We forensically map the technical infrastructure behind disinformation campaigns. From a flagged site to the actor network behind it.
Disinformation campaigns are typically detected at the narrative level. But the technical infrastructure behind them, such as domains, hosting, DNS patterns, and registration chains, often goes unexamined.
This leaves a blind spot between information operations and cyber threat intelligence. The actors running coordinated fake news sites frequently share infrastructure with entities involved in conventional cyber operations. Without forensic analysis of that infrastructure layer, the connection stays invisible.
Domain registration chains, hosting provider identification, shared infrastructure mapping across related domains, historical DNS records, and certificate transparency analysis.
Matching infrastructure patterns against known threat actor tooling and techniques. Identifying when disinformation sites share technical signatures with previously attributed operations.
Connecting infrastructure findings to assess coordinated activity, identify operational patterns, and build the forensic evidence base for threat actor attribution.
All findings delivered as structured threat intelligence in STIX 2.1 format, directly compatible with MISP, OpenCTI, and standard CTI platform workflows.
We take suspected disinformation sites from your existing pipeline and deliver full infrastructure forensic reports with STIX 2.1 formatted intelligence products.
Structured presentation of forensic results to your analysts and stakeholders. What we found, what the infrastructure patterns reveal, and what it means for your threat picture.
Hands-on training in OSINT infrastructure forensics methodology. Your analysts learn to trace registration chains, identify hosting clusters, and produce actionable intelligence.
Assessment of disinformation infrastructure targeting your sector or region, based on our ongoing detection work and research findings.
Documented methodology. OSINT methodology for identifying and technically fingerprinting disinformation infrastructure, developed through real-world detection and attribution work.
Standards-based output. Intelligence delivered in STIX 2.1 format, directly compatible with MISP, OpenCTI, and existing CTI workflows.
European threat landscape. Focused on hybrid threats and influence operations targeting European infrastructure and institutions.
A joint investigation by the DFRLab and Erebus identified Polskanews.org, a Polish-language website launched in August 2020, as a likely foreign influence operation masquerading as a domestic Polish news outlet.
Erebus retrieved and analyzed 3,278 archived snapshots of the site spanning 2020 to 2025. The forensic analysis uncovered Russian-language metadata embedded in the site's HTML, phonetic Cyrillic substitutions consistent with a native Russian-speaking operator, Cyrillic filenames in upload directories, and operator accounts recovered through WordPress artifacts. Editorial analysis exposed fabricated personas using photos stolen from Russian social media.
Temporal analysis showed publishing activity clustered within Minsk and Moscow business hours, and the site's most hostile sections stopped publishing four days after Poland's October 2023 parliamentary elections. The convergence of linguistic, technical, operational, and behavioral evidence indicates a coordinated operation targeting Polish public discourse and democratic institutions.
Read the full investigation at DFRLab →A second joint investigation with the DFRLab examines the website network behind Storm-1516 influence operations targeting Armenia. A modern influence operation does not run one website; it runs a fleet. Looking at any single site reveals little, so the forensic question is relational: which of these sites carry the fingerprints of the same hand?
Erebus extracted coordination signals across four layers of the web stack, from hosting and registration to code and content, and correlated them in a STIX 2.1 evidence graph. DOM structural fingerprinting and a distinctive filename-generator alphabet, reproduced across all eighteen sites of one amplifier cluster, bind seemingly independent outlets into operational clusters built with shared tooling.
Every finding carries an explicit confidence label, and every claim is traceable to the underlying evidence in the project graph. The method is written to be reproducible: a reader can take an unknown set of suspicious sites and run the same sequence of checks to surface the network behind them.
Publication link coming soonWe work with government agencies, defense organizations, and threat intelligence teams across Europe. If you're dealing with hybrid threats targeting your infrastructure or sector, we should talk.