A Russian-Linked Influence Campaign Used AI-Generated Impersonations to Flood Social Platforms
What happened
In May 2025, researchers at the Institute for Strategic Dialogue published an analysis of a coordinated influence operation they had tracked through the first quarter of that year. The campaign, known as Operation Overload and also tracked under the names Matryoshka and Storm-1679, was assessed as Russian-aligned. Its method was straightforward: purported AI-generated voiceovers and visual impersonations layered onto false and inflammatory content, distributed at scale across social media platforms.
ISD's review covered at least 135 discrete posts published between January and March 2025. The targets were a mix of institutions and individuals, and the content was designed to amplify discord rather than carry a single coherent message. What unified the posts was the technique: synthetic-seeming audio and visuals attributed to real people and organizations, produced at a volume and pace that would be impractical through traditional fabrication.
One post from the dataset crossed into broader circulation. A video claimed that USAID had funded celebrity trips to Ukraine, a specific provocation timed to attach a politically contentious spending allegation to an agency already under public scrutiny. ISD described this video, like others in the campaign, as "purported" AI-generated, a qualifier that runs through the report: the researchers assessed the materials as synthetic in origin but could not confirm that determination in every instance.
That word choice is not incidental. "Purported" signals a core problem these operations create for researchers and platforms alike. When a piece of video or audio is uploaded without origin data, the claim that a machine produced it is itself unverifiable. Attribution becomes contested by design, and the campaign benefits from leaving it that way. ISD's ability to name the operation, trace 135 posts, and publish a public analysis is significant counter-documentation. But the underlying ambiguity about what generated the content is never resolved, and it does not need to be for the operation to succeed.
What the report points toward is a provenance gap that sits beneath the surface of any individual post. Nothing in the campaign's distribution trail recorded which system produced each piece of content, who directed its release, or when the synthetic components were generated. A provable record of what a system did and what it output would make attribution analysis faster and more resistant to deliberate muddying. Without that record, researchers are left reconstructing intent from spread patterns alone, working backward from distribution to probable source rather than forward from evidence of production.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.