A Russia-linked disinformation network known as Matryoshka has been detected running a new influence operation aimed at the U.S. midterm elections, using fabricated celebrity videos and bogus CNN branding to persuade Americans to vote against Democratic candidates. The findings were reported by Bot Blocker, a project that tracks coordinated bot activity and information manipulation on social media platforms. According to a representative of the project, four accounts connected to the network posted on X on Thursday, collectively distributing ten video files. The videos contained explicit calls to withhold support from Democratic Party candidates and promoted the hashtag #AllDemocratsAreCriminals. All of the clips carried the CNN logo, suggesting they were produced to look like segments from a legitimate news broadcaster. The appearance of the operation comes at a sensitive moment: the midterm elections are scheduled for November 3, when voters will choose all 435 members of the House of Representatives, one-third of the Senate, and governors in 36 states. The results will determine control of Congress, making the election an especially attractive target for foreign interference. Matryoshka, whose name evokes Russia’s famous nested dolls, is already known to researchers as a repeat offender in the information-warfare space. The new videos represent another iteration of a familiar strategy: exploit authentic materials, blend them with synthetic audio or visual elements, and use social media networks to create the impression that the content is broadly popular and therefore trustworthy.
The technical construction of the videos is both sophisticated and worrying. Some of the clips, according to Bot Blocker, are based on real footage recorded for Cameo, a commercial service that allows fans to pay celebrities for personalized video messages. The network appears to have taken authentic Cameo recordings and altered them for political purposes, changing the soundtrack or adding overlay text to make the celebrities appear to be denouncing Democrats. In other clips, the voices do not belong to the celebrities at all; they are synthetic voices that closely resemble the originals, presumably generated by artificial intelligence. This hybrid production approach makes the content harder to debunk than a fully computer-generated deepfake. A viewer who recognizes a celebrity’s face or voice may accept the message before realizing that the video has been manipulated. The celebrities exploited include Sarah Jessica Parker, Christopher Lloyd, and Julia Roberts, all of whom have substantial name recognition across generations. None of them has any connection to the videos or their political message. Every clip identified by Bot Blocker displayed the CNN logo, despite CNN having no role in their creation. The deliberate use of a major television news brand is a hallmark of influence operations: it borrows an institution’s credibility to make false claims appear verified by journalists. The underlying message is simple and blunt: that Democrats are criminals and must be denied votes in the upcoming election. That message is not a nuanced policy position but a sweeping accusation intended to delegitimize an entire political party.
Bot Blocker also warned that the apparent reach of the campaign may be an illusion. On X, the posts carrying the videos collected between 44,000 and 62,000 views. That might sound significant, but the project said the network uses artificial methods to inflate metrics. Automated programs and fake accounts can inflate view counts, likes, and shares, making malicious content appear far more popular than it actually is. Inflated metrics are not a harmless deception. They exploit a cognitive bias known as social proof: when people see that a video has tens of thousands of views, they are more likely to assume it is important, credible, and worthy of attention. Journalists, political operatives, and ordinary voters may then share it, and the content acquires a real audience through the false appearance of an existing one. The same videos were also posted on Bluesky, the alternative social media platform that has attracted many users seeking a less toxic online environment. There, the campaign fared poorly. According to Bot Blocker, the network does not currently appear to be using view inflation on Bluesky, and the posts generated no more than one like or one save each. The contrast between the two platforms demonstrates that the effectiveness of disinformation is not uniform. It depends on the platform’s architecture, its moderation policies, the size of its user base, and the presence or absence of automated amplification tools.
The Matryoshka network’s distribution method makes the current campaign particularly insidious. According to Bot Blocker, the network typically begins by spreading fake photos or videos through accounts linked to the operation. Once the false content is in circulation, associated accounts post links to these materials and specifically urge journalists to verify their authenticity. This tactic can be described as verification bait. Journalists who receive such a prompt may feel obliged to investigate, particularly when the material involves celebrities, a news logo, or an election. But the very act of researching the content can amplify it. A fact-checking article or news brief will often reproduce a still image from the video, mention the celebrities by name, and quote the hashtag. That provides the original disinformation with new distribution and long-term visibility. Even if the article is skeptical, it may be the first time many readers hear about the fabricated videos. In this way, an influence operation can turn the legitimate verification function of journalism into a vehicle for its own spread. The current campaign appears to follow the same playbook. Bot Blocker’s disclosure is intended to expose the operation early, but it also carries the risk of drawing more attention to the videos. This is a dilemma that election security researchers and media organizations face in every cycle: exposing disinformation is necessary, but every exposure can increase its reach.
The target of the campaign must be understood in the context of the midterm election stakes. On November 3, Americans will vote for all 435 seats in the House of Representatives, about one-third of the Senate, and 36 governors. The outcome will determine whether the Republican Party retains or loses control of Congress, and it will have profound consequences for the legislative agenda for the rest of the current term. Foreign interference in these elections is not a hypothetical concern. The United States has repeatedly accused Russia of attempting to affect the outcome of American elections, including by hacking political organizations, releasing stolen documents, and using social media platforms to spread divisive messages. The Matryoshka network is part of that broader ecosystem of Russian influence operations. It has run similar campaigns before elections in other countries, including Germany, Hungary, and Armenia. The network clearly tailors its content to local political conditions; in this case, it chose to attack Democrats rather than the broader system. That may reflect a calculation about which party’s defeat would best serve Russian strategic interests, or it may simply be an attempt to exploit existing partisan divisions. Either way, the ultimate objective is not necessarily to make one side win. It is to undermine public confidence in the validity of the electoral process, to make voters believe that the political system is corrupted, and to deepen the already dangerous gap between Americans who trust different sources of information.
The discovery of the Matryoshka operation is a reminder that modern election interference is as much about perception as it is about votes. Even if the videos are quickly debunked and few voters are directly deceived, the knowledge that such agents are active can itself corrode trust. It can also provide a template for others who want to disrupt elections. Artificial intelligence is advancing rapidly, making realistic voice cloning and video manipulation cheaper and more accessible. Social media platforms remain vulnerable. X has substantially reduced its trust and safety staff and has often favored lax enforcement, while Bluesky and other new networks are still developing the tools to track coordinated behavior. The burden of defense falls on many actors: researchers like Bot Blocker who map these networks, platforms that must detect and label synthetic media, journalists who must verify before amplifying, and voters who must be skeptical of content that seems too outrageous to be true. The Matryoshka network, named for the Russian nested dolls, is designed to hide layers of deception inside one another. But the same nesting principle can apply to defensive efforts: building layer upon layer of resilience—technical, institutional, and personal—is the only way to keep such operations from succeeding. The public’s best protection is not a single platform policy or a single fact-check, but a sustained culture of caution, curiosity, and independent verification.


