Illegal Russian influence operation continues to go unimpeded on X: Matryoshka targeting the Swedish Elections

Saman Nazari, Alliance4Europe.
Julia Smirnova, Center for Monitoring, Analysis and Strategy (CeMAS).

Ongoing attack 

On the 18th of August, less than a month away from the Swedish elections, the Russian influence operation Matryoshka published at least 6 videos attempting to discredit the ruling coalition (the Moderates and Christian Democrats), Ukraine, Ukrainian refugees, and Germany, while also seeking to spread fear around the elections (1, 2, 3, 4, 5, 6). One of these videos impersonated the major Swedish newspaper Dagens Nyheter; another, the Polish Public Broadcaster TVP World; a third, AFP; a fourth, the German Spiegel; a fifth, Euronews; and finally DW. On the 20th of August, an additional video impersonating EuroNews was published claiming that Russian election interference is a myth spread by ruling parties and candidates in Sweden, Germany and France. 

The six initial videos published on the 18th of August were reported on by Antibot4Navalny and the Swedish Public Broadcaster on the 19th of August. 

The choice and geographic spread of the impersonated outlets are significant. Rather than relying solely on Swedish media brands, the operation appropriated the identities of prominent Swedish, German, Polish, French/international, and pan-European news organisations. This allows the narratives to appear not merely as domestic Swedish concerns, but as claims independently reported and corroborated across multiple European information environments. The combination of a major Swedish newspaper with internationally recognised outlets such as AFP, Euronews and DW may therefore serve both to lend credibility to individual falsehoods and to manufacture the appearance of a broader European media consensus around them. The 20th August video adds a further layer to this strategy: by presenting Russian election interference itself as a politically motivated myth, the operation sought not only to shape perceptions of the election but also to undermine the credibility of warnings about the very type of interference in which Matryoshka was engaged.

Despite being a well-known influence operation with highly recognisable patterns of behaviour, Matryoshka has continued to operate on X across multiple European elections. The operation appears to violate X’s policies on authenticity and platform manipulation, while its impersonations of established media organisations and targeting of political actors also raise potential intellectual property and defamation concerns. While X has taken action against Matrioshka content, this has occurred only after the content was flagged by researchers and after the operation had already been able to spread. The identities of the actors operating Matryoshka remain so far unknown.

Members of the Counter Disinformation Network (CDN) and other influence operation researchers have been tracking the activities of Matryoshka since 2024. The operation has targeted numerous electoral contexts, including the 2024 French elections and U.S. elections, the 2025 German federal election, the 2026 German state elections, the 2026 Swedish election, and most recently, the upcoming 2027 French presidential election, to name a few.

The operation's activity ahead of the 2026 German state elections is particularly notable because it demonstrates its ability to move beyond national elections and target regional political elections and individual candidates. German authorities have identified Matryoshka activity ahead of state elections in Saxony-Anhalt, Mecklenburg-Western Pomerania and Berlin, as well as local elections in Lower Saxony. ZDF reports that the current campaign has specifically targeted lesser-known state-level politicians with fabricated allegations, representing a notable evolution in its targeting.

How to recognise the operation?

The operation has three components. A post with text, a video, and 2 sets of X accounts.

Post tagging media and fabricated impersonation videos

The post provides a one-sentence, clear-text summary of the narrative being amplified. They also tag multiple Swedish, French, German and international media organisations, apparently seeking to attract their attention and encourage further dissemination of the story. Check First has argued that this behaviour serves an additional purpose: overwhelming journalists and fact-checkers with fabricated stories that require time and resources to verify.

The accompanying fabricated videos are edited to resemble news segments produced by legitimate media organisations. They reproduce the outlets’ logos and visual identities, lending an appearance of legitimacy to the fabricated content. The videos typically combine stock footage with overlay text and ominous music.

The influence operation uses two sets of accounts.

The operation relies on two distinct types of accounts. A seed account publishes the original content, while a network of amplifying accounts interacts with the post through likes and reposts and generates views. This coordinated activity can increase the content’s visibility while also creating the appearance of broader or more organic engagement than is actually present.

The accounts display several recurring indicators of inauthenticity, including their profile pictures and descriptions, as well as a distinctive posting pattern in which accounts publish or amplify a single piece of content before becoming dormant.

 

Continuing Operation: Potential Failure to Mitigate Systemic Risk

Despite Matryoshka being a well-documented operation with a highly distinctive and observable pattern of behaviour, it has remained active on X since 2024. Its persistence is particularly notable because elements of the operation can be tracked using data available through X's own API, suggesting that identifying newly activated accounts associated with the campaign is technically feasible. 

The operation appears to violate X's own policies on platform manipulation and authenticity, yet X enforcement has not consistently prevented newly activated accounts from participating in the campaign. Matryoshka's recurring behavioural patterns potentially provide platforms with indicators that could be used to identify and disrupt accounts associated with the operation at an early stage. In addition to potential violations of X's own policies, the operation systematically appropriates the logos and visual identities of legitimate media organisations and publishes fabricated content attributed to them, raising potential intellectual property and other legal concerns. Some fabricated content also contains damaging false claims about identifiable political and institutional actors. This would make the content of the operation illegal through varumärkeslagen (2010:1877) and Chapter 5, paragraph 1 of the Swedish Criminal Code.

Platforms metrics should, however, not be conflated with actual influence. According to metrics accessed through the social listening tool Meltwater, individual posts targeting the Swedish elections received between 263 and 397 reposts and between 133 000 and 211 000 views. Our analysis indicates that a substantial share of this apparent reach is likely attributable to inauthentic amplification. Organic engagement appears to have been limited. The high headline metrics therefore demonstrate the operation’s capacity to manufacture the appearance of reach more clearly than they demonstrate meaningful influence on Swedish audiences.

Earlier Matryoshka activity targeting upcoming state elections in Germany illustrates a further limitation in X’s response. X appears to restrict parts of inauthentic reposting networks used to amplify the seeder posts, while seemingly failing to  to remove the seeder accounts consistently. This distinction is important: suppressing amplification may reduce immediate reach, but leaving the original accounts and content accessible allows the operation’s infrastructure and narratives to persist. It also creates opportunities for subsequent organic amplification. 

Previous Matryoshka videos have gained substantially greater visibility after being picked up by authentic influencers, demonstrating how an initially low-impact influence asset can acquire a secondary audience outside the operation’s own amplification network.

Indeed, direct audience persuasion may not be Matryoshka’s only objective. The operation repeatedly attempts to attract the attention of fact-checkers, journalists and established media organisations by sending them links to fabricated videos and tagging media accounts. In one specific instance, the operation targeted the Danish fact-checking organisation TjekDet, sending it the videos covered in this report. This behaviour suggests that eliciting responses from trusted information intermediaries may itself form part of the amplification strategy. Coverage intended to debunk the operation can inadvertently introduce its narratives to audiences that the operation would otherwise struggle to reach. Journalists and fact-checkers should therefore avoid unnecessarily reproducing fabricated claims or visual material and provide clear contextualisation when reporting on the campaign.

While there is currently little evidence that Matryoshka has achieved significant organic impact in Sweden, the operation is nevertheless an indicator of sustained interest in the Swedish electoral information environment. Its significance should therefore not be assessed solely through engagement generated by individual posts. The operation demonstrates that Russian state or state-aligned actors are actively testing narratives, impersonating trusted institutions and attempting to insert election-related content into Swedish and wider European public debate. Political actors,   authorities and civil society organisations should therefore be prepared for the possibility of additional activity by Russian state or state-aligned actors in both the cyber and information spaces as the election approaches.

Previous responses to Matryoshka and related influence operations, including Doppelganger, also demonstrate that their persistence is not inevitable. 

When BlueSky was alerted to Matryoshka and Doppelganger activity expanding onto its platform, it reacted rapidly against the associated infrastructure. Based on our monitoring, Matryoshka manipulative content on Bluesky is now generally removed before it can acquire meaningful visibility.

The comparison is significant because it demonstrates that behavioural disruption of these operations is technically feasible. The relevant question is therefore not simply whether individual pieces of content can be moderated, but whether platforms are willing and able to identify and disrupt the recurring infrastructure and behavioural patterns that allow the operation to function. X's continued exposure to a campaign whose methods have remained highly recognisable since 2024 suggests a persistent enforcement gap rather than an absence of detectable indicators.

If Bluesky, as a pre-revenue startup, can achieve this, so can X.

 

Our Response

On the 22nd of August, four days after the content first appeared and after it had been flagged to X, it remained accessible on the platform. By the 24th of August, six days after this initial publication, X had removed the content. X therefore did take action against the reported content, but only after a significant delay. In the meantime, the operation has already shifted its focus to the upcoming French Presidential elections

Previously observed patterns of behaviour indicate that the operation may return its attention to the Swedish elections in the week leading up to the vote. The removal of individual posts several days after publication therefore does not amount to an adequate response to an operation that can rapidly shift between targets and activate new accounts. Given the delay in X’s response, and the fact that another platform has demonstrated its ability to disrupt the operation before its content gains meaningful visibility, X’s response falls short of effective risk mitigation.

The authoring organisations have:

  1. Flagged the case to the Swedish Digital Service Coordinator, the European Commission, electoral authorities, the targeted political parties, and the impersonated media entities.
  2. Using the DSA-mandated reporting tool, flagged the pieces of content as illegal impersonation content to X (22/08/2026 - 18:45-18:50 CET). On August 23rd, 20:11 to 20:13, X declined our reporting, claiming that they “found that it is not subject to removal under the legal grounds of Scams and fraud in Sweden”. The following day, the content was  taken down by X, almost a week after the initial content was posted. By then, the operation had already reached its peak. 
  3. Alerted Swedish Civil society organisations about the possibility of future attacks and warned against wasting their time trying to fact-check the operation's content, as the operation seems to have a partial goal of wasting their time.

 

Acknowledgements:

This report was facilitated through the Counter Disinformation Network and Alliance4Europe’s contribution was funded through the Valkollen 2026 (“The Election Check”) project led by Fojo Verified.