Executive summary

  • Russian-linked networks Storm-1516 and Matryoshka are running parallel operations against France’s 2027 presidential election, using deepfakes, cloned media branding, and coordinated bot amplification against candidates seen as pro-Ukraine.
  • A digitally altered video falsely showed candidate Gabriel Attal wearing an earpiece during an August 27, 2026 MEDEF debate; NewsGuard compared it to authentic LCI footage and found the earpiece had been added digitally.
  • In the same window, NewsGuard tallied 66 fabricated news reports from Matryoshka impersonating Euronews and France 24, targeting Attal and Édouard Philippe.
  • The structurally new element: these campaigns increasingly target AI chatbots as an audience — publishing at volume specifically so retrieval-augmented models pick the content up and repeat it as fact, a tactic researchers call “LLM grooming.”
  • Across repeated NewsGuard audits, the ten leading chatbots went from repeating false claims 18% of the time in August 2024 to 35% in August 2025 — misinformation rates nearly doubled in a year, even as models got better at not simply refusing to answer.
  • Mistral’s Le Chat has been a recurring weak point: it confirmed a fabricated Storm-1516 claim about Macron in an April 2025 test, and in a July 2025 audit of 30 prompts tied to Iran-war disinformation, it produced false answers 80% of the time.

When machines become the target: Russia’s disinformation war moves into the age of AI

France’s 2027 presidential race has not yet formally begun, and it is already the site of a battle fought on two fronts simultaneously: for the minds of voters, and for the outputs of the artificial intelligence systems those voters increasingly consult. What began as a familiar playbook of deepfakes and impersonated media has evolved into something structurally new — an attempt to shape not what citizens believe today, but what a chatbot will tell the next citizen who asks.

The strategic axis

A digitally altered video circulating after the August 27, 2026 MEDEF debate falsely depicted candidate Gabriel Attal wearing an earpiece, implying he had been fed answers in real time. NewsGuard reviewed authentic footage broadcast by LCI and found no earpiece present, concluding the clip had been digitally manipulated; one post advancing the claim drew 141,000 views within a day. In the same four-week window, NewsGuard identified 66 fabricated news reports from the Matryoshka network mimicking outlets including Euronews and France 24, targeting Attal and former prime minister Édouard Philippe. A parallel operation had earlier fabricated a claim that rival candidate Raphaël Glucksmann’s partner, journalist Léa Salamé, had bribed outlets to cover him favorably. Russian Fabrications Start Early in French Election +3

Researchers from the Antibot4Navalny project documented eight fake videos styled to resemble BFM, RFI, Le Parisien, AFP, France 24, Le Figaro, Libération and Le Monde, weaving verifiable biographical facts about Attal around fabricated allegations to lend the fakes credibility. Following the Attal campaign, researchers noted the Matryoshka network shifting its focus back to Philippe — a rotation pattern, not a fixation, designed to maximize coverage across the field of candidates. Russia’s Matryoshka bot network targets Emmanuel Macron’s … +2

The numbers behind the threat

The France operation is not isolated. The same month, Matryoshka ran parallel campaigns fabricating video clips branded with the logos of trusted European broadcasters against elections in Sweden and Germany, with Sweden’s public broadcaster SVT and Germany’s domestic intelligence service both documenting the activity. Analysts noted the campaign is engineered to overwhelm newsroom fact-checking capacity rather than to reach mass audiences directly — a strategic recalibration from persuasion to attrition. Russia faked broadcasts from Sweden’s national TV to smear its … +2

France’s national cybersecurity coordination authority has already classified the underlying threat. A 2025 SGDSN/VIGINUM technical report assessed that Storm-1516’s principal objective is very likely to discredit the Ukrainian government, most likely to weaken Western aid to Kyiv, while directly targeting European leaders and their entourages during election periods in France, the United States and Germany, typically through deepfakes and videos of varying production quality. sgdsnsgdsn

The machine as a new battlefield

What distinguishes this cycle from 2024 is the deliberate targeting of artificial intelligence systems themselves. Researchers call it “LLM grooming” — the mass production and duplication of false claims online with the specific intent of manipulating the outputs of large language models. The Pravda network at the center of this strategy does not generate original content; it aggregates Russian state propaganda and republishes it across roughly 150 seemingly independent websites in dozens of languages, engineered for search-engine and crawler indexing rather than human readership. NewsGuard measured the network’s output at 3.6 million articles in a single year. A new type of disinformation campaign based on LLM grooming +2

The consequence is structural, not incidental. A NewsGuard audit of ten leading chatbots — including OpenAI’s ChatGPT-4o, Microsoft Copilot, Google Gemini, Anthropic’s Claude, Meta AI and Mistral’s Le Chat — found they collectively repeated Pravda-linked false narratives 33.55 percent of the time, with seven of the ten directly citing Pravda-network articles as sources. This is not a training-time accident alone. A Common Crawl audit by the Digital Forensic Research Lab found Pravda and comparable state-adjacent content already present in the archive that feeds much of the open AI training pipeline, and research by Anthropic, the UK AI Security Institute and the Alan Turing Institute found as few as 250 malicious documents sufficient to measurably compromise the outputs of a 13-billion-parameter model — a finding with direct implications for the cost-benefit calculus of information-warfare planners in Moscow. Axios: “Russian Disinformation Floods AI Chatbots, Study Finds” … +2

The regulatory and industrial exposure

The trend line is deteriorating, not improving. NewsGuard’s August 2025 audit found the ten tested tools repeated false claims on current-news topics 35 percent of the time, nearly double the 18 percent recorded in August 2024, even as non-response rates fell from 31 percent to zero as chatbots moved toward answering every prompt rather than declining — a design choice trading caution for engagement. eastgate-softwareeastgate-software

France’s own national AI champion sits inside this exposure. A July 2025 NewsGuard audit shared with Les Echos tested Mistral’s Le Chat on ten false claims tied to the Iran war across thirty prompts, and found it produced false information in eight of ten cases; Mistral AI did not respond to NewsGuard’s requests for comment. In a separate August 2025 test on a fabricated claim about Moldova’s president, six of ten models — including Mistral, Claude, Inflection’s Pi, Copilot, Meta AI and Perplexity — repeated it as fact. Even the strongest performer has shown drift: Anthropic’s Claude, which had placed first for accuracy across seven consecutive NewsGuard audits between March 2025 and February 2026, was later found citing Russian state-affiliated media in 15 percent of tests on pro-Kremlin claims, up from roughly 4 percent previously. newsguardtechnewsguardtech

The cost of inaction

Two failure modes now compound each other. Retrieval-layer contamination — a chatbot with live web access surfacing a spoofed news site — can in principle be mitigated by blacklisting offending domains at inference time. Training-data contamination cannot; once absorbed into model weights, correction requires a full retrain, an expense few vendors will bear proactively. For France, the exposure is immediate and dual: an electorate exposed to deepfakes of its own candidates, and a national AI industry — Mistral foremost among it — whose products are simultaneously a strategic economic asset and a demonstrated vector for the very disinformation the state is trying to contain.

The 2027 election will not be decided solely by what French voters see on social media. It will also be shaped by what an algorithm tells them when they ask a simple question about a candidate — and, on the current evidence, that answer cannot yet be assumed to be true.


Contents

  1. Timeline: Storm-1516 and Matryoshka against France, 2024–2026
  2. The mechanism: how “LLM grooming” actually works
  3. Comparative data: how the leading chatbots perform against disinformation
  4. What this means going forward

Timeline: Storm-1516 and Matryoshka against France, 2024–2026

Origins. Storm-1516 grew out of the Internet Research Agency, the Russian troll operation active since 2014, and was first identified by media-forensics researchers at Clemson University in autumn 2023. Reporting has tied the group to John Mark Dougan, a former Florida deputy sheriff granted asylum in Moscow who now works as a Kremlin-aligned propagandist. France’s national cybersecurity coordination body (SGDSN/VIGINUM) assessed in a May 2025 technical report that Storm-1516’s core objective is very likely to discredit the Ukrainian government and undercut Western support for Kyiv, with European leaders and their entourages directly targeted during election periods in France, the US, and Germany.

December 2024 – March 2025: the first wave against France. NewsGuard documented five AI-generated fake news stories, each timed to follow a French government statement on the war, spread across 38,877 posts and 55.8 million views. Two targeted Macron and his wife Brigitte, one accused Zelensky of financial collusion with France, and two were designed to stir communal tension domestically. A European security source confirmed to NewsGuard that all five traced back to Storm-1516.

May 2025: France’s official threat assessment. VIGINUM formally classified the group as a systemic threat to European elections, documenting its routine use of video and even cloned-voice audio deepfakes, and — citing intelligence sourcing — linked one operator to Russian military intelligence (GRU) support in obtaining servers used to generate text and deepfakes.

July 2025: Moldova as the proving ground. Before pivoting hard into France, the separate Matryoshka network (also tracked as “Operation Overload” or Storm-1679, active since September 2023) tested the same playbook against Moldova’s elections — 39 fabricated articles in three months, versus zero the year before — mimicking the BBC, The Economist, and Euronews to accuse President Maia Sandu of corruption and drug dependency.

August 2026: multi-country escalation. Matryoshka ran simultaneous campaigns against elections in Sweden, Germany, and France. Sweden’s public broadcaster SVT documented fake clips impersonating its own branding against the prime minister; Germany’s domestic intelligence agency flagged over 180 fake posts tied to September regional elections; researchers at Antibot4navalny noted the goal often isn’t mass reach — many posts stay in the low thousands of views — but overwhelming newsrooms and fact-checkers with fabricated “verification requests.”

August 12, 2026: the first large-scale strike on Attal. Antibot4Navalny researchers identified eight fake videos styled to resemble BFM, RFI, Le Parisien, AFP, France 24, Le Figaro, Libération, and Le Monde, all targeting Gabriel Attal. The technique wove real biographical facts (his relationship with Stéphane Séjourné, the 2023 abaya ban, Anticor’s loss of accreditation) around fabricated allegations, making the fakes harder to dismiss on sight.

August 27, 2026: the earpiece video. After a MEDEF-organized debate, an altered clip circulated showing Attal apparently wearing a white earpiece, implying he was being fed answers. NewsGuard compared it against authentic LCI footage, found no earpiece, and could not locate the altered version anywhere in French media — concluding it was digitally manipulated. One post pushing the claim reached 141,000 views in a day.

Target rotation. NewsGuard describes Attal as the third candidate hit this cycle, after Édouard Philippe and Raphaël Glucksmann — the latter smeared by a fabricated claim that his partner, journalist Léa Salamé, bribed outlets to cover him favorably. After the Attal push, researchers observed Matryoshka pivot back toward Philippe. Across the four weeks before NewsGuard’s latest report, the network produced 66 fabricated articles impersonating Euronews and France 24.

The mechanism: how “LLM grooming” actually works

The term was coined by the American Sunlight Project (ASP), a US nonprofit, in a February 2025 report on a separate but related network called Pravda (also known as “Portal Kombat”). The mechanism it describes is distinct from — and arguably more consequential than — the direct-to-voter deepfakes above:

  • Pravda doesn’t write propaganda — it duplicates it. It takes claims already circulating in Russian state media and republishes them, largely unmodified, across roughly 150 websites in dozens of languages, optimized for search-engine and crawler indexing rather than for human readers.
  • Volume is the weapon. NewsGuard put the network’s output at 3.6 million articles in 2024 alone. To a crawler or a retrieval-augmented chatbot scanning for corroboration, a single Kremlin claim appearing across dozens of “independent” domains looks like convergent confirmation from unrelated sources — it isn’t.
  • This targets two different layers. The Digital Forensic Research Lab’s April 2026 audit of Common Crawl (the archive that feeds much of the open AI training pipeline) found Pravda, the Chinese-government-adjacent Glassbridge network, and Russian state outlet RT already present in training data. That’s the harder problem: retrieval-layer poisoning (a chatbot searching the live web and citing a bad source) can be mitigated by blacklisting domains at inference time, but training-data poisoning requires a full, expensive retrain to fix. A study by Anthropic, the UK AI Security Institute, and the Alan Turing Institute, cited in that same report, found it takes as few as 250 malicious documents to measurably skew even a 13-billion-parameter model.
  • The results are measurable. NewsGuard’s first audit under this framework, in 2024–2025, found ten leading chatbots collectively repeated Pravda-linked narratives 33.55% of the time, gave a non-response 18.22% of the time, and correctly debunked the claim 48.22% of the time — and seven of the ten chatbots directly cited Pravda-network articles as sources in their answers.
  • EU researchers frame it as a three-stage pipeline: generation (Pravda/Storm-1516/Matryoshka produce the false content), dissemination (SEO-optimized aggregator sites spread it), and engagement (retrieval-augmented chatbots surface it to users) — the same funnel that carries a fake Euronews clip to a voter’s timeline also, months later, can carry it into a chatbot’s answer about the same candidate.

Comparative data: how the leading chatbots perform against disinformation

The clearest single data point is the year-over-year trend: NewsGuard’s August 2025 audit found the ten tested tools repeated false claims on current-news topics 35% of the time, up from 18% in August 2024 — misinformation output nearly doubled. Notably, this coincided with refusal rates dropping from 31% to zero, as chatbots moved toward always attempting an answer rather than declining — a helpfulness gain that came with an accuracy cost.The six models above are the ones NewsGuard published exact figures for in that round; Claude and Gemini scored lowest but I don’t have their exact August 2025 numbers, so I’m not putting invented figures on the chart — worth flagging rather than papering over.

Share of test prompts where each chatbot repeated a false claim 60% 40% 20% 0% 56.7% Pi (Inflection) 46.7% Perplexity 40% ChatGPT 40% Meta AI 36.7% Copilot 36.7% Mistral (Le Chat)

Source: NewsGuard, “AI False Claim Monitor,” August 2025 audit of 10 leading generative AI tools.

Two points worth separating out from that same data:

  • Mistral specifically has a documented pattern, not a one-off. In an April 2025 test, Le Chat confirmed a fabricated Storm-1516 claim about an invented Macron affair. In an August 2025 test on a Moldova-related claim, six of ten models — Mistral, Claude, Pi, Copilot, Meta, and Perplexity — repeated it as fact. In a July 2025 audit shared with Les Echos, using 30 prompts (10 claims × 3 prompt styles) tied to Iran-war disinformation, Le Chat gave false answers in 8 of 10 cases (80%). Mistral did not respond to NewsGuard’s requests for comment on that audit.
  • Even the best-performing model has drifted. A more recent NewsGuard report on Claude specifically found it citing Russian state-affiliated media in 15% of tests on pro-Kremlin claims — up sharply from roughly 4% across seven prior audits between March 2025 and February 2026, despite Claude having placed first (lowest false-claim rate) in every one of those audits.

What this means going forward

  • Target rotation, not saturation — both Storm-1516 and Matryoshka move between candidates and countries (Philippe → Attal → Glucksmann; France → Sweden → Germany → Moldova → Armenia) rather than fixating, consistent with a strategy built to maximize coverage and exhaust newsroom fact-checking capacity rather than to persuade any one audience.
  • The “liar’s dividend” — the sheer volume is partly designed so real and fake footage become equally deniable, a dynamic legal scholars Robert Chesney and Danielle Citron theorized well before this campaign, and one that lets the aggressor’s own genuine misconduct evade scrutiny too.
  • The AI layer is the open flank. Retrieval-layer poisoning can be patched by blacklisting bad domains at inference time; training-data poisoning cannot be patched without a costly retrain. With France’s 2027 vote approaching and Matryoshka’s output already running at dozens of fabricated “articles” per month, that gap is the one to watch — both for candidates and for the vendors, like Mistral, whose products are meant to be trusted for exactly this kind of question.

Copyright of debuglies.com – Even partial reproduction of the contents is not permitted without prior authorization Reproduction reserved

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Questo sito utilizza Akismet per ridurre lo spam. Scopri come vengono elaborati i dati derivati dai commenti.