A few days before Moldova's parliamentary elections (scheduled for September 28, 2025), cybersecurity researchers have uncovered a sophisticated Russian disinformation campaigndesigned to undermine public trust in Moldova's pro-European leadership.

The campaign began in April 2025, when analysts first noticed a cluster of newly registered domains publishing biased news articles in both Romanian and Russian. These sites used identical templates and shared infrastructure with older Russian propaganda outlets. It was an organized effort to sow discord at a critical time for Moldova’s democratic process.
Silent Push analysts detected the campaign through a combination of open-source intelligence and network traffic analysis . Initial signs included dozens of URLs hosting political commentary with inflammatory headlines aimed at discrediting the ruling coalition and amplifying calls for a return to Moscow.
See also: Android banking trojans mimic government apps
Russian disinformation campaign – Connection to previous incidents
Subsequent investigations revealed that these domains led to two IP addresses that had previously hosted content for a disinformation operation 2022. By matching registration metadata and hosting records, researchers established a clear line between the new Moldova targeting effort and previous campaigns.
Through technical analysis, Silent Push analysts noticed that the new sites reused several custom functions that had originally been developed for the 2022 campaign. These functions handled referral redirection social media. Reusing this code not only accelerated development but also provided a unique footprint that allowed researchers to connect the various sites.

The technical footprint was particularly evident in the PHP module responsible for generating article templates and parsing URL parameters. By comparing hash fragments in each URL, analysts were able to trace the evolution of the codebase in both the 2022 Absatz infrastructure and the 2025 Moldova campaign.
Detection avoidance and persistence
The campaign operators demonstrated advanced persistence tactics, carefully designing their infrastructure to evade traditional detection. Each disinformation site used a rotating pool of content delivery networks (CDNs) and proxy services to mask the original IPs, falling back to backup hosts when a primary node went down. DNS records were configured with extremely short TTL values—often under five minutes—forcing security teams to constantly refresh caches and making takedown efforts difficult.
See also: New Domain-fronting Attack Abuses Google Meet, YouTube, and Chrome
In one case, when researchers were able to block access to a malicious domain at the ISP level, the site automatically redirected visitors to an alternative domain using a hidden JavaScript loader. This loader would fetch an obfuscated payload from a third-party CDN, which in turn would refresh the disinformation site’s content in the user’s browser without touching the original domain. Using this two-stage loading mechanism, the campaign was able to survive domain blacklisting and continue publishing articles without significant downtime.

To maintain operational security, all command and control interactions for new content updates were conducted over TLS-encrypted channels, using non-standard ports. The same ports were observed in the 2022 Absatz campaign, further strengthening the connection between the two efforts. Analysts also noted that the social media relied on low-quality bot accounts programmed to mimic the behavior of real users, varying posting times and alternating political content with neutral topics such as sports or local weather.
See also: BRICKSTORM: Chinese hackers had access to American companies for a year
As Moldova approaches the polls, this disinformation campaign highlights the importance of technical cooperation and real-time monitoring in defending democratic integrity.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
