top of page

Migration as a Weapon: 

From Belarus to the United States

By Travis Franklin
Published September 14, 2026

A 30 Minute Read

Three Years in the Making

Act One: The Playing Field

At the beginning of 2024, the United States Congress debated another aid bill for Ukraine. Below are samples of the online narratives that emerged on social media during the debate.

_________
 

“The boarder is invaded everyday by cartels, drugs, and human traffickers…Now illegals are receiving 50 billion in prepaid cards!”

 

“They leave the borders open for Cartels, coyotes & terrorists to enter the U.S., but send billions to Ukraine to protect their people & their borders…”

 

“what a president [Biden] we have.!! Who woulda thought people actually vote for a man that cares more about those living outside the USA it truly blows my mind.!! And I was far from being a big Trump supporter until the last few years that is…”

 

_________

 

The Instagram accounts that put forth this messaging bear the hallmarks of inauthentic behavior: randomly generated usernames, limited or nonexistent posting histories, multiple former names, and content designed to influence and inflame the public’s political views.

 

The strategic placement, tactical timing, and coordinated messaging suggest that these accounts were part of a broader Russian effort to dissuade the United States from sending more aid to Ukraine. This isn’t new information. 

 

What is new is what I uncovered while examining the origins of the United States immigration crisis, which was conflated with the debate over the Ukrainian aid package.

 

The evidence uncovered by this investigation crosses the Atlantic and has direct ties to other immigration schemes. The timing of which overlaps with an immigration crisis created by Belarus and Russia.

 

A transnational digital infrastructure appears to have been used to identify, recruit, and influence prospective migrants in the Middle East and Africa, and portions of that infrastructure were later reused to target South and Central America to potentially create, influence, and increase illegal migration flows to North America, specifically the United States.

 

The two dominant media narratives surrounding the root cause of the U.S. immigration crisis are attributed to the increased sophistication of human trafficking networks (in the U.S. also referred to as Coyotes), or the relaxation of travel restrictions from COVID. 

 

I found neither explanation sufficient to explain the magnitude of what we were seeing, so I began investigating. What I uncovered led me to Europe.

Act Two: The Belarusian Affair

The term hybrid warfare, or gray warfare, refers to the use of indirect attacks, or attacks that lie below the traditional threshold for war. These maneuvers are not physical altercations between adversaries but are carried out covertly: espionage, cyberattacks, and exploiting political divisions among allies, to name a few. The term encompasses operations that occupy the gray area, somewhere in the middle of black and white, between peace and full-scale war. 

 

On May 23rd, 2021, a flight over Belarusian airspace was forced to land due to a fabricated bomb scare. When it was revealed that Belarus had orchestrated the scheme to arrest a dissident journalist on board the aircraft, the EU responded with sanctions. 

 

In response, the President of Belarus appeared to admit to weaponizing migration flows in retaliation. Later, it was confirmed that Belarus funneled migrants from Africa and the Middle East into Belarus, where they were then transported toward Poland and forced to cross the border—in some cases, at gunpoint.

 

The migrant crisis caused widespread consternation in the countries that were targeted, namely Poland, Lithuania, and Latvia, and sent political shockwaves throughout the rest of Europe.

 

Many migrants died while attempting to cross the Belarusian border into the EU.

 

It is also worth noting that on May 28th, 2021, the same day the Belarusian President, Alexander Lukashenko, acknowledged that he would use migration as a weapon, he met with Vladimir Putin, who offered his support against Western sanctions.

 

Days later, on June 3rd, the heads of both the Russian and Belarusian intelligence agencies met to declare a new era of cooperation between the two countries. After this meeting, the operational capacity of the Belarusian Affair increased substantially as online efforts ramped up to facilitate migrant movements from the Middle East. It is currently unknown whether Russia and Belarus were behind these social media efforts.

 

An important point to note here is the timeline. Later reporting would indicate that the Belarusian Affair predates the forced landing of the Ryanair flight. Lithuanian National Radio and Television reported that Belarusian government officials were laying the groundwork as early as May 5th.

 

Intercepted communications obtained by journalist Tatsiana Ashurkevich for Politico indicate that Belarusian authorities knew about the migrant operation for months before it was in full swing in June 2021.

 

This suggests the migration plan was partially operational before the plane’s forced landing, which the Belarusian President cited as the reason for weaponizing migration flows.

 

So, which is it?

 

Was the Belarusian Affair weaponized in response to the EU sanctions following the Ryanair incident? Or was it planned ahead of time, pre-built to be used as a weapon?

Act Three: The Canadian Operation

On February 15th, 2022, two domains were purchased and later used to target people in Central and South America looking for work abroad. These websites did two things. First, they made promises such as guaranteed jobs, free healthcare, housing, food, and help with immigration paperwork. Second, they collected the user’s information and required them to share the message with friends.

 

Initially, these websites claimed to help visitors (“users”) find job opportunities in Canada. Users were instructed to fill out an application and were then forced to share a message with their friends via WhatsApp; otherwise, their “immigration paperwork” wouldn’t be processed. After inadvertently spamming their friends, nothing happened. The user’s data was collected, and they were left waiting. No immigration paperwork ever came through; news organizations reported the websites as fraudulent.

 

The interesting part here is the timing. Canada did put out a press release on February 14, 2022, stating its immigration targets for 2022, 2023, and 2024, including a target admission rate for 2022 of ~450,000 permanent residents.

 

The social media posts driving traffic to these websites mirror this press release almost exactly, but add the figure 670,000, claiming it was the number of jobs currently vacant and needing to be filled. 

 

Canadian authorities have no idea where the 670,000 figure came from. No such metric existed. Further, these posts misconstrued claims about free housing, free healthcare, and visa applications.    

 

On February 16th, 2022, the Internet Archive captured a screenshot of one of the sites, trabajofinanzasjuegos.com, showing that it was live. 

 

Now the timeline gets extremely interesting because the Whois record for that domain did not exist before 2/15/2022. This means it was created and purchased for the very first time on February 15th, just twenty-four hours after the Canadian press release. 

 

If this were a conventional human-trafficking operation, it would require an unusually sophisticated, rapidly coordinated, and scalable operation requiring the following:
 

  • Multilingual staff routinely monitor government press releases for new immigration-related information. 

  • Once captured, the press release must be translated and disseminated to operational staff.

  • Decision-makers must decide quickly whether to weaponize said information.

  • Information must be translated and stylized for public release, modifying the language to increase its strategic ability to lure targets by adding false incentives (free healthcare; 670,000 pre-existing vacant jobs, etc.).

  • Software engineers must be ready at a moment’s notice to procure domains and deploy websites to capture the personal data of potential migrant targets.

  • Social media campaigns must be in place to drive traffic towards these websites. 

 

The first press report on the large-scale social media drive appeared on 2/17/2022. This is breathtakingly fast. Within 72 hours, the operation was so successful that it caught journalists' attention.

 

I have worked as a software engineer, so I speak from firsthand experience when I say pulling something like this off requires an extremely organized, efficient operation. More telling, money doesn’t appear to be a motivating factor. 

 

If you’re in the business of human trafficking, you would assume making money is the key objective, but not in this case. No one was asked to pay. The only thing collected was the user’s data. One website was active for a few weeks; one was live for only 9 days, then they vanished.

 

If not money, then what was the motive for these websites? 

 

And it wasn’t just these few instances, nor were websites the only drivers of this misinformation. Facebook groups, social media posts, and websites targeted Chile. Mexico. Venezuela. CubaHonduras. Panama. Nicaragua.   

 

Investigative journalists across multiple countries and continents reported this independently. They all recognized it as misinformation, as some sort of scam, but only in hindsight does the larger picture come into focus. 

 

Later, it is revealed that there were coordinated efforts directing migrants towards the United States. These operations mirror the Canadian Operation identically. They even used the same invented number of 670,000.

Act Four: Oceans Apart, or Part of the Same Game Plan?

Programmers make errors. We’ve all pushed code to a repository that shouldn’t have been committed. We’ve all forgotten to rename variables or files, or left comments that should have been deleted. 

 

Normally, such errors do not trigger geopolitical repercussions, but sloppy code is what led me to connect this transnational, trans-Atlantic architecture.

 

Buried in the Internet Archive, you can see the file paths of trabajofinanzasjuegos.com, and in that file path you can see where the software engineer forgot to rename the folder containing the pictures for the Canadian operation.

 

 

 

Code that was reused in the Belarusian migrant scheme and or facilitated crisis.

This codebase had been deployed elsewhere first in a "scam" involving Dubai University. Here is an archived version of that site.

 

Not only were the websites functionally the same, but these websites—one targeting Africa, one targeting South America, and one targeting the Middle East—shared the same photos, the same fake Facebook profiles with glowing testimony about the legitimacy of these “scams,” and the same code.

 

These operations span continents and languages; they cross oceans. Some are written in Spanish, others in English, and even Arabic. 

 

What’s more? Money is not the motive. None of these scams, spanning both sides of the Atlantic, ever asked for money.

 

Who is funding this organization? How is it paying its staff? And what is the goal if not money?

 

Are these websites identifying and collecting information on potential migrant targets interested in working or studying abroad? Absolutely. Are they asking for payment? No. Do these websites share common code-based infrastructure, assets, and functionality? Yes. Are they being managed by the same organization?

 

One might argue that this code could have been stolen or reused by other cybercriminal organizations, but that point is refutable for the following reason:

 

The fake Facebook testimonial photos were hosted on 1.bp.blogspot.com. This creates a dependency for other websites that rely on these assets and poses a significant operational risk, especially given the resources invested to generate such a large volume of social media traffic. If 1.bp.blogspot.com went down or changed its photos, these “scam” websites would face damaging downstream effects and lose partial operability.

 

These are tech-savvy organizations. Why would they rely on assets outside of their own control, especially given the ease of hosting one’s own photos?

 

In my expert opinion as a software engineer, there is only one reasonable explanation for such a gamble: the operators behind the Dubai Scheme were also behind the Canadian Operation. Any other explanation would defy logic.

 

Why, also, would someone compile a list of migrant targets from Africa interested in studying abroad in July 2021?

 

Again, the timeline is informative. The Dubai Scholarship Scheme overlaps with the Belarusian Affair. Three domains that were used for the scholarship scheme were purchased after the June 3rd meeting but before the explosion of Facebook groups promoting the Belarusian migration route in summer.

 

According to Politico’s reporting: “Migrants often flew to Moscow or St. Petersburg under the pretext of studying, before traveling on to Belarus.”

 

Did the operators of these dubious scholarship websites help facilitate the weaponization of migrants to Belarus?

 

We know that Belarus and Russia were behind the Belarusian Migration Affair. Did they use this infrastructure, or the data it obtained, to achieve that crisis?

Act Five: Was America the Target All Along?

The websites that launched in 2022 appeared to target Canada, but the code points to another destination.

 

Africa Check was the first to report on a website associated with the Canadian Operation. This website is notable because its domain and functionality were purchased and partially operational before the Canadian press release. By my assessment, it appears to have been in a beta-test phase in late January and Early February of 2022.

 

This same code was later reused and deployed to trabajofinanzasjuegos.com and ofertatrabajosmasivos.com, suggesting these “scammers” were testing the code and the effectiveness of the messaging in Kenya.   

 

A digital forensic analysis of these websites reveals a few striking details. 

 

Regarding the Kenyan site, job-now.make-achange.online:

 

First, the alternative text tag, which gives context to an image for those who are blind or visually impaired, is labeled “Chicago” even though the image is supposed to represent a Toronto skyline. 

 

The original alt tag text was “MTN”, or at least it was on 1/31/2022, and then again on 2/2/22, 2/4/22, and finally on 2/13/22

 

But in August, once you’ve submitted your “application” you’ll notice the change. Not only is the Toronto Skyline tagged as alt=“Chicago”, but so is the Canadian flag. 

Photo of Canadian disinformation website where the image is incorrectly tagged as Chicago.
Photo from Canadian disinformation website that tags the Canadian flag as a Chicago item.

I have years of experience working with frontend code, and you’d be forgiven for thinking this was a copy-and-paste error. When coding, it’s common to copy the entire HTML element, so the original alt tag of “MTN” would have been included if this were a copy-and-paste error. Notice that the width and height did not change. The word “Chicago” was changed manually. But why?

 

The alt text tag also provides search engines with information to rank a website within a geographic area or for a search term. For instance, if someone searched for “jobs for immigrants in the US,” a search engine in 2022 could not recognize the images on the website; instead, it would use the alt text tag to interpret the image and rank the website accordingly, surfacing it for people looking for work in America. 

 

Weighing the other technical possibilities, in my judgment as a frontend engineer, this was an intentional design decision to “place” the website in the United States. It helps expose the website to people interested in migrating to the United States, not just to Canada. This change was documented around the same time social media operations began directing migrants to the United States in late summer and early autumn of 2022. 

 

Canada is also misspelled in the image file. Search engines rely on image file names to rank websites; given the “Chicago” attribution, this raises the prospect that this was done on purpose to diminish this site’s association with Canada and to increase its association with America.

 

Additionally, the image is not of Canada. It appears to be of New York City. Someone photoshopped an image of the CN Tower in Toronto (far left) over an image of New York. You can see One World Trade Center in the middle of the photo.

Photoshopped image where the CN Tower is placed near a NYC skyline.

Why photoshop an image of the CN Tower over NYC? Why not just use a photo of the real Toronto Skyline? Why tag the picture as Chicago? Why conjure an image of America if you are in fact trying to recruit immigrants for Canada?

 

The image above also contains the words “Massive Job Opportunities,” which is the literal Spanish translation of ofertatrabajosmasivos.com, which wasn’t purchased until 02/15/22. This suggests the operators behind the Kenyan beta-test site displaying these photos planned to transition the operation to Latin America from the beginning, before the press release.

Image from transnational digital infrastructure that displays the words "Massive Job Opportunities."

Inside the HTML, you will see a piece of code that is “commented out” in green with two preceding slashes (//). We will see this code on the other websites targeting South America. This is the digital equivalent of a fingerprint.

A snippet of code that has comments which serve as a digital fingerprint.

Finally, in the code of the Kenyan beta website, we find remnants of developer notes written in Serbian.

An image of code with comments written in Serbian.
A second image of code with comments written in Serbian.

Act Six: Where is the Smoking Gun?

There isn’t one yet, but it appears that a weapon of gray warfare was used. There are digital fingerprints and narrative ones—everywhere.
 
The number of interconnected websites and digital trails I uncovered goes far beyond what I’ve reported here. There are dozens of websites, some overtly malicious and some that appear innocuous, but whose true intentions are to direct traffic to these “data-farming” websites. This organization is sprawling; it bounces across continents, traverses language barriers with ease, and has the sole apparent goal of capturing data from people interested in migrating.
 
During the U.S. debate over Ukrainian aid in 2024, the conflation of the immigration crisis at the U.S. southern border and the Ukrainian aid package struck me as odd. More specifically, it struck me as oddly convenient for Russia that we had an immigration crisis that drew our attention away from the ongoing situation in Ukraine.
 
The language on the “Canadian” websites in February of 2022 promised jobs, free housing, healthcare, and help with immigration visas, which was the exact same language used two years later, but this time as a political attack in the United States during an incredibly pivotal time for Ukrainian aid.

An image of disinformation social media accounts weaponizing immigration in order to deplete support for Ukraine.

This serves as a narrative fingerprint. One that traces a line from the fraudulent websites in 2022 to these seemingly fake social media accounts in US battleground states in 2024. These accounts used the same selling points in South America but repurposed them as attack lines against political figures in the United States, specifically Democrats.

 

Is this a coincidence? Did these pro-Russian accounts capitalize on a growing crisis? Or was the crisis created so that they could exploit it?

 

More importantly, how did these pro-Russian accounts know the messaging being used in 2022, given that the websites were only active for a few months? How did they surface the exact same narrative language to weaponize two years later, especially since this operation was almost entirely conducted in Spanish?

 

Did they have a hunch? Did they dispatch their Spanish-speaking propagandists to go looking for talking points in South America that were two years old? That would be an odd move given that they were in a full-scale war at that point.

 

Did they stumble upon these scams and decide to weaponize this language? Or did they invent these websites to instigate the crisis in the first place so that it could later be weaponized politically?

 

It is also worth noting that these “programs” that provide free housing, hotels, healthcare, food, and jobs to migrants simply do not exist in the United States. That narrative, like the 670,000 figure, was entirely invented.

 

Lastly, we have this website: hbomaxtipohosting.com.

 

This Spanish-language site was used to spread rumors and fake news articles about Canadian immigration. It also contained articles about traveling to the United States and the impending invasion of Ukraine.

 

Buried in the HTML are remnants of a news article that appears to serve as a reusable template. The text is mangled, clearly ripped apart and repurposed from the original article, which was intended to explain how migrants could relocate from Belarus to the Republic of Latvia.

 

The name Republic of Latvia appears to have been replaced with Canada, which is why it now reads Republic of Canada. The mangled article also references a Latvian newspaper, Dienas Bizness, and compares wages between Latvia and other Baltic countries. This “template” comes from a Russian source.

 

Why would a Spanish-language site copy a Russian article on immigration, then repurpose that article to fit a Canadian immigration scam? Surely, if the site were managed solely by Spanish speakers, there would be other templates for them to copy. This “scam” involved North America and South America; why are Russia and Eastern Europe in the mix at all?

One possible explanation is that this codebase was designed to identify migrants from Africa and the Middle East, funnel them into Belarus, and then into Latvia. Once that operation was complete, it was repurposed to target North America.

Act Seven: So, Whodunnit?

In Belarus, once the decision was made to use migration as a weapon, the groundwork was already in place. All it took was someone flipping the switch to exploit the existing infrastructure.

 

The European Commission has formally identified Russia's weaponization of migration as a hybrid-warfare tactic directed against the European Union.

 

Did Russia and Belarus use data from these websites in order to fire their hybrid weapon? Was it then repurposed to target the United States and Canada?

 

This network defies expectations for a criminal enterprise because it did not directly seek money. Given the surrounding context, the most compelling theory is that these websites existed solely to compile a list of targets interested in migrating. That data does have value, but only to other human traffickers or criminals. Who else would want to purchase that information?

 

Airlines? Moving companies? Legitimate immigration attorneys? What legitimate business needs this type of data, especially given that it was collected fraudulently?

 

And if a criminal organization was collecting this data, why not collect the money first, then resell the list later? Why not reel in the catch when you have them on the line, as they so clearly did with each target? Why not ask for payment then, in the moment, as they are giving you their name, address, and contact information?

 

The Canadian Operation mirrors the Belarusian Affair not just in technical design, but in that the crisis advanced a strategic geopolitical goal of the Kremlin—a destabilized United States.

 

The operational cadence also aligns with the Belarusian Affair. The groundwork was laid quietly beforehand; an “inciting incident” occurred (the forced landing of the plane); an onslaught of social media activity drove engagement; and a wave of migrants appeared. 

 

In the Canadian Operation, some websites were quietly up and running; the “inciting incident” was the Canadian press release. Then more websites deployed targeting South and Central America, complemented by an onslaught of social media activity that furthered the campaign. Months later, more waves of migrants appeared on the U.S. Southern Border. 

 

This maneuver created a pressure point that Russia’s American-based covert social media accounts could exploit, providing political cover for the U.S. to withdraw support from Ukraine. It also created political narratives that aligned favorably with Donald Trump’s reelection campaign, which Russia has repeatedly supported in the past and again supported in 2024. Russia’s own internal documents explicitly state that its goal was to weaponize immigration for political gain to benefit Donald Trump.
 

  • On 1/31/22, a beta-test website was deployed before the Canadian press release.

  • On 2/8/22, hbomaxtipohosting.com was purchased and code deployed using a Russian template. This site would also help generate leads for migration to North America.

  • On 2/14/22, Canada released a press statement regarding immigration. 

  • On 2/15/22, at least two domains were purchased, one of which was deployed later that same day. The functionality and code are nearly identical to similar operations deployed overseas in Africa and the Middle East during the same timeframe as the Belarusian Affair. 

  • On 2/16/22, the Internet Archive captured images of one, trabajofinanzasjuegos.com, proving its existence and operability and demonstrating the speed and organizational prowess of this group.

  • On 2/17/22, Africa Check reported the viral messaging, proving a social media campaign was well underway.

  • On 2/21/22, Russian President Vladimir Putin formally recognized the self-proclaimed Donetsk People's Republic and Luhansk People's Republic as independent states and ordered troops into the territories under the stated purpose of “peacekeeping.”

  • On 2/24/22, the full-scale invasion of Ukraine took place. 

 

While the intelligence agencies of the world were focused on the impending invasion of Ukraine, no one caught the potential opening salvo of a hybrid war using digital weaponry. 

 

Notably, despite the operatives’ coordinated and thorough efforts to promote migration to Canada, that country did not face a migration crisis comparable to that of the United States. One might speculate, and the evidence also suggests, that Canada served as a cover to compile a target list.

 

The significance of these findings is not that a single piece of code proves who was behind the operation. Rather, multiple independent fingerprints—technical, linguistic, temporal, operational, and narrative—appear to converge on the same underlying operation. An operation that spans continents, crosses oceans, and breaks through multiple language barriers, while generating no obvious revenue from the people it targeted.

 

Who controlled this transnational digital infrastructure, and who ultimately had access to the data it collected? Did they use that data to direct migrant flows? Did they create the migrant flows in the first place?

 

I know exactly where to look, but I’d need subpoena powers to answer those questions.

 

Perhaps the Arizona Attorney General would be interested, given that one of the key websites, trabajofinanzasjuegos.com, was registered in Arizona.

Epilogue: Prebuttal and Future Reporting

Migration to the United States bottomed out in April 2020 but then began to rebound. The crisis exploded in February 2021. This predates these websites by a year. Wouldn’t that suggest that this network was exploiting an existing problem, not intentionally creating it?

 

Perhaps.

 

Perhaps not.

 

Evidence I’ve obtained shows that Russia began laying the groundwork and building the influence-campaign infrastructure needed to sideline the United States as far back as April 2020.

 

The digital asset in question launched on June 3rd, 2020, exactly one year before the Russian and Belarusian intelligence officials would meet. It then began in earnest to prepare on February 21st, 2021, exactly one year out from Putin's big announcement.

More to come.

In the meantime, if you want to know how Russia is using Donald Trump as an asset, that's best covered in a piece of speculative fiction

bottom of page