Kremlin sources planted and amplified fake stories about Western weapons destined for Ukraine being sold in Germany A US cavalry scout assigned to 2nd Cavalry Regiment fires a Stinger missile using Man-Portable Air Defense Systems (MANPADs) during a live fire exercise at the NATO Missile Firing Installation (NAMFI) off the coast of Crete, Greece, November 6, 2017. A conspiracy theory claiming Western-made weapons destined for Ukraine are being illegally sold online can be traced back to the Russian disinformation machine. In this article, the DFRLab examines the seven steps Russia took to disseminate and bring credibility to a conspiracy theory asserting that Ukraine sold Stinger man-portable air defense systems (MANPADS) on the dark web, presenting a danger to Europe’s security because they are capable of downing civilian aircrafts. For Russian audiences, this narrative is likely intended to demonstrate that the Ukrainian government is hypocritical and corrupt for purportedly profiting from the sale of Stinger MANPADS. And by suggesting that military aid to Ukraine could be used against civilians elsewhere in Europe, this narrative is intended to prove to Western audiences that Ukraine is an unreliable and dangerous partner. The DFRLab has previously covered similar iterations of this narrative. Step 1 — Build a false foundation On September 7, 2022, the obscure YouTube and Telegram channel Journalisten Freikorps (“Free Corp of Journalists”) published a six-second video of a Stinger MANPAD lying on the ground. The video description claimed the footage was filmed at the German port of Bremen on July 20, 2022, as Ukrainian military personnel were being arrested for transporting multiple “tubular devices.” The post also claimed the Ukrainian troops were aboard the ship Fl
Conclusions & Recommended Actions & Technical Summary
- Forensic Focus: Audit chain of custody, system timestamps, and artifact logs for related activity.
- Source Provenance: Technical briefing synthesised from DFRLab (Digital Forensic Research Lab) advisories.
- Examiner Action: Update investigation IOCs and cross-reference artifact signatures.
- Forensischer Schwerpunkt: Systemprotokolle prüfen, Artefakte analysieren und die Beweiskette sichern.
- Quellenherkunft: Verifizierte technische Analyse basierend auf Berichten von DFRLab (Digital Forensic Research Lab).
- Maßnahme: Relevante Indikatoren (IOCs) aktualisieren und betroffene Systeme prüfen.