Signal
Submitted
Apr 28, 2026, 14:01 UTC
Russian-backed 'Doppelgänger' disinformation campaign uses European firms, including a German hosting company and UK shell companies, to spread fake news targeting Germany, France and others since 2022.
Since 2022, a sophisticated Russian disinformation campaign dubbed 'Doppelgänger' has been spreading fake news via cloned news sites mimicking reputable outlets like Spiegel and Le Monde. The campaign uses thousands of disposable internet domains, primarily hosted and routed through a network of companies in the UK, Russia, Germany, Finland, and the US. Key actors include TNSecurity Ltd, a UK-registered mailbox company involved in forwarding hundreds of propaganda domains dated August 29, 2023, and Aeza, a young Russian St. Petersburg-based hosting provider owning approximately 40,000 servers valued at around 2.4 million euros. Aeza is linked to several affiliate companies and serves as a core forwarding hub for Doppelgänger infrastructure. The German firm Aurologic, operating the Tornado data center near Frankfurt, provides internet backbone services facilitating Doppelgänger’s traffic, despite EU sanctions on related Russian entities. Finnish branch of German hosting giant Hetzner runs critical servers that host the campaign’s core domains capable of geo-targeting visitors, particularly those physically located in Germany, thus ensuring targeting effectiveness while obfuscating traffic origins. The campaign employs complex multi-stage domain redirections with bots on platforms Facebook and X distributing thousands of throwaway URLs leading to intermediate and final fake news sites. Despite detection and reporting to authorities, European and platform responses have so far failed to shut down this infrastructure. The research is based on analysis by Swedish digital forensics NGO Qurium, Canadian cyber intelligence firm Hyas, Spamhaus, and interviews with involved companies. Doppelgänger aims to foment distrust and anti-Ukraine sentiment within EU populations through fake articles falsely claiming, for example, German retirees funding weapons aid at their expense. The article highlights challenges in combatting disinformation networks embedded within legitimate European IT infrastructure and raises questions about the effectiveness of current regulatory and law enforcement actions.
Confidence: High
The article explicitly documents a Russian hybrid warfare disinformation campaign using European infrastructure to disseminate falsified news and influence populations, identifying named Russian companies and EU-based firms facilitating the campaign, including hosting and domain forwarding. This meets criteria for an aggressive signal.
Source URL
https://correctiv.org/faktencheck/russische-desinformation/2024/07/11/doppelgaenger-wie-russland-eu-unternehmen-fuer-desinformation-und-propaganda-nutzt
Source reliability
A
Info credibility
6
Event time
Jul 11, 2024, 06:00 UTC
Event time confidence
exact
Location
Frankfurt am Main, Germany
Primary actor
TNSecurity Ltd
Country
Unknown
Tags
Russian disinformation, Doppelgänger campaign, Cyber propaganda, Fake news, European hosting, TNSecurity, Aeza, Aurologic, Hetzner, sanctions, Social Design Agency, Struktura, Information operations, Facebook, X (Twitter), Domains hijacking, Malware infrastructure
Nodes
Node 1: Borders, Node 2: 5th Column