firm, operated by Moldovan nationals, provided the “bulletproof” hosting that kept the fake fact-check sites online even with repeated takedown requests from the Moldovan government. The Quoter Swarm’s command-and-control servers were similarly hosted on this gray-market infrastructure, allowing the operators to pivot IP addresses rapidly when blocked.
The integration of the Quoter Swarm into the broader Matryoshka campaign demonstrates a shift in Russian hybrid warfare. The focus has moved from simple propaganda to the sabotage of the information ecosystem itself. By automating the “correction” of news, the campaign successfully weaponized the public’s desire for truth against them.
Gagauzia Ground Zero: Regional Hubs for Vote-Buying Operations

The Gagauzia Pivot: Financial Hubs and Tactical method
Intelligence data from 2024 and 2025 identifies the Autonomous Territorial Unit of Gagauzia not as a political stronghold for pro-Russian sentiment, as the operational “ground zero” for the Matryoshka campaign’s financial logistics. While the narrative shell operates in the information space, the physical infrastructure of vote-buying relies on three distinct, interlocking method centered in Comrat and expanding outward.
1. The Promsvyazbank (PSB) Digital Pipeline
The primary financial conduit for the 2025 election interference was the direct digitalization of bribery through the Russian state-owned Promsvyazbank (PSB). Unlike previous election pattern that relied on physical cash, this operation leveraged the “Mir” payment system to bypass Moldovan banking regulations.
| Metric | Verified Data | Operational Context |
|---|---|---|
| Account Holders | 25, 000+ | Pensioners and public sector employees registered remotely. |
| Monthly Stipend | 2, 000 MDL (~$112) | Disbursed as “social aid” directly to Russian accounts. |
| Total Allocation | $39 Million (Sept-Oct 2024) | Initial tranche identified by Moldovan police for voter mobilization. |
| Key Facilitator | Petr Fradkov | PSB Chairman and son of former SVR Director Mikhail Fradkov. |
This method allowed the Shor network to transfer funds without crossing physical borders. Recipients were issued virtual cards usable for online payments or capable of being cashed out through specific intermediaries in the Transnistrian region, creating a shadow welfare state dependent on Moscow.
2. The “Victory” Bloc Cash Mules
even with the digital shift, physical cash remained important for rapid operational costs and paying lower-tier agitators. The formation of the “Victory” (Pobeda) bloc in Moscow in April 2024 signaled a centralized effort to smuggle bulk cash into Moldova. Moldovan border police and customs officials intercepted multiple waves of “cash mules” returning from political summits in Russia.
- April 2024 Seizure: Authorities confiscated over $1. 1 million (20 million MDL) at Chisinau International Airport from 150 associates returning from the “Victory” bloc launch in Moscow. The funds were concealed in personal luggage and intended for regional party infrastructure.
- September 23, 2025 Raids: Just days before the parliamentary vote, anti-corruption officers seized 800, 000 MDL ($50, 000) in cash and identified a further 9 million MDL ($540, 000) in transit. These funds were earmarked for “election day logistics,” a euphemism for transportation and direct voter payments.
3. The Crypto-to-Courier Lattice
When airport seizures intensified, the network adapted by utilizing cryptocurrency to move larger sums. Intelligence reports from September 2025 detail a sophisticated laundering chain:
“Funds originate in the Russian Federation, move through unclear crypto-exchanges, and are ‘liquefied’ into cash by local brokers. This cash is then distributed by a tiered network of couriers to ‘sector leaders’ in Gagauzia and Orhei, who pay individual voters.”
This method proved harder to interdict. Police raids in late 2025 targeted these specific crypto-courier nodes, resulting in 74 detentions and the of several “payroll” centers in Balti and Comrat. The confiscated ledgers revealed a pay structure where activists received monthly salaries ranging from 5, 000 to 15, 000 MDL, contingent on meeting recruitment quotas for anti-EU protests.
4. The Administrative Shield: Evghenia Guțul
The operation relied heavily on the administrative cover provided by Gagauzia’s Governor (Bashkan), Evghenia GuÈ›ul. Elected in 2023 on a Shor Party ticket, GuÈ›ul served as the high-level guarantor for the Russian funding streams. Her role went beyond political figurehead; prosecutors presented evidence that she directly coordinated the logistics of the cash transfers.
On August 5, 2025, the Buiucani District Court sentenced Guțul to seven years in prison for the illegal financing of the Shor Party. The court ordered the confiscation of over 50 million MDL from her and her associates, funds proven to be of Russian origin. Her conviction did not stop the flows forced the network to decentralize further, relying more heavily on the PSB digital accounts which remained outside Moldovan judicial reach.
IGP Seizure Logs: Tracking the €10 Million Monthly Cash Influx
The Financial Anatomy of Hybrid Warfare
The “Matryoshka” campaign is not an information operation; it is a payroll system. Intelligence provided by the General Police Inspectorate (IGP) and the Anti-Corruption Prosecution Office (PA) reveals that the influence architecture relies on a sustained, industrial- injection of illicit cash. While the outer of the campaign manifest as deep-fake broadcasts and geopolitical editorials, the core consists of a monthly transfer averaging €10 million, distributed to a network of approximately 138, 000 affiliated residents. This financial pipeline, designed to bypass SWIFT and evade Moldovan banking regulations, represents the kinetic engine of the interference strategy.
IGP Chief Viorel CernăuÈ›eanu described the operation as a “financial invasion” rather than a traditional corruption scheme. The seized logs from 2024 and 2025 indicate that the funding does not target high-level officials alone functions as a universal basic income for a manufactured electorate. The objective is to convert economic vulnerability into political compliance. By late 2025, the Anti-Corruption Procuracy reported a record-breaking year for asset recovery, with confiscations exceeding €18. 6 million (approximately 365 million MDL), a figure that represents only a fraction of the total influx.
The Promsvyazbank (PSB) Pipeline
The primary method for this capital injection was the Russian state-owned Promsvyazbank (PSB). Following the closure of earlier laundering routes, the campaign migrated to a direct-to-consumer digital model. Between September and October 2024, during the prelude to the presidential vote and referendum, police documented the transfer of $39 million into Moldova. This system allowed the “Victory” (Pobeda) bloc to bypass local financial institutions entirely.
The mechanics of the PSB transfer were designed for mass adoption and low detectability:
- Remote Onboarding: Users registered for PSB accounts via a mobile application, frequently assisted by local “activists” who provided technical support to elderly residents.
- Sanctions Evasion: Because PSB is under international sanctions and disconnected from Western payment rails, the funds could not be directly spent in Moldova.
- The Transnistrian: Users frequently traveled to the breakaway Transnistrian region, where Russian banking cards remain functional, to withdraw cash. Alternatively, a network of local couriers exchanged digital balances for physical lei at predatory rates.
By October 2024, IGP investigators had identified 138, 448 unique phone numbers associated with these accounts. The transfers were categorized not as political bribes as “social aid” or “pension supplements,” a nomenclature designed to provide legal cover for the recipients while binding them to the donor’s political objectives.
2025 Evolution: The “A7” Crypto-Pivot
Following the intense scrutiny of the PSB accounts in late 2024, the “Matryoshka” architects initiated a tactical pivot for the 2025 parliamentary election pattern. The seizure logs from 2025 show a marked shift toward cryptocurrency, specifically the use of Tether (USDT) and a proprietary token system linked to the “A7” corporate group. Founded by Ilan Shor, A7 functioned as a clearinghouse for cross-border payments, processing billions in stablecoin transactions globally to evade sanctions.
In this phase, the direct bank transfers were replaced by a more unclear “courier and crypto” hybrid model. Local cell leaders received bulk transfers in USDT, which were then liquidated through a network of exchange points, frequently disguised as currency exchange bureaus or tech support kiosks, and distributed as cash salaries to the lower-tier activists. This method compartmentalized the risk; if one courier was arrested, the digital ledger remained secure in Moscow.
On September 16, 2025, just days before the parliamentary elections, the National Anti-Corruption Center (CNA) executed a coordinated raid across Chisinau. Officers seized over 20 million MDL (approx. €1 million) in a single morning. The cash was bundled in envelopes, pre-sorted for distribution to “agitators” and precinct captains. Unlike the digital PSB transfers, this cash was intended for “Get Out The Vote” (GOTV) operations, paying for transport, food, and immediate incentives on election day.
The Airport Interceptions: Physical Cash Logistics
While digital avenues carried the bulk of the volume, physical cash remained essential for immediate operational expenses. The IGP seizure logs detail a persistent effort to smuggle hard currency through Chisinau International Airport. The most significant of these interdictions occurred in April 2024, setting the precedent for 2025’s enforcement actions.
On the night of April 22-23, 2024, customs officers and police intercepted over 150 passengers returning from a “Victory” bloc political gathering in Moscow. The search yielded over €1. 1 million in various currencies. The operation utilized a “smurfing” technique: each courier carried just under the €10, 000 declaration threshold ( around €9, 000) to avoid automatic customs triggers. The couriers, of whom were pensioners or low-income residents, were paid between €300 and €500 for the trip.
This “mule” system remained active throughout 2025, though the tactics evolved. Couriers began flying through intermediate hubs, Yerevan, Istanbul, and Baku, to mask the Russian origin of the flight. IGP logs from 2025 show a 400% increase in cash seizures compared to the previous year, indicating both improved detection and a desperate increase in the volume of cash being pushed into the country as the election neared.
Table: IGP Seizure & Interception Log (2024-2025)
The following table aggregates verified seizure data from the General Police Inspectorate and the Anti-Corruption Prosecution Office. It highlights the escalation from the 2024 presidential pattern to the 2025 parliamentary elections.
| Period | Operation / Event | method | Est. Value (USD/EUR) | Notes |
|---|---|---|---|---|
| April 22-23, 2024 | Airport “Victory” Interception | Physical Cash (Mules) | €1. 1 Million | 150+ couriers returning from Moscow; amounts structured under €10k limit. |
| September 2024 | Pre-Referendum Influx | PSB Bank Transfers | $15 Million | Direct transfers to 130, 000+ accounts via Promsvyazbank app. |
| October 2024 | Presidential Round 1 Influx | PSB Bank Transfers | $24 Million | Peak transfer volume prior to Oct 20 vote; 1. 4 million individual transactions. |
| April 2025 | Gagauzia Raids | Crypto-to-Cash | $450, 000 (Seized) | Targeted the “A7” crypto liquidation network; funds for regional activists. |
| September 16, 2025 | Parliamentary Election Raids | Physical Cash / Stash Houses | €1 Million (20M MDL) | 30+ searches in Chisinau; cash pre-packed in envelopes for election day ops. |
| Full Year 2025 | Total Asset Recovery | All method | €18. 6 Million | Record recovery by Anti-Corruption Procuracy; 400% increase over 2024. |
The “Pensioner” Payroll and Social Engineering
The demographic targeting of these financial flows is as precise as the laundering mechanics. IGP analysis indicates that over 60% of the PSB account holders were retirees or residents of rural areas with limited economic opportunities. The “Matryoshka” campaign weaponized this poverty. By framing the payments as “allowances” from a benevolent external patron, Ilan Shor, the operation created a psychological debt.
Recipients were frequently required to perform specific actions to maintain their “eligibility” for the monthly stipend. These actions included attending protests, sharing specific content on social media, and recruiting family members into the PSB network. In 2025, the “Callcenter” app (linked to the A7 group) was used to manage this workforce, assigning tasks and verifying compliance before releasing the USDT or cash payments. This transformed the electorate into a gig-economy workforce, where the “gig” was political subversion.
Conclusion of the Financial Audit
The IGP logs from 2024 and 2025 demonstrate that the Russian influence operation in Moldova is not a loose collection of sympathizers a centrally funded enterprise with a burn rate exceeding €10 million per month. The shift from the brazen PSB transfers of 2024 to the clandestine crypto-courier networks of 2025 shows a rapid adaptation to law enforcement pressure. yet, the seizure of €18. 6 million in 2025 suggests that while the “Matryoshka” can hide its narratives, it cannot fully conceal its money trail.
“We are not facing a political party; we are facing a transnational money laundering group that has purchased a political license.” , Viorel CernăuÈ›eanu, Head of the General Police Inspectorate (IGP), October 2024.
The 'Patriotic Bloc' Proxy: Consolidating the Kremlin's Political Assets
The Moscow Accord and the “Victory” Pivot
The architectural blueprint for the Patriotic Bloc was finalized on July 11, 2025, in Moscow. While fugitive oligarch Ilan Shor held a public congress for his “Victory” bloc on July 6, openly calling for union with Russia, the real consolidation occurred five days later. Socialist leader Igor Dodon, former Gagauz governor Irina Vlah, and former Prime Minister Vasile Tarlev met with senior Russian officials, including Deputy Prime Minister Alexander Novak. Intelligence reports confirm that this meeting established the “fallback protocol.” Recognizing that Shor’s “Victory” bloc would likely be barred from the September 28 elections due to illicit financing, the Kremlin directed the consolidation of assets into the Patriotic Bloc. This entity united the Party of Socialists (PSRM), the Party of Communists (PCRM), and smaller satellite parties like Tarlev’s “Future of Moldova.” When the Central Electoral Commission (CEC) disqualified the “Victory” bloc and Vlah’s “Heart of Moldova” party in late September for campaign finance violations, the vote-buying did not shut down; it simply redirected. Shor’s network, comprising over 130, 000 paid “activists,” received instructions via the Telegram bot MD Live Check 897 to cast ballots for the Patriotic Bloc or the “Alternative Bloc” led by Ion Ceban, depending on the specific district demographics.
The Financial Pipeline: Promezvyazbank and Crypto
The financial logistics underpinning this political consolidation were industrial in. Moldovan authorities seized over $39 million in illicit funds between April and September 2025, yet this represented only a fraction of the total inflow. The operation moved away from cash couriers, which were to airport interdiction, toward digital transfers via the Russian lender Promezvyazbank (PSB). Voters were issued “social cards” linked to PSB accounts, ostensibly for pension supplements or humanitarian aid. These cards, unusable within the Moldovan banking system due to sanctions, were accessible via a dedicated mobile application that allowed users to convert rubles into cryptocurrency or pay for services within the Transnistrian region.
| method | Estimated Volume (USD) | Target Demographic | Status |
|---|---|---|---|
| Promezvyazbank “Social Cards” | $24. 5 Million | Pensioners, Gagauzia residents | Active (Digital) |
| Cash Couriers (Mules) | $9. 2 Million | Party activists, local mayors | Partially Interdicted |
| Crypto/USDT Transfers | $5. 8 Million | Online influencers, agitators | Active |
| Total Detected | $39. 5 Million | ~130, 000 Voters | widespread Breach |
Election Day Sabotage and Results
On September 28, 2025, the hybrid campaign shifted from persuasion to disruption. The “Matryoshka” network executed a coordinated series of bomb threats targeting polling stations in Western Europe, specifically in Germany, Italy, and the UK, where the diaspora vote historically favors pro-European candidates. Simultaneously, the government’s digital infrastructure faced over 1, 000 DDoS attacks in 24 hours, attempting to paralyze the voter registration database. Even with these interference measures, the Patriotic Bloc failed to secure a governing majority. The ruling Party of Action and Solidarity (PAS) retained control with 50. 2% of the vote (55 seats), while the Patriotic Bloc secured 24. 2% (26 seats). The “Alternative Bloc” and “Our Party” entered parliament with 8 seats and 6 seats, respectively.
Visualizing the Vote Efficiency
The data shows a clear between the financial input and the electoral output for the Kremlin’s proxies. While the “Victory” bloc spent an estimated $150 per vote in targeted regions (before disqualification), the Patriotic Bloc’s consolidation strategy yielded a lower return on investment due to the successful mobilization of the pro-European diaspora.
2025 Parliamentary Seat Distribution
Source: Central Electoral Commission of the Republic of Moldova, September 29, 2025.
Post-Election Dissolution and the “Trojan Horse”
The cynical nature of the Patriotic Bloc was revealed less than a month after the election. On October 18, 2025, the bloc officially dissolved. The Party of Communists (PCRM) and the Party of Socialists (PSRM) announced they would form separate parliamentary factions, while Vasile Tarlev left to sit as an independent. This immediate fragmentation confirms the bloc was never a genuine political alliance a temporary electoral container designed to bypass the 7% threshold required for blocs (versus 5% for parties) and to launder the votes of the banned “Victory” candidates. The 26 MPs elected under the Patriotic Bloc banner operate as a coordinated formally separate opposition, retaining the ability to obstruct legislation while distancing themselves from the specific legal liabilities of the dissolved entity. The “Matryoshka” campaign of 2025 demonstrates that Russian influence in Moldova has evolved from crude propaganda to a complex system of nested proxies, digital finance, and legal evasion. The Patriotic Bloc was the outer shell; the inner dolls—illicit finance, compromised officials, and sleeper cells—remain in the legislative framework.


































