Digital Dispatches
September 15, 2026

ISD-US
Coordinated Inauthentic Behaviour, Information Warfare and Online Manipulation
‘United by chaos:’ Examining the Russian nexus to online networks of nihilistic violence
DISCLAIMER: The principal network examined in this report regularly exploits media coverage to enhance its reputation and attract new participants. To mitigate the risk of unnecessary amplification, ISD refers to this network as ‘the Alliance’ or ‘the coalition.’ Certain lesser-known groups within the Alliance are identified as ‘Group A’ and ‘Group B,’ while individual online usernames are withheld and replaced with role-based descriptions. In some cases, ISD has chosen to explicitly name organizations, including when they are already well-known through public reporting or when doing so is necessary for analytic clarity or evidentiary value. These editorial decisions are intended to ensure reader understanding while limiting undue publicity for actors who may benefit from notoriety.
Since April 2026, a coalition of groups operating within the broader Com Network—referred to in this report as ‘the Alliance’—has sought to provide greater coordination, operational capability and strategic direction to an otherwise fractured ecosystem of nihilistic violence, where violence is generally pursued without a concrete political or ideological objective. Since its emergence, the coalition has brought together pre-existing Com entities, including 764, with predominantly Russian-speaking groups. At the same time, the Alliance has placed heightened emphasis on facilitating and incentivizing offline violence.
This Dispatch examines the development of the Alliance, its activities to date and indicators of possible Russian state sponsorship, arguing that the potential exploitation of online nihilistic communities by state-linked actors merits viewing these networks as a potential vector for hybrid warfare. However, it cautions against portraying the Com as a Kremlin-directed project, suggesting instead that potentially state-linked actors are attempting to hijack an otherwise organic, youth-driven network as a recruitment pool for violence.
Key findings
- The Alliance is imposing greater coordination and strategic direction across otherwise fragmented parts of the Com, while connecting actors espousing different ideologies. Groups with previously distinct ideological and geographic focuses are coalescing around a shared commitment to offline violence and the fomenting of chaos worldwide.
- Alliance-linked actors are introducing a level of operational sophistication and practical support for violence that is unusual across the wider Com. This includes original instructional material produced by Russian-language groups within the Alliance, including videos related to explosives and poisons. They have also developed a dark web infrastructure which hosts resources related to weapons, operational security, hacking and other harmful activities.
- Activity associated with the Alliance includes online threats, violent propaganda and significant offline harm. One Alliance-linked group, referred to in this report as ‘Group A,’ has been linked to dozens of swatting incidents (hoax reports designed to trigger an armed response from law enforcement at a specific location) and arson attacks globally. Additionally, young adherents have been implicated in alleged school attack plots in Ukraine and a murder conspiracy in Germany.
- ISD identified multiple indicators suggesting possible Russian state-linked support for the Alliance. These include financial incentives for violence, proxy-style tasking, advanced technical infrastructure and coordinated propaganda. This mirrors established Russian methods for recruiting ‘disposable agents’ for violence abroad.
- These indicators do not mean that the Com as a whole is a Russian-directed phenomenon, but they illustrate the risk of hostile states exploiting an existing recruitment pool of individuals interested in committing violence. The Com remains a primarily organic, youth-driven ecosystem, but external actors appear to be exploiting these networks by providing financing, expertise and direction.
Background and history of the Alliance
The Alliance formally debuted on Telegram in April 2026. However, one of its constituent groups and several tactics that would later characterize the coalition were visible more than a year earlier. In February 2025, the counter-hate organization Hope Not Hate exposed a network of Telegram channels operated by an ostensibly UK-based group known as ‘Direct Action,’ which offered payments for anti-migrant vandalism and sabotage. In parallel, a primarily Russian-speaking group named ‘397’ (which would later emerge as a central node within the Alliance) announced a partnership with Direct Action. During this time, 397 encouraged more lethal violence and shared instructional material related to explosives. While 397 largely avoided scrutiny from researchers and journalists, subsequent media reporting and court proceedings revealed that Direct Action was connected to arsons targeting UK Prime Minister Keir Starmer’s properties in the UK in May 2025. Further, it was revealed that the perpetrators were recruited and promised compensation by an individual alleged by the BBC to be a possible Russian diplomat.
It is unclear whether 397 played a direct role in these arsons or whether its partnership with Direct Action involved genuine coordination. However, the episode provided an early example of a payment-for-violence model that would later be formalized by the Alliance. Tactics included recruitment through social media, offering financial incentives, demanding proof of action and encouraging increasingly destructive offline violence.

When ISD began monitoring 397’s Telegram channels in early 2025, it displayed several features that would become emblematic of the Alliance. Its channels combined violent content depicting assaults, arsons and possible killings with an emphasis on practical guidance, including multiple videos that appeared to show members building and testing explosives. Much of its material was also published in both Russian and English, suggesting an intent to build audiences beyond Russian-speaking spaces. The apparent goal of this content was not simply to glorify violence, but to lower the barriers to carrying it out and make it more damaging.
After its Telegram channels were banned following the UK-focused campaign in early 2025, 397 re-emerged that summer as part of an alliance with the pre-existing Com-affiliated groups No Lives Matter (NLM) and Maniac Murder Cult (MKY), producing co-branded propaganda. This marked a significant shift: a group that had previously embedded itself within a UK-focused anti-migrant campaign was now integrating itself into the ideologically nebulous and youth-facing world of the Com. This transition is difficult to explain but can perhaps be understood as an attempt to access and influence a new recruitment pool.

397 was not the only Russian-speaking entity building an international Com audience through an increased emphasis on real-world violence. In late 2025, a Russian group (hereafter referred to as ‘Group A’) emerged within Com spaces, combining youth-focused recruitment and the offer of social and monetary rewards, along with the True Crime Community’s emphasis on school attackers and mass violence. On Telegram and TikTok, Group A produced content targeting alienated and bullied students, presenting violence as a path toward revenge and recognition. Notably, the group claimed that it would provide recruits with money, equipment, clothing and assistance with attack planning. At the same time, it encouraged supporters to prove themselves through arson, vandalism and other acts committed in its name. Concerningly, Group A displayed an overt fixation on school violence and claimed involvement in several school plots and attacks in Europe, although many of these assertions are difficult to verify and were likely intended to generate notoriety.
Nevertheless, Group A’s real-world impact became clear in January 2026, when it used Telegram to issue threats against schools across Texas, prompting closures and a significant law enforcement response. Shortly before these threats, a series of vehicle arsons was conducted in Fort Worth, Texas, culminating in an arrest of a teenager who was active in Group A’s online spaces. While the precise relationship between these incidents and Group A’s Russian leader—discussed in more detail later in this report—remains unclear, they showed that Group A’s activity extended beyond online posturing.

In April 2026, Group A and 397 appeared alongside established Com entities such as 764, NLM and MKY as members of the newly launched Alliance. Unlike the loose and often short-lived partnerships common across the Com, the Alliance quickly began developing a level of coordination, digital infrastructure and operational sophistication that is unusual within the broader ecosystem of nihilistic violence.
Organizing violence across the Com
Since its launch in April 2026, the Alliance has distinguished itself from the wider Com through the degree of coordination and discipline it has introduced into an otherwise fragmented online environment. Rather than simply promoting one another’s channels, member groups present the coalition as a shared structure for exchanging information, accessing technical resources and coordinating activity. Groups seeking admission have been expected to demonstrate continuous offline action, while some members have even been removed for inactivity. In its own messaging, the Alliance has emphasized tangible results over group history or competing claims of authenticity, which is a departure from the broader Com’s fixation on whether groups truly are who they claim to be.
This emphasis on results has produced an expanding catalogue of Alliance-linked offline activity, with Group A providing some of the clearest examples. Following the Texas school threats and arsons, the group continued to threaten schools, hospitals and other facilities across the US and Europe. At the same time, it circulated footage that appeared to document arson and vandalism in several American and European locations. Some videos also appeared to show the arson of a church and farm equipment (likely somewhere in North America), reflecting an escalation from low-level crime towards more serious violence. This progression mirrors dynamics observed elsewhere in the Com and in the aforementioned Direct Action case, where activity moved from stickering or vandalism toward arson.

In other instances, activities linked to Group A appear to have escalated considerably further. In April 2026, the Security Service of Ukraine (SBU) alleged that Russian handlers operating through Group A had recruited a 15-year-old and an 11-year-old to conduct separate school attacks in Ukraine. The following month, German police detained several teenagers aged 14 to 16 over an alleged conspiracy to murder a minor, which authorities discovered during an investigation into Group A. Separate reporting linked Group A to the arson of a house in Germany which injured two people and caused substantial financial damage. While these incidents remain under investigation, they illustrate how a model of incentivizing and documenting violence can move beyond low-level vandalism and threats toward potentially lethal activity.

Other Alliance-affiliated groups also regularly publish videos depicting vandalism, arson and assault, often accompanied by handwritten notes displaying associated group names as proof of action. This allows several groups to claim responsibility for the same incident while rewarding participants with recognition and fostering the impression of a geographically dispersed coalition of violent actors who adhere to a common plan. Not every act is likely to have been centrally orchestrated, as some likely involved young participants acting independently in pursuit of status or admittance to the Alliance. Nevertheless, by branding and promoting these incidents across affiliated channels, the Alliance can present disparate acts as evidence of a coordinated transnational campaign, potentially broadening its influence across the wider Com.
The coalition also connects groups focused on different forms of harm. 764 is a formal Alliance member despite its longstanding involvement in sextortion, coerced self-harm and performative cruelty. At the same time, Alliance-linked actors have criticized these activities as insufficiently ‘accelerationist’, instead encouraging participants to engage in direct physical violence and sabotage. Nevertheless, the Alliance appears willing to tolerate and even promote 764, reflecting its likely desire to access a recruitment pool of young adherents who can be pushed toward overtly terroristic violence.
The Alliance has also developed an unusually sophisticated digital infrastructure within the wider Com. In July 2026, it launched a public website and dark web forum containing ideological materials and technical guides available in Russian and English on subjects such as operational security, cybercrime, poisons, explosives, weapons and methods for conducting violence. On Telegram, several Alliance-linked channels announced these online spaces within minutes of each other, suggesting a strong degree of coordination.
A so-called ‘marketplace’ established shortly after the launch of these websites further illustrates the Alliance’s emphasis on professionalization. This marketplace allows for the purchase of various illegal goods and services, including weapons, chemicals and stolen data, with transactions purportedly being secured through escrow. It is unclear whether the marketplace is actually operational or instead merely aspirational, and its actual volume of trade is unknown. However, this attempt to integrate propaganda, recruitment, operational guidance, cyber activity and material support within a single coalition is a significant departure from the more chaotic and ephemeral structures normally associated with the Com.
Taken together, these developments suggest that the Alliance has the potential to organize and intensify violence across the wider Com, which has otherwise been relatively undisciplined and improvisational. However, its model is not entirely new and many of the Alliance’s practices have a clear precedent in MKY.
The Alliance as an evolution of the MKY organizational model and ideology
The Alliance’s effort to introduce structure and strategic direction into the Com did not emerge from scratch. Organizationally, MKY provides the clearest precedent: a designated terrorist entity in Canada and the UK, it pioneered many of the practices the coalition has since adopted and expanded. This includes using violence as proof of commitment, repackaging footage of criminal activity into propaganda and rewarding participants with status for increasingly severe acts of violence. The Alliance is therefore best viewed not as an entirely new model, but as an effort to scale one that developed organically within MKY and was later adopted by other Com groups like NLM. Importantly, however, there is no evidence suggesting that earlier iterations of MKY were directed or supported by the state actors.
MKY encouraged geographically dispersed individuals to commit violent or criminal acts on its behalf, and to provide photographic or video evidence as proof. These actions could secure entry into the organization, bolster a member’s reputation within the group and generate propaganda designed to inspire further violence. Over time, this developed into a system of so-called ‘murder points’ through which members advanced through the ranks based on the severity of their documented actions.
The Alliance retains this model while scaling it across otherwise distinct Com groups. It links entities with different cultures and recruitment pools, allowing violent propaganda, operational expertise and participants to circulate between them. Prospective member organizations are judged by their ability to produce real-world action, while some affiliated entities have created ‘feeder’ arrangements that provide pathways from lower-level participation into more established groups. Accordingly, violence functions simultaneously as proof of commitment, a mechanism for advancement, a source of propaganda and a route into higher-status groups within the Alliance.
Alongside these organizational features, the Alliance provides a common purpose for groups rooted in different ideologies or subcultures. Its constituent groups draw on a diverse range of subversive worldviews, including misanthropy, National Socialism, Satanism, occultism, nihilism and anti-system extremism. Importantly, however, the coalition repeatedly presents chaos as the principle that transcends these differences. On its website, the Alliance states that while its members may hold different worldviews, they are “united by one thing: Chaos.” In this sense, the Alliance does not require adherence to a single coherent ideological framework so much as a shared willingness to disrupt society.
Individual member groups reach this objective through different ideological routes. For example, 397 and the current iteration of MKY embrace explicitly National Socialist and misanthropic themes. Other members (including a prominent member of the Alliance referred to in this report as ‘Group B’) lean into Satanic and occult aesthetics, framing violence as a form of ‘purification.’ Meanwhile, Group A has adopted a more personalized form of misanthropy targeting alienated youth, presenting violence as a means of empowerment. These distinctions broaden the coalition’s potential recruitment pool, but importantly, they remain subordinate to the broader objective of generating chaos through violence.
This makes the Alliance unusually explicit in its embrace of accelerationism (the use of violence to hasten societal collapse) compared to many other Com groups. While the behavior of many Com groups often appears accelerationist, it is more frequently driven by a desire for notoriety and a sadistic fascination with violence rather than a commitment to any political project. The Alliance is different in that its own rhetoric describes chaos as its primary objective, while its organizational model rewards groups for producing tangible results. This does not mean that every Alliance participant understands themselves to be an accelerationist, but that the coalition as a whole views violence as an essential instrument for weakening society and facilitating its collapse.
Taken together, the Alliance’s organizational model, tactical resources and pursuit of chaos suggest an effort to impose greater strategic direction on parts of the Com that have historically been fragmented. Notably, the most prominent actors steering this development primarily speak Russian in an environment that has largely operated in English. Their role in providing financial support, technical knowledge, mentoring and coordination raises an important question: does this represent the organic emergence of unusually capable actors within the Com, or is some form of external support driving the Alliance?
Assessing the potential Russian nexus
While the Alliance displays numerous indicators of potential Russian state sponsorship that merit investigation, definitive attribution would require direct evidence tying its leadership or financing to identified Kremlin-linked actors. Any assessment must also begin with the caveat that the broader Com should not be understood as a Russian-directed project. It remains primarily an organic, youth-driven ecosystem, and many young people acting on behalf of the Alliance are likely unaware of any foreign involvement. Nevertheless, predominantly Russian-speaking actors associated with the Alliance are introducing capabilities and practices that are unusual across grassroots Com networks, suggesting that more experienced, well-resourced and operationally sophisticated actors are entering the field and shaping its direction.

The offering of financial incentives is one indicator that suggests the possibility of external sponsorship. In January 2026, Group A offered thousands of dollars for vehicle arsons and claimed that it would ‘fully sponsor’ recruits by providing weapons, clothing, tactical materials and assistance with attack planning. Other Russian-language Alliance members have adopted similar approaches, with Group B and an associated channel advertising payment for violent activity while attempting to recruit couriers, chemical manufacturers and other operators capable of providing an on-the-ground presence in cities worldwide. Group A has also published photographs of apparent cryptocurrency transfers as evidence that participants were compensated (see Figure 6). Although these claims cannot be independently verified, this payment-for-action model mirrors well-documented Russian efforts to recruit low-level online proxies for arson and sabotage abroad, using ‘disposable agents’ while maintaining plausible deniability.
Russian-speaking Alliance leaders also provide a level of practical support that goes well beyond the role of a typical Com organizer. Group A has consistently promised to help recruits with attack planning and acquiring weapons and tactical equipment, while 397 has published original bomb-making instructional videos in both Russian and English. Meanwhile, Group B has assembled an extensive archive comprising thousands of files containing guidance about poisons, chemistry, weapons and other harmful topics, while the Alliance more broadly has consolidated similar material on its dark web forum. Further, the establishment of an escrow-supported marketplace, offering of cybersecurity support for followers and claims of having conducted cyber-attacks point to a level of operational capability that is unusual in youth-led Com networks.
The coalition’s digital behaviour provides additional evidence of sophistication. Russian-language Alliance groups have followed a similar playbook that involves the creation of ‘adapter’ or gateway Telegram channels leading to more restricted spaces, the maintenance of multiple backup accounts or channels with predictable usernames and succession plans, the use of bots to vet prospective recruits, and attempts to migrate audiences from Telegram to Tor, Matrix, Session and other platforms that are perceived as being more secure. While none of this requires state involvement—and experienced terrorists, cybercriminals and organized crime actors have long engaged in similar practices—it reflects a departure from the often improvised and inconsistent management of youth-led Com networks.

Also of note, imagery analysis of propaganda posted by ostensibly separate Alliance entities suggests a level of coordinated activity that raises questions around the authenticity of these actors. Images posted by the Alliance and member groups including Group A, Group B, another Alliance-affiliated group and NLM repeatedly feature the same interior location and show matching furniture, curtains, blankets, wall features and extremist or occult memorabilia. Of particular interest, Group A’s leader (who Russian authorities claimed to have arrested in Dagestan in June 2026) shared apparent images of himself featuring clothing, patches, objects and the same indoor setting seen in images posted by Group B’s leader, a central figure in the Alliance who has continued to operate after the arrest. Alliance announcements and propaganda have also frequently appeared across multiple member channels within minutes or seconds of one another. While these overlaps do not prove that the same individual controls all of these accounts and channels, they complicate the Alliance’s presentation of itself as a spontaneous coalition of independent groups and users. Instead, they suggest that a significant portion of the network’s propaganda creation and dissemination may be coordinated by a relatively small number of Russian-speaking actors.

Importantly, attribution of the Alliance’s activities is complicated by the network’s own use of deception and exaggeration, alongside competing state narratives. For example, the SBU has accused Russia of using Group A to recruit minors for school violence in Ukraine. By contrast, Russian authorities announced in June 2026 that they had arrested Group A’s leader and claimed that he had operated under SBU direction. This claim should be treated cautiously: the suspect’s identity and precise role have not been independently verified outside Russian state media and Group A has since relaunched under an administrator who claims to also lead 397. While the arrest could reflect the genuine disruption of a non-state operator, it could also be disinformation intended to obfuscate the Alliance’s leadership and affiliations or redirect scrutiny towards Ukraine.
None of these indicators prove Russian state control or influence over the Alliance. However, the peculiar combination of financial incentives, proxy-style tasking of low-level recruits to conduct violence, unusual technical and operational sophistication, coordinated inauthentic propaganda and emphasis on arson, sabotage and the fomenting of chaos abroad resemble established patterns of Russian hybrid warfare. Further, they echo a pattern of behaviour demonstrated by the neo-Nazi accelerationist group ‘The Base,’ which used cryptocurrency payments, coordinated online activity and unusual communications practices to support violent campaigns aligned with Russian geopolitical interests. While the degree of state involvement in the Alliance is unclear, the possibility that Russia-linked actors are exploiting the Com’s youth networks to enable deniable acts of violence and disruption abroad warrants serious attention.
Implications and conclusion
One of the most pressing implications of the Alliance’s emergence is that external exploitation of the Com could significantly increase the sophistication and lethality of its violence. The ecosystem already contains alienated minors, regular exposure to extreme harm and participants willing to engage in dangerous activity for recognition. This means that well-resourced actors, including hostile states, may view these spaces as convenient recruitment pools and provide financing, technical knowledge, equipment and other forms of support that can steer vulnerable individuals towards increasingly destructive and lethal forms of violence. Such methods are consistent with Russia’s longstanding use of criminal groups as proxies, and those carrying out these actions are often unaware that they are serving the interests of an external actor.
More broadly, the Alliance suggests that online subcultures of nihilistic violence may be emerging as a new frontier for state-linked hybrid warfare. This possibility requires a broader analytical and prevention response that harnesses the expertise of counter-extremism practitioners, youth radicalization specialists and experts on hostile state activity alike. While specialists across these disciplines often seek to understand and counter threats through separate frameworks, effective detection and disruption of the Alliance may require more sustained cooperation across sectors, jurisdictions and institutions that are often siloed. Additionally, given the transnational nature of both the Alliance and the Com, responses must involve international cooperation by default, with regular information sharing between governments, law enforcement, researchers, platforms and other stakeholders.
Interventions must also look beyond the individual channels and group names affiliated with the Alliance. So far, the coalition has demonstrated a strong degree of resilience and adaptability by quickly restoring banned channels, migrating to and experimenting with alternative platforms, and frequently absorbing smaller independent organizations. Account takedowns by platforms like Telegram remain vital. However, responses should also target the supporting infrastructure that enables violence. This includes technical services, cross-platform coordination and financial flows. In particular, the Alliance’s use of cryptocurrency and offers of financial rewards suggest that lessons from counter-terrorism financing and cybercrime investigations may be helpful for identifying funders and intermediaries and ultimately disrupting the mechanisms that incentivize violence.
Finally, researchers and media outlets must carefully assess the Alliance’s activities. They should avoid uncritically amplifying its propaganda and self-presentation. Its members routinely exaggerate their reach, claim responsibility for attacks without evidence and exploit media coverage to bolster their notoriety and attract new recruits. Public reporting on this subject should therefore clearly distinguish verified activity from uncorroborated claims, be cognizant of the possibility of state-backed information operations and manipulation, and avoid uncritical coverage of the network that may inadvertently elevate their status.
Ultimately, the Alliance represents an effort to impose greater organization, capability and ideological direction on an already dangerous but highly fragmented online ecosystem of nihilistic violence. While the available evidence does not conclusively prove that the Alliance is entirely controlled by Russia, there are legitimate indicators that Kremlin-linked actors are using Com participants as deniable instruments of violence and disruption. The central challenge is to counter this exploitation without losing sight of the vulnerable, youth-driven online milieu that makes it possible.
