Meta Threat Research

Threat Research Indicators

Welcome to the Meta Threat Research Indicator Repository, a dedicated resource for the sharing of Indicators of Compromise (IOCs) and other threat indicators with the external research community. In support of the global security research community, we are publishing threat indicators related to covert influence operations detailed in our Adversarial Threat Reports. We hope that by sharing indicators of compromise and behavioral signatures our industry partners and the broader security research community can enhance detection and mitigation of similar adversarial activities across platforms and the internet.

📋 Published Networks And Threat Indicators

Date Report Origin Targets
H2 2026 Russia-Based Influence Operation Targeting Western Audiences Russia Western Audiences
H2 2026 Israel-Based Influence Operation Targeting France, the UK, Australia, and Africa Israel France, the United Kingdom, Australia, Iran, Togo, Gabon, and Angola
H2 2026 Iran-Based Influence Operation Targeting United States Iran United States
H2 2026 Iran-Based Influence Operation Targeting Sub-Saharan Africa Iran Sub-Saharan Africa
H2 2026 Iran-Based Influence Operation Targeting Azerbaijan Iran Azerbaijan
H2 2026 France and Spain-Based Influence Operation Targeting Sub-Saharan Africa France and Spain France, Mali, Chad, DRC, Senegal, Cameroon, Burkina Faso, and Côte d’Ivoire
H2 2026 Russia-Based Influence Operation Targeting Hungary Russia Hungary
H2 2026 Deep Dive: Beyond Brute Force—Doppelganger’s Changing Operations Russia France, Germany, Hungary
H2 2026 Russia-Based Influence Operation Targeting Europe, the Middle East, and Africa Russia Europe, the Middle East, and Africa
H2 2026 Ukraine and Bulgaria-Based Influence Operation Targeting Multiple Countries Ukraine and Bulgaria United States, Germany, Italy, the United Kingdom, the Netherlands, France, Belgium, Latvia, Ukraine, and Moldova
H1 2026 Russia-Based Influence Operation Network Targeting Eastern Europe Russia Eastern Europe
H1 2026 Deep Dive: Domestic Pakistani Activity Displaying Wide Use of AI Pakistan Pakistan
H1 2026 China-Based Influence Operation Network Targeting Taiwan China Taiwan
H1 2026 Iran-Based Influence Operation Network Targeting Azerbaijan Iran Azerbaijan
H1 2026 Deep Dive: Dissecting the Kill Chain of an Early-Stage Iranian Influence Operation Iran United States, Iraq
H1 2026 Russia-Based Influence Operation Network Targeting Sub-Saharan Africa Russia Sub-Saharan Africa
H2 2025 Moldova-Based Influence Operation Network Targeting Moldova Moldova Moldova
H2 2025 India-Based Influence Operation Network Targeting India India India
H2 2025 Poland-Based Influence Operation Network Targeting Poland Poland Poland
H2 2025 Belarus, Russia-Based Influence Operation Network Targeting Poland Belarus, Russia Poland
H2 2025 Russian Use of Authentic Operators in SSA Russia Sub-Saharan Africa
H2 2025 Updating Attribution of Persistent Iranian Influence Operation to “Endless Mayfly” Iran United States, France, Israel, United Kingdom

📚 Resources

❓ FAQ

Why are you releasing this?

We’re sharing these threat indicators in this format to enable further research by the open-source community into any related activity across the web. Note that we’ve been sharing threat indicators in PDF format for years as part of our regular threat reporting

How were these indicators identified?

Meta employs a diverse array of techniques to identify malware and malicious activities. We do not typically disclose our exact methods publicly.

How often are the Indicators of Compromise (IOCs) updated?

We regularly update the IOCs as part of our broader threat reporting. For further threat analysis, visit our Transparency Center.

📝 License

All the data in this repository is provided under the MIT License. For the full license text, refer to the LICENSE file.