October 1, 2026 | Memo
FDD Exposes Network of Fake Watchdog and News Websites Advancing Qatari Interests
October 1, 2026 | Memo
FDD Exposes Network of Fake Watchdog and News Websites Advancing Qatari Interests
Qatar’s attempts to buy influence around the world aren’t always subtle or — according to Belgian prosecutors — legal. But that is no secret. What remained hidden until now is that the most vocal critics of the prosecution are not independent news sites, but rather a network controlled by a single creator, likely acting at Qatar’s behest.
On December 9, 2022, Belgian authorities carried out raids in Brussels and arrested several members of the European Parliament (MEPs) and their staffs after uncovering a corruption scheme linked to Qatar.1 Police found around 150,000 euros ($159,000) stored in bags inside the Brussels residence of Eva Kaili — a Greek MEP who was then one of the vice presidents of the European Parliament — and separately caught her father attempting to remove another 750,000 euros (about $795,000) in cash from the apartment.2 Further investigations found that Kaili and her partner, Francesco Giorgi, purchased roughly 7,000 square meters (1.7 acres) of land on the sought-after Greek island of Paros, a purchase investigators suspected may have been used to launder proceeds from the bribery scheme.3 Six days after the raids began, the European Parliament adopted a resolution supporting the ongoing Belgian criminal investigation and calling for broader investigations into foreign interference and corruption linked to Qatar.4 The raids marked the public emergence of a probe that had been underway for more than a year and subsequently expanded into a sprawling, multiyear case.5 To date, none of the cases has gone to trial. The defendants challenged the validity of numerous investigative acts, but a court ruling in February 2026 rejected their efforts, allowing the case to proceed.6
Authorities also determined that former Italian MEP Antonio Panzeri established a human rights nongovernmental organization, Fight Impunity, which served as institutional cover for receiving illicit payments from Qatar.7 Police found approximately 600,000 euros ($635,000) in cash at Panzeri’s residence. In addition, Luca Visentini, then secretary-general of the International Trade Union Confederation, received less than 50,000 euros (about $53,000) in cash routed through Panzeri’s organization.8 Overall, Belgian prosecutors charged five current or former MEPs in connection with the probe.9 The scandal became known as Qatargate.
Less than two months after the first raids, beginning on February 7, 2023, a network of websites posing as watchdog organizations and news outlets began publishing content that attempted to discredit the findings of Belgian law enforcement. The websites claimed that Belgian authorities had fabricated the Qatargate investigation in coordination with Doha’s rival, the United Arab Emirates (UAE), and argued that the scandal should be renamed “Belgiumgate.” The sites consistently framed Qatar as the victim of politically motivated smear campaigns rather than a party to the corruption scandal. Moreover, they consistently inflate genuine friction in the long, slow, and procedurally imperfect judicial process, turning it into alleged evidence of a systemic anti-Qatar conspiracy.
In October 2025, one of the fake watchdogs, NGO Report (ngoreport[.]org), came to the attention of FDD’s Center on Cyber and Technology Innovation (CCTI) when it published articles critical of FDD and added FDD to its “blacklist” of biased organizations.10 NGO Report presents itself as an independent evaluator of other organizations’ objectivity but primarily publishes content targeting those it portrays as aligned with the UAE, Israel, and several other countries, while framing Qatar as the target of disinformation. Based on an investigation of the website’s hosting infrastructure and other technical indicators (see Appendix A), NGO Report appears to share a common creator with at least four other websites, all under the control of a single operator: Anti-Money Laundering Network (amlnetwork[.]org), Brussels Watch (brusselswatch[.]org), Inform Europe (informeurope[.]com), and Evening Star (eveningstar[.]uk). These websites similarly present themselves as watchdogs, investigative, or news outlets and publish overlapping narratives that dismiss the Qatargate corruption scandal and criticize Qatar’s regional rivals while portraying Qatar in a favorable light.
An advertisement on Evening Star for an obscure electric scooter website, electricscooterx[.]com, turned up a half-dozen additional sites in the Qatar-aligned network. The ad for the scooter site stood out both because of the site’s obscurity and because Brussels Watch and Inform Europe either currently or previously ran ads for it.11 An examination of other websites that advertise electricscooterx[.]com led to Nordic Rights (nordicrights[.]org), another purveyor of Qatar-aligned content. A technical investigation into nordicrights[.]org (see Appendix B) surfaced five additional websites that appear to have been created and operated by the same entity: Dagblad Bergen (dagbladbergen[.]com), Fokuset (fokuset[.]com), Bureau de Presse (eupressdesk[.]com), L’Europe Libre (Leuropelibre[.]com), and Le Parisien Temps (Leparisientemps[.]com).
All websites in this secondary network present themselves as regional news or watchdog outlets and advance overlapping narratives aligned with Qatari interests.12 Nordic Rights and Fokuset portray themselves as Scandinavian human rights or commentary websites and publish content alleging that the UAE orchestrated reputational attacks against Qatar. Dagblad Bergen presents itself as a Norwegian digital newspaper but frequently highlights Qatar’s labor reforms while downplaying criticism of Doha. Bureau de Presse, L’Europe Libre, and Le Parisien Temps operate as French-language or multilingual news sites that criticize the UAE and Israel and praise Qatar as a constructive diplomatic actor. This secondary network is less developed — its websites generally have less content and are less polished — as well as older than the main network. The same person who developed the primary network almost certainly created all of the websites in the secondary network. The clearest indicator is a common email address that connects the secondary network to the individual who developed multiple websites in the primary network. (See Appendix C.)
None of the sites in these two networks appear to acknowledge any connection to the others, nor do they appear to identify their owners. As of August 17, 2026, none of the sites appears to have associated legal entities, such as registered nonprofits. None of the sites appears to identify a named editorial staff. AML Network lists purported contributors, including Pulitzer Prize-winning journalists and other prominent financial-crime experts, whose apparent involvement seems implausible given the site’s low quality.13 Other sites rely largely on generic, unverified, or seemingly inauthentic WordPress author profiles. Most sites also do not list mailing addresses or physical locations. Fokuset lists an address at a Stockholm building that houses a Regus business center offering virtual-office and mail-address services.14 One NGO Report PDF also lists a commercial mailing address at a New York virtual office.15
However, the sites do share technical signatures and other features suggesting centralized creation and control by the same operator. The individual who created the websites appears to be a Bangladesh-based web developer and digital marketer who, curiously — despite the anti-UAE angle of many of the sites — also claims to spend part of his time in Dubai. The creator appears to be a commercial actor rather than ideologically motivated, raising the question of who pays for the network (see Appendix C).
What is clear is that whoever pays for these sites seeks to advance Qatari interests. Researchers have exposed pro-Qatari social media botnets in the past.16 Moreover, CCTI recently attributed to Qatar the operation of an open-source intelligence platform (OSINT) known as Eekad, which is highly active on social media.17 The networks detailed in this report, however, appear to represent the first documented instance of a Qatar-aligned actor relying on websites representing fictional organizations to advance its interests.
The 2025 U.S. National Security Strategy calls for “protect[ing] this country, its people” from “hostile foreign influence,” including “influence operations.”18 The Qatari-aligned operation detailed in this report — which CCTI will refer to as the “Belgiumgate” or “Belgiangate” networks, after a term the networks use to discredit Qatargate — has not yet built a strong following. However, in addition to seeking to discredit the Qatargate scandal, it is openly calling for institutional action, such as sanctions, against American citizens and organizations, while actively disparaging their reputations.19 This merits a response from U.S. policymakers, especially when the network appears to advance the interests of Qatar, which is officially a U.S. ally.
Clues to the Identity of the Networks’ Creator
Most websites use domain names, such as google[.]com or apple[.]com, because letters and words are easier to remember than the numerical Internet Protocol (IP) addresses that computers use. The Domain Name System, or DNS, is often described as a phonebook for the internet: It helps translate human-readable domain names into the machine-readable IP addresses that computers use to locate the server or online service that hosts a website’s content.
By querying DNS records to identify a website’s IP address, analysts can often identify other sites that have shared the same IP address, suggesting that the websites may share hosting infrastructure. This method shows that the same server that historically hosted ngoreport[.]org also hosted eveningstar[.]uk, amlnetwork[.]org, brusselswatch[.]org, and informeurope[.]com (see Appendix A). That these domains were associated with the same server is not, in itself, sufficient evidence to prove that the same individual or organization created them. However, other technical aspects of the websites further strengthen the assessment that they are the work of one hand (see Appendix A).
For example, all five websites were registered on the same day, and four were registered within 16 seconds of each other. All five websites also began in quick succession to use a service called Cloudflare, which hides the true IP address of the site’s web-hosting servers. Additionally, the name “Anisur” appeared in the metadata of various files across all five websites.
As noted above, advertisements for electricscooterx[.]com led to the discovery of a secondary Qatar-aligned network consisting of six websites. As with the main network, the websites in the second one shared web-hosting servers, registration patterns, and other common technical traits (see Appendix B).
All six active websites in the secondary network also used WordPress to publish their content. WordPress websites can sometimes expose information about their users, including links to Gravatar profile images tied to those users’ email addresses. Gravatar is a service that allows users to associate an avatar image with an email address, so the same profile image can appear across different platforms that support Gravatar, such as WordPress and Slack. Gravatar avatar links do not necessarily show the user’s email address in plain text, but they may include a unique identifier generated from the user’s email. Since the same user email addresses appeared in avatar identifiers across multiple websites in the second network, it is highly likely that the same person or team set up or managed those sites (see Appendix C).
One of the email addresses associated with these Gravatar identifiers is mediasolutionsnordicm@gmail[.]com. A registrant named “SM Asif” used that same email address to register fokuset[.]com, providing a key clue to the apparent creator of both the primary and secondary networks. The same registration records also listed a phone number that OSINT Industries, an open-source intelligence platform, linked to accounts using the name Asif Hassan.
Putting these pieces of information together led to a man named SM Asif Hassan. Based on his online presence, Hassan appears to be a Bangladesh resident who spends part of his time in Dubai (see Appendix C). Looking at LinkedIn profiles and websites associated with Hassan, CCTI found that he had once advertised the creation of Eveningstar[.]uk. Archived copies of AcorNovusIT[.]com, a company website associated with Hassan, show that the site once advertised NGOreport[.]org as a client.
Although the websites do not explicitly identify Hassan as their creator, these apparent operational-security lapses strongly support CCTI’s assessment that Hassan, possibly with associates, created and managed these networks.
The Network’s Reach and References From AI Chatbots
The three websites across both networks that achieved the greatest reach appear to be AML Network, NGO Report, and Brussels Watch. According to web-traffic analytics tool Similarweb, AML Network had over 15,000 visitors in July 2026, while NGO Report had slightly more than 10,000 and Brussels Watch slightly over 600. As of April 28, 2026, YouTube channels associated with NGO Report, AML Network, and Brussels Watch have gained a combined 35,983 views across 715 videos.
It is unclear whether the networks have successfully undermined impressions of the legitimacy of the Qatargate investigation in Europe or damaged the reputations of the UAE, Israel, or Saudi Arabia. NGO Report, AML Network, and Brussels Watch, however, have successfully gained citations by AI tools, a pair of British think tanks, and a credit-rating platform, increasing their appearance of legitimacy.
For example, Chatham House, the London-based international affairs think tank, cited NGO Report in a 2025 analysis.20 Additionally, the Royal United Services Institute, the world’s oldest defense and security think tank, cited NGO Report in a 2026 publication.21
Similarweb data indicates that all referral traffic — traffic arriving from websites rather than search engines — directed to NGO Report and Brussels Watch in November 2025 came from ChatGPT. However, it is unclear what led ChatGPT users to the sites. CCTI also tested whether ChatGPT would cite content published by AML Network. CCTI selected a question that closely matched the subject of an AML Network article, asking, “Is Aisha Yousef al-Mannai a PEP?” with PEP being a reference to “politically exposed person.” ChatGPT cited AML Network several times in its response, demonstrating that the site’s content could appear in answers to relevant user queries.

Screenshot from Similarweb showing ChatGPT as a top referring website for ngoreport[.]org.

Screenshot from Similarweb showing ChatGPT as a top referring website for brusselswatch[.]org.
Grokipedia, a Wikipedia alternative launched by Elon Musk’s xAI that reportedly relies largely on the Grok large language model to generate articles, also cites NGO Report, AML Network, and Brussels Watch at least 45 times across various topics.22 The ChatGPT and Grokipedia references suggest that multiple AI tools may play a role in directing users to NGO Report, AML Network, and Brussels Watch’s claims.

ChatGPT response citing AML Network as a source.
Why the Websites Appear Inauthentic
Several websites in the networks appear to have been created haphazardly, demonstrated by blank “About” sections, scrambled Latin-based placeholder text (commonly known as Lorem Ipsum), broken social media links, and other irregularities. The incompleteness of these websites suggests they were created in a hasty and unprofessional fashion, reinforcing CCTI’s assessment that these websites likely represent inauthentic media outlets. Moreover, as of August 25, 2026, none of them appears to have associated legal entities, such as registered nonprofits.
For example, Evening Star UK demonstrates clear creation errors with all icons linking to social media accounts. In addition, the “About” page and the “Contact” page are not working and one webpage includes Lorem Ipsum.23
Inform Europe displays similar unfinished aspects. Its “About” and “Contact” sections are blank, Lorem Ipsum appears at the top of five of the seven content categories, and all social media profiles associated with the website are broken.24 Additionally, an author named “SEO Guy” is listed as the author of over 400 of the website’s articles.25
Nordic Rights lists a generic placeholder contact email address (info@example[.]com), includes broken social media buttons, and features an “About Us” section that appears to be a default text rather than an original description.26 Additionally, Nordic Rights lists an article category titled “vv” that exhibits filler content.27 Fokuset’s website also includes broken social media buttons and features an empty “Top Insights” section in the footer.28
Several French outlets in the networks display similar issues. Le Parisien Temps includes Lorem Ipsum filler text and broken social media buttons.29 L’Europe Libre and Bureau de Presse display placeholder and filler articles. For example, Bureau de Presse’s website features an article titled, “Why mom was right about cool tech gadgets.”30 Additionally, Bureau de Presse features apparent default text in its footer.31
Turning Qatargate Into ‘BelgiumGate’: Attempts To Discredit Belgian Authorities
According to Doha, Qatargate was an artificial scandal. From the outset, Qatari officials publicly rejected any association with the case. In December 2022, the Qatari Mission to the European Union stated that Qatar “categorically rejects any attempts to associate it with accusations of misconduct,” calling such claims “baseless and gravely misinformed.” Similarly, Qatar’s foreign minister, Sheikh Mohammed bin Abdulrahman Al-Thani, stated in January 2023 that Qatar “should not be dragged” into what he described as an internal European matter, describing allegations of Doha’s involvement as having “no basis.”32 One of the preeminent focuses of the network — composed of the following websites — exposed by CCTI has been its effort to assert Qatar’s innocence and present claims that Belgian officials have waged an illicit campaign to frame Doha.
Brussels Watch describes itself as a watchdog that monitors the foreign affiliations of European Parliament members and claims not to accept government funding. Numerous articles on the site rebrand Qatargate as “Belgiangate” or “Belgiumgate,” making statements like “the startling truth is that Qatargate was Belgiumgate from the very beginning.”33 Several earlier articles assert that the UAE and Belgium engineered the controversy.34 However, there appears to be no credible public evidence backing this claim that the scandal resulted from an Emirati-Belgian conspiracy. Newer articles describe “Belgiangate” as an ongoing institutional failure by, for example, claiming Belgian officials leaked sensitive Qatargate materials and exposed MEPs to reputational harm.35
Brussels Watch also accuses Belgian authorities of hacking the email accounts of Qatari and Mauritanian diplomats, spying on European members of Parliament, violating diplomatic immunity, suppressing free expression, and undermining democracy. Moreover, Brussels Watch published a 121-page report in September 2025 alleging that Belgium exploits its position as the institutional center of the European Union to exert disproportionate influence over policymaking through lobbying networks, institutional access, and affiliated organizations.
Evening Star, which describes itself as a UK news website, also frequently rebrands Qatargate as “Belgiumgate,” or “BelgianGate.”36 Fabrication of the scandal is a persistent theme, with some pieces claiming the Belgian government colluded with Moroccan intelligence.37
Several articles cast doubt on the credibility of Michel Claise, a former judge in the Qatargate case.38 Claise recused himself after one suspect’s lawyer raised allegations that Claise had a conflict of interest.39 Ultimately, Belgian prosecutors concluded there was no concrete evidence that his impartiality had been compromised. He withdrew as a precautionary measure, not due to a finding of misconduct.40 Another piece criticizes Politico’s coverage of Qatargate,41 while a third claims diplomats are not safe in Belgium due to alleged surveillance and intelligence-sharing with foreign governments, particularly in the Middle East.42
While a majority of Evening Star’s content criticizing the integrity of the Qatargate investigation was published in 2023, the site started aggressively publishing similar content again in late 2025 — a trend visible across the network. These more recent articles build on the theme of institutional breakdown, alleging “prosecutor-media collusion” and claiming that prominent Belgian outlets like Le Soir and Knack acted as facilitators for leaked investigative materials.43 Several articles focus on prosecutor Raphael Malagnini, alleging ties to “intelligence-linked actors” and suggesting he may have connections to foreign intelligence services.44 Malagnini previously oversaw the case before accepting a different post.45

Partial screenshot of archived copy from December 19, 2025, of Evening Star’s special report, “Unmasking Collusion Between Belgium’s Government and Media: The Qatargate Deception,” originally published on October 10, 2023.
Inform Europe has a blank “About” section but presents itself as an online news website focused on European affairs.46 It too reframes Qatargate as “BelgianGate.” A recurring focus of Inform Europe’s content is the alleged relationship between Belgian prosecutors, anti-corruption officials, and journalists from outlets such as Le Soir and Knack.47 Articles claim that confidential documents, wiretap summaries, and raid plans were leaked to journalists and published in coordination with law-enforcement actions.48 The site also directly attacks the former prosecutor Malagnini and senior officials within Belgium’s Anti-Corruption Office.49 In addition, the site occasionally seeks to burnish Doha’s reputation, with an article that praises Qatar’s “unwavering belief in dialogue,” its “commitment to peaceful resolution,” and mentioning a $500 million contribution to UN humanitarian programs.50
L’Europe Libre presents itself as a French-language online news and cultural outlet.51 It often publishes near-identical articles to Inform Europe, though written in French. Even the graphics and images are often the same. From December 15 through December 30, 2025, the site published a series of articles alleging that the scandal was driven not by foreign corruption but by misconduct within Belgium’s own institutions.52 Like Inform Europe, L’Europe Libre repeatedly accuses journalists from Le Soir and Knack of serving as amplifiers for leaked judicial and intelligence material.53
Bureau de Presse presents itself as a French-language news website, though with articles in English and several in Swedish. Its content is little different from other sites in the network, branding the scandal as “BelgianGate.” One article claims investigations into the Qatargate scandal will likely reach a legal impasse and collapse.54 Another asserts coordinated leaks influenced legal proceedings.55 Another article alleges that a former anti-corruption official acted as an intermediary between prosecutors and journalists.56
Nordic Rights presents itself as a Scandinavian human rights and social-policy news outlet focused on Sweden and the wider Nordic region. It asserts the implicated MEPs were victims of an orchestrated influence campaign conducted by Swiss private intelligence firm Alp Services on behalf of the UAE.57 According to a report in The New Yorker, the UAE has paid Alp Services to discredit individuals and organizations that it perceives as linked to Qatar or the Muslim Brotherhood.58 What remains unverified, however, is the claim that Alp Services fabricated the Qatargate criminal case or caused the Belgian investigation.
One piece attacks Claise, the judge, and references a separate “Kazakhgate scandal,” noting that Qatargate “is not an isolated occurrence.”59 “Kazakhgate” appears to allude to a Belgium-linked influence-peddling scandal involving allegations that a former Belgian minister helped a Kazakhstan-linked businessman obtain a favorable settlement in a criminal proceeding.60
Like other sites in its network, Nordic Rights sharply increased its output of “BelgianGate” content in late 2025. Between December 15, 2025, and January 2, 2026, it published at least 28 articles on this topic, featuring the standard allegations of leaks, media-prosecutor collusion, and failures within Belgium’s justice system.61 Specific targets once again include journalists at Le Soir and Knack.62
Fokuset presents itself as a Sweden-based online news outlet with a section dedicated to human rights. It criticizes Claise for allegedly collaborating with Belgian intelligence, a claim that does not appear backed by credible public evidence.63 It also claims Claise “misled fellow judges” and “concealed key documents” to undermine the impartiality of the investigation, without clearly identifying an alleged motive.64 Like other sites in the network, Fokuset also criticizes Malagnini, alleging the existence of a “war room” that coordinated raids, intelligence handling, and media exposure to shape public narratives before trial.65 Similarly, the site mirrors its counterparts’ accusations against Le Soir and Knack.66 It also runs positive stories about Qatar, including an article claiming that Qatar reformed its labor laws to improve conditions for migrant workers before it hosted the World Cup.67
Dagblad Bergen presents itself as a Norwegian-language online news outlet and has published several articles that focus on Qatar’s labor reforms, specifically highlighting the country’s efforts to improve migrant worker protections surrounding the 2022 World Cup.68 Like Fokuset, it argues that Qatar should be a model for other Gulf states.69 Another article argues that international criticism of Qatar’s labor practices fails to acknowledge and contextualize similar abuses in other countries that have hosted major sporting events, such as Brazil and Russia.70
NGO Report describes itself as an NGO watchdog and claims it “receive[s] zero financial support from external organzations, corporations, or governments.” Supposedly, its “team consists entirely of dedicated volunteers.” The organization’s motto is “Promoting accountability and trust.”71 NGO Report’s main project is publishing blacklists of biased NGOs. It lists 157 organizations it calls pro-Israel, 97 labeled pro-Saudi, 146 pro-Emirati, 7 pro-Russia, and a single pro-France group. A page is reserved for pro-China NGOs, but none is listed.72 NGO Report also publishes articles, which adhere to the theme of presenting Qatar as the victim of smear campaigns, often asserting the attacks are at the behest of the UAE.73
NGO Report previously had a blacklist on its site devoted to “Pro-Qatar NGOs,” which had 10 entries in an archived version from October 2025. The list includes the Al Jazeera network and a number of influential U.S. think tanks.74 As of May 8, 2026, the blacklist of pro-Qatar NGOs no longer appears on the website.75 NGO Report also appears to have taken down articles on its website discussing allegedly pro-Qatar NGOs.76 In addition to its blacklists, the site maintains what it calls an “NGO database” with lists of organizations based in 19 countries, although several of the lists have no entries, including the list for Qatar.77
Promoting Anti-UAE Narratives
Tensions between Qatar and its neighbors culminated in the 2017 Gulf crisis, when the UAE, Saudi Arabia, Bahrain, and Egypt imposed a political and economic blockade on Qatar, accusing it of backing Islamist groups and using state media to undermine regional stability.78 Although the blockade formally ended in 2021 with the al-Ula Declaration, and Gulf states later adopted a united stance against Iranian attacks in 2026, tensions have remained, driven by Qatar’s continued support for political Islam and accommodating stance toward Iran.79 Among Qatar’s neighbors, the UAE has been the most vehement in its criticism, making Abu Dhabi the logical target of reputational attacks from Qatar-aligned actors.
Many NGO Report articles place particular emphasis on alleged different standards applied to the UAE and Qatar. One piece criticizes the Arab Federation for Human Rights (AFHR) for promoting a pro-UAE agenda and unfairly targeting Qatar’s National Human Rights Committee (NHRC).80 Another frames Europe as unfairly applying greater scrutiny to Qatari influence than UAE influence in the European Parliament.81
NGO Report also posts letters that it appears to have sent to the United Nations asking it to investigate groups that it says are proxies for the UAE or that align with Emirati interests, with the goal of barring them from participating in the UN’s Human Rights Council.82 Less frequently, the site calls for similar action against groups allegedly acting on behalf of Saudi Arabia and Israel.83
Brussels Watch’s homepage includes a section titled “Under the Spotlight” that highlights three webpages with derogatory information about the UAE and Belgium.84 The first spotlighted page lists 150 allegedly pro-UAE MEPs, claiming that many of them “participated in undisclosed, all-expenses-paid trips to the UAE, coauthored policy reports, or advocated for Emirati positions in key debates.”85 Regarding its allegations of undisclosed UAE influence, Brussels Watch writes “notably, this mirrors the ‘Qatargate’ scandal, but on a broader and more institutionalized scale.”86
The second spotlighted page discusses a 121-page Brussels Watch report alleging that Belgium exploits its position as the institutional center of the European Union to exert influence over EU policymaking.87 The third summarizes a 56-page report published by Brussels Watch titled “UAE Lobbying in European Parliament.”88 The full report is available on the NGO Report website but does not list an author. Extracting the metadata from the PDF, however, shows an author named “Haseeb Ullah.” CCTI could not learn anything more about Haseeb Ullah’s identity or his connection to the network.

The cover page of Brussels Watch’s 56-page report presenting alleged UAE lobbying in European Parliament as “undermining democracy and transparency.”
Anti-Money Laundering Network (AML Network) describes itself as an independent financial watchdog group that receives no government funding. One article on the group’s website urges the European Union to “IMMEDIATELY re-instate the UAE to high-risk status” for money laundering and illicit finance.89 The site also published three long-form reports alleging that the UAE engaged in various forms of illicit finance, including trading and laundering gold to finance the Rapid Support Forces in Sudan, a group that has committed genocide according to the U.S. State Department.90 As with Brussels Watch, none of these reports lists an author.
Evening Star UK has highlighted a report from an outlet called Orient XXI that documented alleged Emirati efforts to influence France, claiming that “the UAE’s lobby incites against Qatar and the Muslim Brotherhood, waging a fierce campaign against political Islam as a whole.”91 The article warns that “narratives associating the Muslim Brotherhood with terrorism may contribute to growing hostility towards Muslims in Europe and potentially destabilize European societies in the long run.”92 Another claims the UAE “financed a smear campaign against Islamic Relief Worldwide,” a charity that the Emiratis designated as a terrorist organization in 2014 and that critics assert the Brotherhood controls.93 Evening Star also highlights accusations against a UAE think tank for recruiting EU officials to act as lobbyists for the UAE, “whitewashing the country’s human rights record.”94
Nordic Rights adds the allegation that the UAE secured its role as host of a major climate conference, COP28, by directing several billion dollars in foreign aid to Asia-Pacific countries and making covert side payments.95
Defending Islamism and the Muslim Brotherhood
Across both Belgiumgate networks, dozens of articles focus on political Islam, or Islamism, and the Muslim Brotherhood transnational movement that pursues the Islamist objective of reshaping government and society to conform with Islamic law, or sharia.96 Qatar has provided financial support and safe haven to figures and organizations associated with political Islam for decades, including the senior leadership of Hamas, which is the Palestinian wing of the Brotherhood.97 As mentioned earlier, in 2017, the UAE, Saudi Arabia, Egypt, and Bahrain blockaded Qatar primarily due to Qatar’s support for political Islam and the Muslim Brotherhood, which they consider a threat to their own stability.98
NGO Report seeks to discredit criticism of the Muslim Brotherhood by criticizing various individuals and organizations for “demoniz[ing] political Islam,” “conflat[ing]… Islamism with violent extremism,” not accepting “ideological pluralism,” and “reinforcing divisive ideological lines within the Muslim world.”99 The site also accuses individuals and organizations of unfairly attacking the Muslim Brotherhood while ignoring failings or rights violations by the UAE and Egypt.100 When blacklisting NGOs, the site often highlights their criticism of political Islam and the Muslim Brotherhood. It even characterizes one organization as a “front in the war against the Muslim Brotherhood.”101
Likewise, NGO Report often claims that criticism of the Muslim Brotherhood advances the UAE’s agenda. The site’s more aggressive pieces accuse those who criticize political Islam and the Muslim Brotherhood of effectively serving as agents of the UAE’s interests. It claims one organization “secretly lobb[ied] with the UAE” by “pressing the EU to tighten its girp [sic] around the neck of Muslim Brotherhood affiliates.”102
Brussels Watch emphasizes alleged Emirati ties to France’s Rassemblement National (RN), the hard-right political party founded as the “National Front” by Jean-Marie Le Pen. Articles claim that RN figures “echo” Abu Dhabi’s longstanding campaign against the Muslim Brotherhood and Islamic activism.103
Multiple near-identical pieces state that RN’s anti-Islamist narrative allows the party to portray alleged Emirati funding, loans, and political coordination as a legitimate security partnership rather than foreign influence. Articles pair these claims with broader allegations of “Emirati lobbying” efforts in France that seek to “stigmatize Muslim Brotherhood-linked organizations as terrorist or extremist.”104
Le Parisien Temps similarly amplifies these claims. In February 2026, the site published two articles alleging financial ties between the UAE and the RN, citing Brussels Watch’s investigation and echoing its claim of 55 million euro ($58.3 million) in UAE-linked financing.105 The articles connect the alleged financing to the RN’s ideological alignment with Abu Dhabi’s opposition to political Islam and the Muslim Brotherhood, while suggesting that Emirati support could translate into political influence.
Two other sites in the network — L’Europe Libre and Bureau de Presse — published nearly identical articles in French alleging a $64 million funding scandal involving RN and ties to the UAE.106
One article in Evening Star claims that Emirati lobbying in France mobilizes media outlets, private companies, and think tanks to amplify anti-Muslim Brotherhood narratives.107 Another alleges that Emirati-linked actors were behind the publication of the 2019 book Qatar Papers, which it describes as part of a smear campaign accusing Qatar of financing Islamic associations across Europe.108 The book, by French journalists Christian Chesnot and Georges Malbrunot, drew on leaked documents from a major Doha-controlled NGO, Qatar Charity, examining the organization’s financing of mosques, Islamic centers, and other projects across Europe.109 The same article by Evening Star names Alp Services — a frequent target of the network — as a key intermediary in these efforts.110
Nordic Rights also targets Alp Services as well as U.S.-based scholar Lorenzo Vidino, claiming that his research on Muslim Brotherhood networks in Europe and their financial links to Qatar served a hidden Emirati agenda.111 A related piece advances the same claim, alleging that the UAE ran a covert influence operation known as “Constellation” to counter the Muslim Brotherhood in Europe and used Alp Services as an intermediary.112
The exception to these trends consists of one article published by Le Parisien Temps framing investigations into Islamist links as legitimate and necessary for defending secularism, transparency, and public security in France.113
Rare Instances of Criticism Targeting Qatar
The narratives outlined above clearly show that both Belgiumgate networks closely align with Qatari interests. However, on several occasions, websites in the networks published content that either criticized Qatari officials or added Qatari NGOs to blacklists. Much of this content was taken down throughout the course of FDD’s investigation, although no evidence connects the investigation with its removal.
AML Network occasionally highlights accusations against prominent Qataris. However, even when it does so, it simultaneously compliments them for other accomplishments. For example, AML Network labels Qatari academic and politician Aisha Yousef al-Mannai as a PEP but also praises her as a “pioneering female political appointee.”114 The site also assures readers “there is currently no credible evidence linking her directly to financial misconduct or money laundering.” AML Network also had an article about the current Qatari emir, Sheikh Tamim bin Hamad Al Thani, that mixed praise with measured critique.115 However, the article is no longer online, and was taken down before CCTI could archive it.
In a related show of balance, AML Network occasionally praises UAE figures while identifying them as PEPs.116 The lone outlier is an article about former Qatari Emir Hamad bin Khalifa Al Thani that draws attention to his alleged use of offshore finance and tax havens but does not explicitly praise him other than noting that “his reign expanded Qatar’s political and economic clout.”117
There are two other exceptions of note to the overwhelming positive treatment of Qatar. On Inform Europe, one article criticizes Qatar’s handling of the 2022 World Cup and describes the event as marked by corruption, governance failures, and human rights abuses.118 On Dagbladbergen, an article discusses the luxury aircraft given to President Donald Trump by the emir of Qatar, arguing that the gesture reflects Qatar’s use of high-profile gifts as a form of soft power.119
Ultimately, these anomalies underscore that the vast majority of the content spread by this network — in particular the content concerning Qatargate, Qatar’s rivals, and political Islam — clearly and strongly aligns with Qatari geopolitical interests.
Attacking Americans and American Organizations
The networks target at least 250 American individuals, organizations, and companies.120 The attacks consist of calls to blacklist, investigate, and even sanction these Americans, accusing them of illicit lobbying or malign influence, or characterizing them as pro-UAE, pro-Saudi, or pro-Israel.
For example, NGO Report speculated in 2023 that then-Senator Marco Rubio’s “support for Saudi Arabia is motivated by financial interests, as he has received campaign contributions from Saudi Arabian donors.”121

Partial screenshot of archived copy from December 16, 2025, of NGO Report article labeling Marco Rubio as a “Pro-Saudi Senator,” originally published on November 27, 2023.
The networks target at least 28 former and current U.S. officials. These include President Donald Trump, former Defense Secretary Robert Gates, former Deputy Secretary of State Richard Armitage, former National Counterterrorism Coordinator Richard A. Clarke, former Special Middle East Coordinator Dennis Ross, former Deputy Defense Secretary John Hamre, and former NSC Senior Director for the Gulf Kirsten Fontenrose.122 The networks also target many current and former members of Congress, such as Senators Jim Inhofe, John Boozman, John Cornyn, and others.123 The main criticism of these targets is alleged lobbying for Saudi Arabia and the UAE or holding a bias in favor of these countries.
The networks also attack at least 90 American think tanks, nonprofits, philanthropic organizations, and advocacy groups, often calling for them to be blacklisted or investigated due to their alleged ties or lobbying linked to foreign countries. For example, the networks label the Hudson Institute, Carter Center, Atlantic Council, Middle East Policy Council, and American Security Initiative as pro-Saudi.124 They label the Wilson Center, Middle East Institute, Anti-Defamation League, International Peace Institute, German Marshall Fund, and Center for New American Security as pro-UAE.125 They label StandWithUs, the Jewish Institute for National Security of America, Foundation for Defense of Democracies, and the American Enterprise Institute as pro-Israel.126
The networks also target at least 59 American companies and law firms. These include Lockheed Martin, CyberPoint International, Capitol Media Group, CACI International, Boston Consulting Group, Booz Allen Hamilton, Boeing, and IBM.127 Targeted law offices include Squire Patton Boggs, White & Case LLP, WilmerHale, Gibson Dunn & Crutcher LLP, and others.128 As with their critiques of other American organizations, the networks attack these law firms for allegedly advancing the cause of, or shielding Saudi, UAE, Israeli, and other foreign or elite interests through legal, lobbying, and influence work. The networks have also targeted American higher education with the network calling for the Massachusetts Institute of Technology (MIT) to be blacklisted and investigated due to alleged Saudi influence and lobbying ties.129 Other targets include the U.S. media outlets FrontPage Magazine, The Tablet (a Christian publication that they appear to confuse with the Jewish publication Tablet), and The Algemeiner, for allegedly disseminating pro-Israel misinformation and propaganda.130
Policy Recommendations: Washington Should Probe Qatari Influence Operations
The 2025 United States National Security Strategy stresses the importance of protecting Americans from “destructive propaganda and influence operations.” While open-source evidence is sufficient to show that the Belgiumgate networks are part of a centrally directed and Qatar-aligned operation, an investigation that employs the full means available to the U.S. government could determine who precisely funds and controls the networks. Given that several websites in the secondary network target French and Swedish audiences specifically, it would be advisable for U.S. officials to partner with the Swedish Psychological Defense Agency and France’s Vigilance and Protection against Foreign Digital Interference Service (VIGINUM), which are dedicated to countering influence operations. In addition to U.S.-European collaboration, European countries will likely want to collaborate with each other through programs such as the European Center for Democratic Resilience, designed to improve information sharing and operational cooperation on foreign malign influence.131
To ensure this issue receives sufficient attention in the United States, Congress should mandate a formal report from the intelligence community (IC), in coordination with the Departments of State and Defense, that examines Qatari-aligned covert influence operations targeting the U.S. and its allies. Specifically, the report should come from the director of national intelligence, in coordination with the secretaries of state and defense, and arrive within 180 days of enactment of the mandate. The House and Senate intelligence and armed services committees, alongside the Senate Foreign Relations Committee and House Foreign Affairs Committee, should have oversight of this process. To facilitate broader public understanding of the issue, both in the United States and abroad, the report should be unclassified with a classified annex if necessary.
Given that the networks target named Belgian magistrates and seek to undermine an ongoing Belgian judicial proceeding, Belgian authorities should assess whether conduct associated with the networks constitutes unlawful interference with judicial proceedings or violates other applicable Belgian laws concerning threats, harassment, impersonation, or unauthorized access.
The European Union has also created a sanctions architecture for foreign information manipulation, although an expansion would be necessary to address the Belgiumgate networks. The framework established under Regulation 2024/2642 covers destabilizing activities linked to the Russian government and therefore cannot be applied to a potential Qatari-aligned operation. Thus, the European Union should establish a country-neutral sanctions framework for serious foreign information manipulation and interference, subject to clear attribution and evidentiary thresholds, so that it has a preexisting mechanism for responding to comparable operations regardless of their country of origin. EU policy is already moving toward a more origin-neutral approach to countering foreign malign influence: in March 2026, the EU Council affirmed that the European Union should be prepared to respond to hybrid threats, which include foreign information manipulation and interference, “irrespective of their origin, scale and intensity.”132
Finally, social media companies, including X, Instagram, Medium, Pinterest, TikTok, and YouTube, should conduct internal investigations, given that the Belgiumgate networks either currently or have previously had a presence on their platforms, and cooperate with relevant European authorities. The European Union’s Digital Services Act requires very large online platforms to assess and mitigate systemic risks arising from coordinated manipulation and inauthentic use of their services. The European Commission should examine whether the platforms on which the Belgiumgate networks maintain, or previously maintained, a presence adequately addressed the networks’ activity and whether their handling of the operation demonstrates compliance with their systemic-risk obligations under the DSA.
Conclusion
Qatar has furthered its influence in the United States and around the world through financial investments, spending, and donations, including at least $400 billion in the United States since 2000. It also employs overt channels of influence, such as its well-known state media outlet Al Jazeera.133 The Belgiumgate networks, however, appear to represent the first publicly documented instance of a covert network of inauthentic watchdog organizations and news websites that specifically advance Qatari interests. Covert influence operations that employ such websites represent a tactic more associated with Russia, Iran, and China. This reinforces concerns about covert Qatari or Qatar-aligned influence raised previously by CCTI through research into the suspected Qatari influence operation known as “Eekad.”134
Considering that Qatar is officially a Major non-NATO Ally of the United States — and that the Belgiumgate networks do not only meddle in European affairs but also directly attack U.S. individuals and organizations — these networks raise serious concerns for U.S. and EU policymakers about Doha’s trustworthiness. These concerns should prompt wider investigations into the threats posed by Qatari, or Qatar-aligned, foreign malign influence.
Appendix A: Shared Infrastructure and Technical Indicators for the Primary Belgiumgate Network
Investigating web-hosting servers is an effective means of discovering websites that may be connected to each other. Web-hosting servers provide the infrastructure that stores a website’s data and transmits its content to browsers or other endpoints upon request. CCTI first discovered websites in the primary network by triaging websites that shared the same web-hosting server as the initial lead, ngoreport[.]org.
Ngoreport[.]org has historically used shared web-hosting servers, not dedicated web-hosting servers. Shared hosting tends to be cheaper than using dedicated hosting, but the result is that it can obscure the connection between multiple related websites.135 Hundreds or even thousands of unrelated organizations will use shared web-hosting servers, making it difficult for investigators to pivot off them to discover related websites.
Seven websites appeared on the shared server located at IP address 162[.]0[.]209[.]106 between February 19 and 21, 2023, one day before and after ngoreport[.]org first appeared on that server.136 Of these websites, brusselswatch[.]org, amlnetwork[.]org, and eveningstar[.]uk shared similar design and content to ngoreport[.]org.

Silent Push, a cyberthreat intelligence tool, showing domain names that first appeared on 162[.]0[.]209[.]106 24 hours before or after ngoreport[.]org first appeared on this server. The domain names are highlighted in red appeared related to ngoreport[.]org upon initial triage by FDD.
A wider search of domain names that appeared 14 days before or after ngoreport[.]org first appeared on 162[.]0[.]209[.]106 surfaced many other websites. Only one of these websites seemed related to ngoreport[.]org, namely, informeurope[.]com, based on design and content. Informeurope[.]com first appeared on 162[.]0[.]209[.]106 on February 8, 2023.

Silent Push showing that informeurope[.]com appeared on 162.0.209.106 on February 8, 2023, which was a little under two weeks in advance of ngoreport[.]org’s first appearance on this server.
Because shared servers can host thousands of unrelated domains, analysis of additional technical indicators is necessary to confirm that the same person or people created and control ngoreport[.]org, brusselswatch[.]org, amlnetwork[.]org, eveningstar[.]uk, and informeurope[.]com. These indicators include overlapping registration and update timelines, shared infrastructure migration patterns, common website technologies, author names found in metadata, and other technical features.
A privacy service called Withheld for Privacy redacts the name of each website’s registrant, meaning the person who registered the website. The use of a privacy service is not suspicious, as many legitimate websites use privacy services, for reasons such as preventing the registrant’s email from receiving spam.137
Despite the redaction, patterns in registration, expiration, and update dates show signs of coordinated creation across all five websites. All five websites have a registration date of February 7, 2023, and four websites have a registration time within 16 seconds of each other.138 All five websites also have the same expiration date, February 7, 2026.139 On top of this, brusselswatch[.]org, eveningstar[.]uk, and amlnetwork[.]org all received registration updates on February 18, 2024, and both brusselswatch[.]org and ngoreport[.]org received updates on September 24, 2025.140 All five websites use Namecheap, a domain registration and web-hosting services company. Namecheap allows its users to buy and update domains in bulk.141 This functionality makes it feasible for a single individual or entity to register and update multiple domains within short, closely clustered time frames.
After being registered, the five websites all initially appeared on web-hosting servers leased by Namecheap. All five websites then began using Cloudflare’s reverse proxy services — which hide the true IP address of a domain’s web-hosting server — around a similar time frame.142
The five domains thus display similar timelines for shifts in their underlying internet infrastructure. These patterns provide a strong indication that the same person or people centrally manage all five websites.
Additionally, all five websites use Cloudflare nameservers — which essentially connect domain names to the specific web-hosting servers that store the sites — that are identical across the five websites. In all cases, the websites use braden.ns.cloudflare[.]com and maeve.ns.cloudflare[.]com.143 This common nameserver combination is significant, as there are over 2,550 CloudFlare nameserver pair combinations.144
The technologies underlying all five websites also display considerable overlap. All five websites use WordPress, a widely used website platform.145 Four use Elementor, a drag-and-drop design tool for WordPress, and three use the paid version, Elementor Pro, which requires an active license.146 All five websites also currently use Namecheap’s email hosting infrastructure, evidenced by their use of Namecheap’s proprietary Jellyfish email filtering system.147 This setup means Namecheap’s built-in infrastructure handles their email, not third-party providers such as Gmail or proprietary mail servers. More distinctively, all five websites rely on the same search-engine optimization plugin, Rankmath.148 While Rankmath is popular among WordPress users, it is significantly less popular than the dominant alternative, Yoast SEO.149 While each of these technologies is common on its own, the consistent use of this specific combination across all five websites strengthens the case for a shared origin or coordinated setup when considered alongside other indicators.
Additionally, the name “Anisur” appears in the metadata of various files across all five websites. For example, the logos on the homepage of informeurope[.]com, amlnetwork[.]org, and brusselswatch[.]org all show an author named “Anisur” in their metadata.150 Eveningstar[.]uk’s favicon — a small icon that visually represents a website in browser tabs, search results, and bookmarks — shows the same author name in its metadata.151 A PDF available for download on ngoreport[.]org also shows the same author name.152 “Anisur” likely is the name of a graphic designer; however, the person’s exact role remains unclear.
Several other technical indicators further connect all five websites. According to the cyber threat intelligence tool Security Trails, the domain informeurope[.]com has a subdomain eveningstar.informeurope[.]com.153 Although this subdomain does not currently resolve to an active page and no archived version can be found (as of October 27, 2025), its existence suggests that the web developer for informeurope[.]com may have intended for a subdomain of informeurope[.]com to refer to eveningstar[.]uk. Additionally, both eveningstar[.]uk and informeurope[.]com have static advertisements that link to the websites of an electric scooter website, electricscooterx[.]com.154 Historical versions of Brusselswatch[.]org also show an advertisement for electricscooterx[.]com.155 It is unlikely that two unrelated sites would both link back to this obscure website, which, according to the internet traffic analysis tool Similarweb, received only 52 visits in the month of September 2025.156

Security trails showing a selection of subdomains for informeurope[.]com, including eveningstar.informeurope[.]com.
Appendix B: Technical Analysis of the Secondary Network
Searching for websites linking to electricscooterx[.]com surfaced a website that served as the initial investigative lead for the secondary network. This website, nordicrights[.]org, also includes a static advertisement linking to electricscooterx[.]com and attacks the UAE and criticizes Qatargate.157
One of nordicrights[.]org’s previous web-hosting servers, located at IP address 185.212.70.248, hosted several websites that had content and design overlaps with nordicrights[.]org. These domains include fokuset[.]se, dagbladbergen[.]com, fokuset[.]com, eupressdesk[.]com, leuropelibre[.]com, and leparisientemps[.]com. The domain fokuset[.]se is currently inactive, and no record of it exists on the Internet Archive.158
Dagbladbergen[.]com, fokuset[.]se, and nordicrights[.]org all first appeared on 185.212.70.248 between February 19 and 22, 2022.159 Fokuset[.]com appeared on 185.212.70.248 a little under three months later, on May 14, 2022.160 Eupressdesk[.]com, leuropelibre[.]com, and leparisientemps[.]com all appeared on 185.212.70.248, between June 11 and 13, 2023.161 Several days earlier, these three domains also appeared on another shared server located at 84.32.84.32.162 The overlapping web-hosting servers shared among all seven websites provide the first indicator that they are centrally managed.

Timeline of the first appearance of websites in the secondary network across two shared servers. Source: FDD.
Analyzing these websites’ registration patterns and other technical signatures further confirms their connection: specifically, a registrant with a redacted name registered nordicrights[.]org on February 18, 2022, using the email mediasolutionsnordicm@gmail[.]com, the phone number +880.1624506969, and a physical address in Dhaka, Bangladesh. A man named “SM Asif” used the same email, phone number, and physical address to register fokuset[.]com on May 13, 2022.
A registrant with a redacted name in Bangladesh — who CCTI later determined to also likely be SM Asif — also registered dagbladbergen[.]com on February 21, 2022, two days after the registration of nordicrights[.]org. On top of this, dagbladbergen[.]com’s registration information received an update on February 18, 2024, the same day as brusselswatch[.]org, amlnetwork[.]org, and eveningstar[.]uk. In addition to the advertisements to electricscooterx[.]com, this common update date provides one of the first clear indicators of this secondary network’s connection to the primary network.
Eupressdesk[.]com, leuropelibre[.]com, and leparisientemps[.]com all have their registrant’s identity redacted, however, common registration patterns show they likely were created and controlled by the same person or people. Specifically, a registrant with a redacted name registered all three domains on June 8, 2023, within six minutes. These three domains also received updates within one second of each other on August 8, 2023, and all were set to expire on June 8, 2026. They were renewed on March 19, 2026, and are now set to expire on June 8, 2029.163 The three domains all also use the same registrar — the company through which a registrant registers a domain — namely, HOSTINGER operations, UAB.164
One of the strongest indications that the same person created websites in the secondary network comes from the Gravatar avatars linked to the websites. Gravatar provides a service that allows a user to create a profile image that appears across different platforms such as WordPress, GitHub, and Slack.165 Gravatar also creates a unique code, called a hash, from a user’s email address.166 This hash appears in the URL that links back to a user’s Gravatar avatar.167 All six active websites use WordPress.168 WordPress websites sometimes expose metadata associated with their users (such as administrators, editors, authors), including links to a user’s Gravatar.169
Websites that have WordPress users with the same associated Gravatar hashes are very likely connected to each other. Two identical hashes appear across Gravatar avatars associated with users across eupressdesk[.]com, leuropelibre[.]com, and leparisientemps[.]com.170 An identical hash also appears across dagbladbergen[.]com and nordicrights[.]org.171
One of the identical hashes that appears across eupressdesk[.]com, leuropelibre[.]com, and leparisientemps[.]com is a SHA-256 hash of editor@gmail[.]com.172 More tellingly, the other identical hash that appears across these three domains is the SHA-256 hash of mediasolutionsnordicm@gmail[.]com. Moreover, Dagbladbergen[.]com and nordicrights[.]org both have WordPress users with an MD5 hash of mediasolutionsnordicm@gmail[.]com in their Gravatar. SHA-256 hashes essentially are harder to decode than MD5 hashes.173
The same email appearing in the decoded Gravatar hashes associated with eupressdesk[.]com, leuropelibre[.]com, leparisientemps[.]com, dagbladbergen[.]com, and nordicrights[.]org provides a very strong indicator that the same person or people operate all five websites. On top of this, a registrant named “SM Asif” used mediasolutionsnordicm@gmail[.]com to register fokuset[.]com. The name of this registrant provided a key clue that identifies the creator of both the primary and secondary network.
Appendix C: Identifying the Creator of the Networks
A man named SM Asif Hassan appears to have created the primary and secondary networks. Hassan appears to be a web developer and digital marketer based out of Bangladesh, who also sometimes presents himself as based out of Dubai.
The website fokuset[.]com briefly exposed the name “SM Asif” in registration records captured by Domain Tools, a domain intelligence company, between May 14, 2022, and April 27, 2024.174 “SM Asif” also used the phone number +880.1624506969 to register fokuset[.]com.175 The registrant of nordicrights[.]org used the same number.176 OSINT Industries, an open source intelligence platform, connected this phone number to multiple accounts owned by “Asif Hassan,” confirming that “SM Asif” is SM Asif Hassan.

Excerpt of OSINT Industries results showing two accounts associated with +880.1624506969.
Hassan used the email mediasolutionsnordicm@gmail[.]com to register fokuset[.]com. As explained, the registrant of nordicrights[.]org uses this same email, and WordPress users associated with all other sites in the secondary network also use this email. The consistent use of this email provides strong evidence that Hassan created and controls all websites in the secondary network.
Hassan also appears to have created and control all websites in the primary network. Hassan’s name appears in the metadata of an older logo file on ngoreport[.]org under the file’s author field.177

Author name “SM Asif Hassan” exposed in the metadata in an old log for ngoreport[.]org.
Tellingly, Hassan identifies himself as the founder of a firm called AcorNovus IT on his LinkedIn account. An old copy of the website associated with AcorNovusIT (acornovusit[.]com) from August 26, 2024, lists ngoreport[.]org on its homepage as one of its customers.178 As of March 6, 2025, the website no longer advertises ngoreport[.]org as one of its customers.179 AcorNovusIT’s website also currently includes a photo of eveningstar[.]uk under the portfolio section of its homepage.180 Hassan’s LinkedIn page also lists Evening Star (eveningstar[.]uk) as one of his projects, further confirming his personal involvement in the site’s development.

SM Asif Hassan presenting himself as the founder of AcorNovus IT on his LinkedIn accounts.

SM Asif Hassan linking himself to the creation of eveningstar[.]uk on his LinkedIn.
The fact that Hassan personally claims development of eveningstar[.]uk, and that his company claims development of ngoreport[.]org, provides strong evidence that Hassan created both websites. Considering the primary network’s infrastructure ties, registration patterns, and overlapping technology stacks outlined above, Hassan likely created the entire primary network. Hassan also described electricscooterx[.]com as one of his websites on a support ticket for Rankmath, explaining the curious fact that several websites across the primary and secondary networks advertise the electric scooter website.181
A registrant under the name “Johaiman Al Dosari” also used a personal email associated with Hassan, asif102439@gmail[.]com, to register the domain name trialformbs[.]com in 2022.182 This suggests that Hassan may sometimes operate under this Arabic name as a pseudonym. Moreover, the domain he registered, trialformbs[.]com, appears set up to target the Saudi crown prince. The domain trialformbs[.]com does not currently show an active website, and there appears to be no public archived record of it, making it unclear if Hassan set up a website for the domain.
Hassan appears to have commercial motivations, rather than political or ideological ones. His publicly available social media profiles show no clear indicator of a personal pro-Qatar and anti-UAE stance. On the contrary, Hassan’s LinkedIn profile states that he and AcorNovus IT are based in Dubai, and many of his profile photos are pictures of him in Dubai. FDD was not able to determine whether Hassan spends most of his time in Dubai or in Bangladesh, where many of his sites are registered and many of his associated accounts are located. An alternative LinkedIn page for AcorNovus IT also lists its location in Dhaka, Bangladesh.183
It is unclear if Hassan is the only operator involved in the creation and management of the networks. It is also unclear who specifically paid Hassan to create both networks. However, whoever did pay Hassan clearly sought to further Qatari geopolitical interests.
Appendix D: Social Media Presence of the Belgiumgate Networks
Across the network, social media presence and engagement varies. Eight websites in the network maintain social media accounts. Dagblad Bergen, Le Parisien Temps, and Bureau de Presse appear to not have a social media presence.
NGO Report has, or has previously had, a social media presence across X, Instagram, Medium, YouTube, TikTok, and Pinterest.184 It appears it may have previously had Facebook and LinkedIn accounts, but neither appears online.185 NGO Report’s X account lists its location in Washington, DC, but X’s transparency features show the account is based in the United Kingdom and connected via the UK app store.186 Within Instagram’s transparency features, NGO Report’s account is based in Pakistan. Several letters published on its website also list a physical address, 347 5th Ave. #1402, New York, NY 10016.187 This appears to be a “virtual office space,” which, like a PO box, means that NGO Report might not have a physical presence at this location.188
Brussels Watch has associated X, Instagram, YouTube, Pinterest, and TikTok accounts.189 Its X account lists its location in Strasbourg, France, but X’s transparency features show the account is based in the United Kingdom and connected via the UK app store.190 Instagram’s transparency features show the account is based in Pakistan. It appears to also have previously had an associated Facebook account, but it is no longer online.191
AML Network’s active social media presence spans X, YouTube, and Pinterest.192 X’s transparency features list its account as based in the United Kingdom.193 The AML Network’s website also links to TikTok, Facebook, and Instagram accounts, but they no longer appear online.194
Evening Star has an active X account that lists its location as London, United Kingdom.195
Inform Europe has associated X and YouTube accounts.196 The X account lists its location in London, but within X’s transparency page the account is based in Pakistan and connected via the web.197
Nordic Rights has an associated X account.198 The X account lists its location as Denmark, but within X’s transparency page, the account is based in the United States and connected via the web (as opposed to via the X mobile application).199
Fokuset has an associated X account.200 The X account lists its location as Norway and is connected via the web.201
L’Europe Libre has an associated X account.202 Within X’s transparency section it says the account is based in the United States and connected via the web.