CopyCop Targets AI Investment in Armenia
The Russian influence network CopyCop (Storm-1516) targeted the joint US-Armenian Firebird AI data center in Hrazdan, Armenia, through three documented media impersonation campaigns between June 24 and July 13, 2026. The campaigns used typosquatting domains impersonating TechCrunch and Gizmodo, plus fabricated Iranian military messaging, to disseminate false narratives about earthquake risk, power grid instability, and military targeting of the facility. The third instance achieved over 1.6 million combined views, demonstrating growing reach. CSS stylesheet hash analysis linked the infrastructure to previously confirmed CopyCop domains, and the same amplifier accounts were reused across campaigns targeting different Armenia-linked Western investment projects.
- domaineuronews[.]us[.]comPreviously confirmed CopyCop infrastructure used for media brand impersonation. Linked to tech-crunch.org via CSS stylesheet hash analysis.
- domaingizmodo[.]ccTyposquatting domain impersonating Gizmodo, registered June 26, 2026 via Namecheap and hosted via Hostinger (AS47583). Hosted fabricated video impersonating journalist Webb Wright claiming power grid instability threatened Firebird facility viability.
- domainhaaretz24[.]comPreviously confirmed CopyCop infrastructure used for media brand impersonation. Linked to tech-crunch.org via CSS stylesheet hash analysis.
- domainpolitico-24[.]comPreviously confirmed CopyCop infrastructure used for media brand impersonation. Linked to tech-crunch.org via CSS stylesheet hash analysis.
- domaintech-crunch[.]orgTyposquatting domain impersonating TechCrunch, registered June 21, 2026 via Namecheap (AS22612). Hosted fabricated video claiming magnitude 7.4 earthquake threat to Firebird facility. CSS stylesheet hash analysis linked this domain to confirmed CopyCop infrastructure.
Detection / Hunteropenrouter
What Happened
A Russian propaganda network called CopyCop created fake news videos and articles to undermine a major American-Armenian artificial intelligence project in Armenia. The network impersonated well-known media outlets like TechCrunch and Gizmodo using look-alike websites, and even fabricated a fake Iranian military threat video claiming the data center was a military target. The fake content was spread through coordinated social media accounts and reached over 1.6 million views. This matters because it is part of a broader Russian effort to prevent Armenia from building closer ties with Western countries. Organizations involved in Western-backed projects in Armenia should monitor for brand impersonation and coordinated disinformation campaigns, and media outlets should watch for unauthorized use of their names and logos.
Key Takeaways
- CopyCop (Storm-1516) conducted three media impersonation campaigns targeting the Firebird AI data center in Hrazdan, Armenia between June 24 and July 13, 2026, using fabricated earthquake risk, power grid instability, and Iranian military threat narratives
- The campaign used typosquatting domains registered via Namecheap and hosted via Hostinger, with CSS stylesheet hash analysis linking the domains to previously confirmed CopyCop infrastructure
- Third instance achieved over 1.6 million combined views across amplifier accounts, indicating substantial growth in audience reach compared to earlier instances
- CopyCop previously targeted the TRIPP corridor project in March 2026, demonstrating a persistent and redeployable social media amplifier network for laundering influence narratives
- Future targets likely include the Metsamor Nuclear Power Plant replacement negotiations and the US-Armenia critical minerals framework, both of which give Russia direct commercial stakes in opposing outcomes
Affected Systems
- Firebird AI data center (Hrazdan, Kotayk Province, Armenia)
- TechCrunch brand (impersonated via typosquatting domain)
- Gizmodo brand (impersonated via typosquatting domain)
- Iranian state messaging channels (impersonated for fabricated military threat)
- Western social media platforms (used for amplification)
- TRIPP corridor infrastructure project
- Metsamor Nuclear Power Plant (potential future target)
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Reconnaissance: CopyCop identifies high-visibility Western investment projects in Armenia (Firebird AI data center, TRIPP corridor) tied to Armenia's westward geopolitical realignment
- Infrastructure Development: Register typosquatting domains via Namecheap (AS22612) and host via Hostinger (AS47583), reusing CSS stylesheets linked to previous CopyCop infrastructure
- Content Creation: Fabricate media reports impersonating legitimate outlets (TechCrunch, Gizmodo) or state messaging (Iranian military), producing videos with false narratives about earthquake risk, power grid instability, or military targeting
- Amplification: Deploy known CopyCop-linked social media amplifier accounts to disseminate fabricated content across Western social media platforms
- Impact: Narratives reach growing audiences (up to 1.6 million combined views by third instance), undermining public confidence in targeted projects and advancing pro-Russian geopolitical objectives
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Recorded Future Intelligence Operations Platform, Recorded Future Brand Intelligence
No detection rules are provided in the article. Recorded Future customers can use the Intelligence Operations Platform to track CopyCop infrastructure and amplifier accounts, and Brand Intelligence to identify impersonation attempts targeting media brands.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | None | This is an influence operation involving domain registration, content fabrication, and social media amplification. Endpoint detection is not applicable as no malware or intrusions are described. |
| Network Visibility | Low | Network monitoring could detect access to typosquatting domains if users in the organization visit them, but the primary attack surface is public social media and web infrastructure outside the defender's network perimeter. |
| Detection Difficulty | Hard | Influence operations use legitimate infrastructure (domain registrars, hosting providers, social media platforms) and mimic legitimate media outlets. Attribution requires correlation across domain registration patterns, CSS fingerprinting, amplifier account reuse, and content analysis. Defenders lack visibility into the adversary's infrastructure development and amplification activities on third-party platforms. |
Required Log Sources
- DNS query logs for typosquatting domain resolution
- Web proxy logs for access to impersonation domains
- Brand monitoring feeds for domain registration alerts
- Social media monitoring platforms for amplifier account activity
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Newly registered domains that closely resemble legitimate media brand names may be CopyCop infrastructure used for impersonation campaigns. Consider monitoring domain registration feeds for typosquatting patterns against known media brands. | Domain registration WHOIS data, passive DNS, certificate transparency logs | Resource Development | Medium — typosquatting domains are also used by cybercriminals, ad fraud operators, and unrelated actors |
| Multiple domains sharing identical CSS stylesheet hashes may indicate a common influence operation infrastructure set. Consider correlating stylesheet hashes across newly registered domains impersonating media brands. | Web content analysis, URLscan.io results, archived web content | Resource Development | Low — shared CSS hashes across impersonation domains is a strong indicator of common infrastructure |
| Social media accounts that repeatedly amplify narratives targeting specific geopolitical topics (Armenia-Western investment, Russian interests) may be part of the CopyCop amplifier network. Consider tracking account reuse across campaigns. | Social media platform APIs, threat intelligence feeds tracking known amplifier accounts | Amplification | Medium — legitimate users may share similar content, requiring correlation with known amplifier accounts |
Control Gaps
- Traditional security controls (EDR, SIEM, IDS) do not detect influence operations conducted on external social media and web infrastructure
- Brand protection monitoring may not cover typosquatting domains registered days before campaign launch
- DNS filtering may not block newly registered impersonation domains before they are flagged by threat intelligence feeds
Key Behavioral Indicators
- Domains registered within days of fabricated content publication via Namecheap (AS22612)
- Hosting via Hostinger (AS47583) with patterns consistent with previous CopyCop operations
- CSS stylesheet hashes matching previously confirmed CopyCop infrastructure
- Reuse of known amplifier accounts across multiple campaigns targeting different Armenia-linked projects
- Content narratives targeting Western investment projects in Armenia with fabricated risk or threat claims
False Positive Assessment
Low — the domains are specifically identified as CopyCop infrastructure through CSS stylesheet hash correlation and amplifier account reuse. The social media accounts are tracked as known CopyCop amplifiers across multiple campaigns.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking the identified typosquatting domains (tech-crunch.org, gizmodo.cc, haaretz24.com, euronews.us.com, politico-24.com) on DNS filtering and web proxy infrastructure if applicable to your environment.
- If your organization is a media brand mentioned in this report or similar to those impersonated, consider engaging brand protection and takedown services to remove infringing domains and accounts.
- If your organization operates in Armenia or is involved in Western investment projects there, consider monitoring the identified social media amplifier accounts for emerging narratives targeting your brand or projects.
Infrastructure Hardening
- Consider implementing domain monitoring alerts for newly registered domains that typosquat your organization's brand name across major TLDs.
- Evaluate whether your organization's public-facing projects in sensitive geopolitical regions warrant proactive monitoring for coordinated disinformation campaigns.
- If applicable, consider registering defensive domain variations to reduce the available surface for typosquatting impersonation.
User Protection
- Consider educating employees who interact with external media or public communications to verify the authenticity of news articles referencing organizational projects, especially those from unfamiliar domains.
- If your organization is named in fabricated content, consider establishing a verification channel for stakeholders to confirm the authenticity of official communications.
Security Awareness
- Consider incorporating awareness of influence operations and brand impersonation into existing security awareness programs, particularly for employees in communications, PR, and executive roles.
- If your organization operates in geopolitically sensitive regions, consider briefing relevant staff on the risk of coordinated disinformation campaigns targeting organizational projects.
MITRE ATT&CK Mapping
Resource Development
Additional IOCs
- Other:
@Truthtellerftm- CopyCop-linked social media amplifier account used in both the June 24 TechCrunch impersonation and the June 30 Gizmodo impersonation campaigns targeting Firebird.@GreenwaySh57854- CopyCop-linked social media amplifier account used in the June 24 TechCrunch impersonation campaign targeting Firebird.@Ibrahim_alFiqar- CopyCop-linked social media amplifier account used in the June 24 TechCrunch impersonation campaign targeting Firebird.@DangerousThinkg- CopyCop-linked social media amplifier account used in the June 30 Gizmodo impersonation campaign targeting Firebird.@TheWyteRabbit1- CopyCop-linked social media amplifier account used in the June 30 Gizmodo impersonation campaign targeting Firebird.@SprinterPress- CopyCop-linked social media amplifier account used in both the June 30 Gizmodo impersonation and the July 7 Iranian military impersonation campaigns. The July 7 post alone exceeded 1.4 million views.@RoaaWarStudies- CopyCop-linked social media amplifier account used in the July 7 Iranian military impersonation campaign. Post claimed Iranian video showed destruction of Firebird AI data center.@TheSaviour- CopyCop-linked social media amplifier account used in the July 7 Iranian military impersonation campaign targeting Firebird.