Hybrid Threat Intelligence

Detection and attribution of disinformation infrastructure

We forensically map the technical infrastructure behind disinformation campaigns. From a flagged site to the actor network behind it.

Disinformation campaigns are typically detected at the narrative level. But the technical infrastructure behind them, such as domains, hosting, DNS patterns, and registration chains, often goes unexamined.

This leaves a blind spot between information operations and cyber threat intelligence. The actors running coordinated fake news sites frequently share infrastructure with entities involved in conventional cyber operations. Without forensic analysis of that infrastructure layer, the connection stays invisible.

Infrastructure forensics for hybrid threats

Infrastructure Extraction

Domain registration chains, hosting provider identification, shared infrastructure mapping across related domains, historical DNS records, and certificate transparency analysis.

Fingerprint Correlation

Matching infrastructure patterns against known threat actor tooling and techniques. Identifying when disinformation sites share technical signatures with previously attributed operations.

Attribution Analysis

Connecting infrastructure findings to assess coordinated activity, identify operational patterns, and build the forensic evidence base for threat actor attribution.

STIX 2.1 Intelligence Production

All findings delivered as structured threat intelligence in STIX 2.1 format, directly compatible with MISP, OpenCTI, and standard CTI platform workflows.

How we work with you

Forensic Analysis

We take suspected disinformation sites from your existing pipeline and deliver full infrastructure forensic reports with STIX 2.1 formatted intelligence products.

Findings Debrief

Structured presentation of forensic results to your analysts and stakeholders. What we found, what the infrastructure patterns reveal, and what it means for your threat picture.

Technical Workshop

Hands-on training in OSINT infrastructure forensics methodology. Your analysts learn to trace registration chains, identify hosting clusters, and produce actionable intelligence.

Threat Landscape Briefing

Assessment of disinformation infrastructure targeting your sector or region, based on our ongoing detection work and research findings.

Why us

01

Documented methodology. OSINT methodology for identifying and technically fingerprinting disinformation infrastructure, developed through real-world detection and attribution work.

02

Standards-based output. Intelligence delivered in STIX 2.1 format, directly compatible with MISP, OpenCTI, and existing CTI workflows.

03

European threat landscape. Focused on hybrid threats and influence operations targeting European infrastructure and institutions.

Joint investigations

Polskanews.org: a foreign influence operation masquerading as Polish news

With the Atlantic Council's DFRLab · March 31, 2026

A joint investigation by the DFRLab and Erebus identified Polskanews.org, a Polish-language website launched in August 2020, as a likely foreign influence operation masquerading as a domestic Polish news outlet.

Erebus retrieved and analyzed 3,278 archived snapshots of the site spanning 2020 to 2025. The forensic analysis uncovered Russian-language metadata embedded in the site's HTML, phonetic Cyrillic substitutions consistent with a native Russian-speaking operator, Cyrillic filenames in upload directories, and operator accounts recovered through WordPress artifacts. Editorial analysis exposed fabricated personas using photos stolen from Russian social media.

Temporal analysis showed publishing activity clustered within Minsk and Moscow business hours, and the site's most hostile sections stopped publishing four days after Poland's October 2023 parliamentary elections. The convergence of linguistic, technical, operational, and behavioral evidence indicates a coordinated operation targeting Polish public discourse and democratic institutions.

Read the full investigation at DFRLab →

The website infrastructure behind Storm-1516 operations targeting Armenia

With the Atlantic Council's DFRLab · Forthcoming

A second joint investigation with the DFRLab examines the website network behind Storm-1516 influence operations targeting Armenia. A modern influence operation does not run one website; it runs a fleet. Looking at any single site reveals little, so the forensic question is relational: which of these sites carry the fingerprints of the same hand?

Erebus extracted coordination signals across four layers of the web stack, from hosting and registration to code and content, and correlated them in a STIX 2.1 evidence graph. DOM structural fingerprinting and a distinctive filename-generator alphabet, reproduced across all eighteen sites of one amplifier cluster, bind seemingly independent outlets into operational clusters built with shared tooling.

Every finding carries an explicit confidence label, and every claim is traceable to the underlying evidence in the project graph. The method is written to be reproducible: a reader can take an unknown set of suspicious sites and run the same sequence of checks to surface the network behind them.

Publication link coming soon

Contact

We work with government agencies, defense organizations, and threat intelligence teams across Europe. If you're dealing with hybrid threats targeting your infrastructure or sector, we should talk.

Location Stockholm, Sweden