OSINT Researchers Trace GRU-Linked Information Operation Targeting the Baltics

DFRLab researchers mapped a Storm-1516 operation targeting the Baltic states, uncovering cloned news sites, fabricated NATO stories and a multilingual amplification network spanning X, Telegram and other platforms.

OSINT Researchers Trace GRU-Linked Information Operation Targeting the Baltics
Illustration. (Credit: AdriaDefense.com)

A Russian-linked information operation has expanded its focus to the Baltic states, using cloned media websites, manipulated videos and networks of social media accounts to spread false claims involving NATO forces, Ukrainian troops and Baltic political leaders.

Researchers at the Atlantic Council’s Digital Forensic Research Lab, or DFRLab, identified four separate campaigns linked to accounts previously associated with Storm-1516, an information manipulation operation that has been publicly connected to Russia’s military intelligence ecosystem.

The campaigns ran between late July and mid-August and targeted Estonia, Latvia and Lithuania.

DFRLab said the operation displayed patterns previously associated with Storm-1516, including the impersonation of established news organizations and the use of fabricated video reports carrying legitimate media branding.

Fake NATO casualties and cloned defense media

One of the false narratives claimed that a Ukrainian soldier had opened fire during a military exercise in Latvia, killing three NATO personnel before taking his own life.

The fabricated story was distributed through a video carrying Euronews branding, according to DFRLab. Researchers found no legitimate report supporting the claim.

Another campaign claimed that debris from a Ukrainian drone shot down over Estonia had damaged two Portuguese Air Force F-16 fighter jets.

To give the story credibility, operators used a website designed to imitate defense publication The Defense Post, replacing the legitimate .com domain with a .eu address while reproducing the publication’s visual identity.

The false claim was then amplified by several social media accounts previously observed participating in Storm-1516 campaigns.

A third operation falsely linked the presidents of Estonia and Lithuania to Jeffrey Epstein’s trafficking network, using an imitation of EUobserver and a fabricated video carrying the outlet’s branding.

The fourth claimed that only 25% of young Latvians called for national defense service were reporting for mandatory medical examinations. Latvian reporting cited by DFRLab indicated that the actual figure was around two-thirds.

OSINT analysis maps the distribution network

The investigation offers a detailed look at how open-source intelligence techniques can be used to reconstruct an information operation after it begins spreading.

DFRLab researchers identified 275 mentions of the four narratives across X, Telegram, Facebook, TikTok, Instagram, VKontakte and websites belonging to the Pravda Network.

Researchers used social-media monitoring platforms including Osavul, Junkipedia and BuzzSumo, combined with advanced web searches and native platform search tools.

Each post was categorized according to its account, platform, language, publication time, engagement, distribution pattern and links to other content.

The team then analyzed 1,651 unique X accounts that had reposted the original content.

Of those, 105 accounts, roughly 6.4%, amplified more than one of the four campaigns. Eleven accounts amplified three separate narratives, although researchers said the available evidence was insufficient to conclude that all of the amplifying accounts were coordinated or inauthentic.

That distinction is important: the investigation identified repeat amplification patterns, but it did not establish that every account spreading the material was controlled by Storm-1516.

From X to Telegram and across languages

X served as the primary point of introduction and generated the strongest engagement across the four campaigns.

Telegram played a significant role in further distributing two of the narratives, including the fabricated story about NATO soldiers being killed during the Latvian exercise. The content subsequently appeared on Facebook and TikTok, although DFRLab found significantly lower levels of engagement on those platforms.

The campaigns also crossed linguistic boundaries.

English remained the principal language, but researchers identified content or amplification in Russian, Portuguese, Spanish, Italian, French, German, Czech, Serbian and Turkish.

The operation’s ability to move the same narratives between countries and languages is one of the main conclusions of the investigation.

Pravda Network also appears

Researchers also detected activity from the Pravda Network, a broader pro-Kremlin content ecosystem that has previously drawn attention for publishing large volumes of material potentially accessible to search engines and large language models.

Pravda-linked websites and VKontakte accounts amplified the narratives concerning the alleged deaths of NATO troops and Latvian military conscription.

Some of that content was targeted not only at European audiences but also toward users in countries including Australia and Japan.

Storm-1516 has targeted multiple Western countries

Storm-1516 has been tracked by researchers since at least 2023 and was formally given its current designation in 2024.

Previous investigations have identified campaigns targeting the United States, Germany, France, Moldova, Armenia and Ukraine.

DFRLab notes that the operation’s underlying infrastructure and participants have been linked in public reporting and government assessments to actors associated with Russian influence operations and military intelligence.

Earlier this year, DFRLab and partner organizations documented 45 Storm-1516 campaigns targeting Armenia, demonstrating how cloned websites, fabricated stories and coordinated distribution networks could be identified using website forensics and open-source investigation techniques.

Baltics become the latest target

The latest investigation suggests that the Baltic security environment is increasingly becoming a target for the same information-operation infrastructure.

The four narratives shared a common theme: weakening confidence in Baltic governments, NATO forces or continued support for Ukraine.

DFRLab concluded that the campaigns demonstrate the need for intelligence and security organizations to monitor information operations across languages and platforms rather than treating each national information environment in isolation.

For OSINT practitioners, the investigation also provides a practical example of how domain analysis, account histories, repost patterns and cross-platform monitoring can expose the infrastructure and distribution mechanisms behind an influence operation.