Understanding Nexus operations: Where Cyberattacks and Disinformation converge

Untangling disinformation narratives-7

Disclaimer: This section of our website features news and stories about disinformation from external sources. The views and opinions expressed in these articles are those of the original authors and do not necessarily reflect the ATHENA project’s official position. The ATHENA project cannot be held responsible for any use which may be made of the information contained within the publication.

Original article published by CyberPeace Institute on Sep 01, 2025.

Cyberattacks and disinformation are increasingly part of the same campaign – planned, timed, and executed to reinforce each other. At the CyberPeace Institute, we call this convergence the ‘Nexus’: the strategic intersection where technical intrusions and influence operations combine to destabilize, deceive, and coerce.  The impact of these hybrid attacks lies in their persistence, coordination, and psychological effect. From phishing emails that enable propaganda campaigns, to hacked news portals used to plant false narratives, these attacks are designed to manipulate both systems and opinions.  

To help the public, researchers, and frontline defenders make sense of this evolving terrain, we’ve identified (after mapping over 70 of these types of attacks) ten distinct categories of nexus operations. These fall into two overarching types: those that begin with a cyberattack, and those that begin with information manipulation (FIMI/disinformation) but evolve into or enable technical compromise.    

Cyberattack-initiated Nexus operations:

  1. Access and control of dissemination channels TargetInformation infrastructure (e.g., social media accounts, websites) Attackers seize control of platforms or channels to disseminate false or distorted narratives – e.g., hijacking a CSO’s X (Twitter) account to push wartime propaganda or disinformation masked as official updates.
  2. Access and control of information sources TargetInformation integrity itself Cyberattacks are used to access, create, suppress or manipulate sources of information: fake or defaced websites, doctored documents, or leaked data combined with fabricated or cherry-picked information. It also includes attacks to remove access to credible information. This includes classic “hack-and-leak” or “leak-and-spin” operations and some specific ‘“DDoS” attacks with a suppression intent..
  3. Credibility, distraction or revenge attacks TargetThe organization’s reputation and capacity Technical attacks are launched to discredit or undermine efforts of fact-checkers, watchdogs, or official voices – planting fake indicators of compromise, eroding trust in their reporting, or simply by distracting or consuming resources otherwise used against the threat actor.
  4. Disinformation amplification via cyber assets TargetPublic perception, via indirect manipulation Here, the cyberattack (such as an email dump) isn’t paired with a platform hijack but is instead used as raw material for the dissemination of FIMI / Disinformation campaigns.
  5. Cyber-coercion or financial extortion TargetThe victim’s autonomy or security Hackers may threaten to release sensitive data unless demands are met, using both real and fabricated content to create coercive pressure. Disinformation becomes part of the extortion strategy.
  6. Complex coordinated attacks TargetMultiple dimensions (infrastructure, information, reputation) These are sophisticated, multi-pronged operations involving simultaneous or sequenced attacks—blending intrusion, narrative control, and psychological manipulation to overwhelm response capabilities. 

FIMI-initiated Nexus operations

  1. Credibility or revenge attacks (Disinfo-led) TargetCivil society or critical actors The same logic as above, but reversed: disinformation campaigns that lay the groundwork for cyberattacks against their targets – often CSOs or other actors that represent an obstacle for the Threat Actor’s goals.
  2. Exploitation of cognitive vulnerabilities TargetSpecific individuals or groups, based on disinformation exposure Psychological profiling derived from FIMI / Disinformation campaigns is used to tailor cyberattacks. For example, individuals drawn into conspiracy movements may be more vulnerable to phishing lures echoing those narratives.
  3. Repurposing of collected data TargetUsers engaged with disinformation ecosystems Email addresses, contacts, or behavioral data gathered during a disinfo campaign are used for follow-on attacks—such as spear phishing, malware delivery, or identity theft.
  4. Repurposing of mobilised networks or infrastructure TargetThe disinformation community itself The community built around a disinformation narrative is weaponised for cyber ends: DDoS campaigns, malware disguised as activist tools, or fraudulent fundraising operations cloaked in ideological rhetoric.  

NOTE: This list is based on current research and is intended to be iterative and adaptable to evolving threats.

Why It Matters  

Understanding who is being targeted and in what sequence allows for smarter prevention, faster attribution, and more appropriate responses, especially when democratic institutions or civil society are on the front line. Nexus operations are not anomalies; they are the new norm in digital conflict and will continue to grow with AI development.   

The CyberPeace Institute is actively investigating this phenomenon and building initiatives to help organizations recognize these hybrid threat patterns, assess their exposure, and develop collective resilience. We do this through technical, analytical, and communicative strategies, providing defenders with the tools, intelligence, and frameworks they need to respond. From integrated threat analysis to capacity-building workshops, our work is rooted in building collective resilience.  If you’re a researcher, policymaker, or organization facing these threats, get in touch with us to learn how we can support you. 

.

Posted by: Nayara Güércio (Trilateral Research)