Russian fakes target a US-backed AI data center in Armenia

Between June 24 and July 13, a Russian influence network built three separate fabrications about one building site in Armenia. The first was a video dressed as a TechCrunch report, warning that an imminent magnitude 7.4 earthquake threatened the facility. The second impersonated a named Gizmodo journalist to argue that the power grid around it made the investment economically unsustainable. The third dropped the media disguise entirely and posed as Iranian military messaging, declaring the site a legitimate target.

The third one was seen more than 1.6 million times.

Recorded Future's Insikt Group documented all three and attributes them to CopyCop, the Russian influence network also tracked as Storm-1516. Insikt assesses that CopyCop very likely targeted the site as part of a broader effort to undermine Armenia's turn toward the West.

Why a construction site is worth this much effort

The target is the Firebird AI data center in Hrazdan, the first large-scale AI facility in the Caucasus, built with the US and Armenian governments and NVIDIA. Phase One, roughly $500 million, was due to open in July 2026 with more than 6,000 NVIDIA Blackwell GPUs. Phase Two would take the total to around $4 billion, which Insikt notes would place Armenia among the top five countries in the world for AI computing infrastructure.

That makes it a physical symbol of a political shift. Armenia has frozen its participation in the Russia-led Collective Security Treaty Organization since February 2024, and signed frameworks with Washington on semiconductors and AI, critical minerals and strategic partnership. The data center is the most photogenic piece of that realignment, which is exactly why an influence operation would rather it looked fragile.

The same builder behind all three sites

The fake TechCrunch video was hosted on tech-crunch[.]org, a domain registered through Namecheap on June 21, three days before the video appeared. Insikt tied it to previously confirmed CopyCop infrastructure by comparing CSS stylesheet hashes, the fingerprint left behind by reusing the same page template. The matches included haaretz24[.]com, euronews[.]us[.]com and politico-24[.]com, all imitations of real outlets. The Gizmodo fake ran on gizmodo[.]cc, registered through Namecheap on June 26 and hosted via Hostinger, the same pattern six days later.

Independent researchers at the Gnida Project separately reached the same attribution on the first video, which is the kind of corroboration this field rarely gets.

The accounts matter more than the domains

Domains are cheap and get taken down. The amplifier accounts are the durable asset, and they were reused across the campaign: one account pushed both the earthquake and the power-grid fakes, and another carried both the power-grid fake and the Iranian impersonation, including a single post with more than 1.4 million views. Insikt reads that reuse as evidence of a persistent, redeployable network rather than a one-off effort, and the same conclusion runs through Google's account of the pro-Russia influence ecosystem pivoting back toward the West.

Where Insikt expects this to go next

CopyCop has already worked the same territory. On March 8 it amplified a false claim that Armenia had granted a Turkish construction firm a 40-year concession over the Zangezur Corridor, when the actual agreement grants US development rights of up to 99 years. That one was placed in a legitimate Turkish outlet rather than on a spoofed site, a different technique for the same end. Insikt has not observed CopyCop targeting the Metsamor nuclear plant negotiations or the critical minerals framework, but flags both as likely future subjects, and the reasoning on Metsamor is uncomfortable: the network has already tested a narrative that critical infrastructure is unsafe, and pointing that template at a Soviet-era nuclear plant would carry far more fear.

Takedowns are the practical lever

There is no patch here. The organizations with something to do are the ones whose brands were stolen: media outlets should pursue domain and account takedowns and press platform trust and safety teams to pull infringing content quickly, because reach in these campaigns concentrates in the first days. For anyone financing high-visibility Western-linked infrastructure in the South Caucasus, Insikt's assessment is that targeting by Russia-aligned influence networks is now a normal project risk. The full Insikt Group report carries its indicator list.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions