Spamouflage

Last updated

Spamouflage, Dragonbridge, Spamouflage Dragon, or Storm 1376 is an online propaganda and disinformation operation that uses a network of social media accounts to make posts in favor of the Chinese government and harass dissidents and journalists overseas. [1] Beginning in the early 2020s, Spamouflage accounts also began making posts about American and Taiwanese politics. [2] [3] It is widely believed that the Chinese government is behind the network. [1] [4] [5] [3] Spamouflage has increasingly utilized generative artificial intelligence for influence operations. [6] The campaign has largely failed to receive views from real users, [2] although the evolution of its tactics has allowed some Spamouflage accounts to see some success in receiving organic engagement. [5] [7] :2

Contents

History

In September 2019, research firm Graphika published a report identifying a network of spam accounts across different social media platforms making posts supporting the Chinese government and attacking its critics, naming the network "Spamouflage Dragon" due to its tactic of mixing in non-political spam content as camouflage. [8] :2 The network initially targeted exiled businessman Guo Wengui in 2018 and gradually also added criticisms of the 2019–2020 Hong Kong protests. [8] :22 The spam network's content did not receive much genuine engagement or views from real users, and the report concluded at the time that the low quality of the operation suggests that "it was not a state-backed operation". [8] :22

In early 2020, after becoming mostly dormant for a period of time following takedowns by social media platforms that occurred as a result of the 2019 Graphika report, [9] :5 the Spamouflage network reemerged with a focus on praising the Chinese government response to COVID-19 in addition to posting about its previous topics of interest. [9] :2

In February 2021, a Graphika report indicated that some accounts in the Spamouflage network had begun to see some success in receiving views from real users. [7] :3 Instead of solely using disposable spam accounts, Spamouflage began using accounts with a veneer of plausibility, developing fictional personas and co-opting the identities of stolen accounts. [7] :45 Spamouflage posts began to be amplified through retweets by Chinese government officials, including Zhao Lijian and then-ambassador to Venezuela Li Baorong. [7] :13,56 Its posts closely followed Chinese government messaging and had a new focus on aggressively criticizing the United States and both of its major political parties. [7] :4–5

In October 2022, Google's Mandiant reported that Spamouflage, which it calls Dragonbridge, was spreading propaganda and disinformation targeting the 2022 United States midterm elections. One video discouraged Americans from voting and cast doubt on the American political system. [10]

In April 2023, the United States Department of Justice (DOJ) unsealed an indictment against 34 officers of China's Ministry of Public Security (MPS) accused of running a disinformation campaign targeting US-based Chinese dissidents. Meta Platforms and private researchers cited by CNN believe that they are linked to Spamouflage, although the DOJ did not explicitly refer to Spamouflage by name. [1] [4]

In August 2023, Meta announced a takedown of nearly 9000 accounts and pages associated with Spamouflage; their threat intelligence report also covered the propaganda campaign's activities on YouTube, TikTok, and other social media platforms. They also indicated that Spamouflage had created a fake research paper blaming the United States for COVID-19 and attempted to publicize it via various social media networks. [11]

In April 2024, Institute for Strategic Dialogue researchers stated that some Spamouflage accounts had begun making posts about American politics under false American personas, a strategy that was previously used by Russian disinformation campaigns. [5] Under this new strategy, Spamouflage accounts pretending to be supporters of Donald Trump received engagement from real users, with one post being retweeted by conspiracy theorist Alex Jones. [5] The researchers indicated that they did not find Spamouflage accounts pretending to be Joe Biden supporters, although the existence of such accounts could not be ruled out. [5]

Activities

Criticism of Guo Wengui

Criticizing exiled businessman Guo Wengui, who has become a prominent critic of the Chinese government, was the initial focus of the Spamouflage network, and Guo has continued to be one of the targets of the network. [12] :15 The prolonged propaganda campaign featured numerous political cartoons attacking Guo and associates such as Li-Meng Yan and Steve Bannon in multiple languages. [13] :1

Harassment and transnational repression

A June 2022 report by the Australian Strategic Policy Institute (ASPI) found that several journalists, mostly women of Chinese descent working for overseas media outlets, were subjected to a harassment campaign carried out using Spamouflage accounts in what the ASPI called an instance of "digital transnational repression". [14]

Interference in American politics

Prior to the 2020 United States presidential election, Spamouflage accounts made posts criticizing Donald Trump in relation to the COVID-19 pandemic, actions he took against China, and the George Floyd protests. Although the network made a large volume of videos, they were of poor quality and received few authentic views. Many of the videos had broken English, and the intended audience of the videos was unclear. [15]

In 2021, a Graphika report noted that Spamouflage, which previously focused on criticizing Trump and then-Secretary of State Mike Pompeo, began criticizing Biden after the new president was inaugurated. The report concluded that the focus of the network was to spread the narrative of "China's rise and America's fall" rather than partisan election interference. [7] :4–5

Before the 2022 United States midterm elections, the Spamouflage network made posts casting doubts on the American political system, pointing to examples of political division and violence as evidence of the United States's decline. [16] Videos they posted portrayed American elections and the American government as being ineffective in improving Americans' lives. [10]

Russian invasion of Ukraine

In the lead-up to the 2024 United States presidential election, Spamouflage accounts began making posts about divisive American political issues. Accounts pretending to be American Donald Trump supporters spread false conspiracy theories about Joe Biden and amplified Russian disinformation about the Russian invasion of Ukraine. In contrast to previous Spamouflage campaigns, these accounts received engagement from real American users. [5]

Interference in Canadian politics

In 2023, fabricated videos in which Chinese dissident Liu Xin is depicted via deepfake to be making baseless allegations of legal and ethical violations by Justin Trudeau, Pierre Poilievre and other Canadian politicians were posted by Spamouflage accounts. Global Affairs Canada and Liu both believe that the videos may have sought to discredit Liu and hurt Canadian politicians' perception of him. [17]

Interference in Taiwanese politics

Leading up to the 2024 Taiwanese presidential election, the Spamouflage campaign used generative artificial intelligence to create memes and videos featuring AI television anchors in order to attack pro-independence presidential candidate Lai Ching-te with fabricated corruption allegations. [3] [6] Spamouflage also created a fake audio clip of Terry Gou endorsing another candidate. [3]

Advancement of Chinese geopolitics and foreign policy narratives

Spamouflage has made posts criticizing American foreign policy decisions relating to Taiwan, Ukraine, and trade restrictions on China targeting semiconductors. [18] It has also capitalized on the Israel–Hamas war to portray the United States as a threat to world peace. [19]

Attempted mobilization of real-world protests

COVID-19

According to Mandiant, in April 2021, Spamouflage accounts called for protests in New York City against Li-Meng Yan, Guo Wengui and Steve Bannon for spreading "rumors" about COVID-19 and publicized an address purportedly belonging to Guo. Although Spamouflage accounts claimed, sometimes using manipulated images, that the protests were successful, there is no evidence that protesters were successfully mobilized. [20]

Rare earth mines

A 2022 Mandiant report indicated that Spamouflage accounts had called for protests against proposed rare earth mines in the United States and Canada. The minerals are of strategic importance in electronics manufacturing, and the United States had started trying to increase domestic production in order to counter China's control over the field. [21]

Effectiveness

Low quality and limited authentic engagement

The network has largely been ineffective at getting views and engagement from real users. [2] One reason identified for the failure of the propaganda campaign, in contrast to more successful campaigns by Russia and other state actors, is its operators' lack of familiarity with the global information environment owing to the closed-off nature of the Chinese internet. [2] While some new technical tools adopted by Spamouflage operators, such as generative artificial intelligence, may increase the operation's efficiency, they will not necessarily make the operation more effective. [2]

An August 2020 Graphika report noted the poor quality of Spamouflage content. Videos that Graphika discovered contained "clumsy" text-to-speech voiceovers, grammatically incorrect English, and poorly-translated Chinese idiomatic expressions like "cast a chestnut in the fire will burn themselves with fire". [22] :19

Successes

Spamouflage has been able to disrupt discussions on controversial subjects by taking up space in search results with spam posts. [13] :14–15 Additionally, new tactics attempted by the network, such as a small cluster of Twitter accounts discovered in 2024 that pretended to be American supporters of Donald Trump, which researchers named "MAGAflage", have allowed it to receive some real engagement. [5] Researchers have expressed concerns that Spamouflage may start to gain more traction due to amplification by authentic accounts or a scaling up of the MAGAflage strategy. [2]

Attribution

The network has been attributed to the Chinese government by Twitter and Meta. [1] [14] Global Affairs Canada has also linked the campaign to the Chinese government. [23] Sources have linked Spamouflage to the Chinese Ministry of Public Security's "912 Special Project Working Group", which was the subject of a 2023 indictment by the American Department of Justice. [2]

An August 2023 threat report released by Meta notes that the timing of the network's activities match up with office hours in China, and that the network displays coordinated activity across multiple platforms. [1] Institute for Strategic Dialogue researcher Elise Thomas notes that the operation's lack of innovation despite prolonged ineffectiveness is characteristic of a government campaign. [2] In August 2023, Jack Stubbs of Graphika indicated that the firm had seen open source evidence pointing to the involvement of the Chinese group indicted by the DOJ with limited confidence. [24]

Initial reports of Spamouflage's activities did not always attribute the campaign to the Chinese government. Graphika researcher Ben Nimmo speculated in 2019 that amateurs or a private firm was behind the campaign. [25] In 2020, Graphika stated that it was unable to determine the relationship between Spamouflage and the Chinese government. [15]

In a response to CNN, Chinese government spokesperson Liu Pengyu denied China's involvement in Spamouflage. [1]

See also

Related Research Articles

<i>The Epoch Times</i> Far-right media company affiliated with Falun Gong

The Epoch Times is a far-right international multi-language newspaper and media company affiliated with the Falun Gong new religious movement. The newspaper, based in New York City, is part of the Epoch Media Group, which also operates New Tang Dynasty (NTD) Television. The Epoch Times has websites in 35 countries but is blocked in mainland China.

Russian web brigades, also called Russian trolls, Russian bots, Kremlinbots, or Kremlin trolls are state-sponsored anonymous Internet political commentators and trolls linked to the Government of Russia. Participants report that they are organized into teams and groups of commentators that participate in Russian and international political blogs and Internet forums using sockpuppets, social bots, and large-scale orchestrated trolling and disinformation campaigns to promote pro-Vladimir Putin and pro-Russian propaganda.

Informatized warfare of China is the implementation of information warfare (IW) within the People's Liberation Army (PLA) and other organizations affiliated or controlled by the Chinese Communist Party (CCP). Laid out in the Chinese Defence White Paper of 2008, informatized warfare includes the utilization of information-based weapons and forces, including battlefield management systems, precision-strike capabilities, and technology-assisted command and control (C4ISR). However, some media and analyst report also uses the term to describe the political and espionage effort from the Chinese state.

Mandiant is an American cybersecurity firm and a subsidiary of Google. It rose to prominence in February 2013 when it released a report directly implicating China in cyber espionage. In December 2013, Mandiant was acquired by FireEye for $1 billion, who eventually sold the FireEye product line, name, and its employees to Symphony Technology Group for $1.2 billion in June 2021.

State-sponsored Internet propaganda is Internet manipulation and propaganda that is sponsored by a state.

<span class="mw-page-title-main">Guo Wengui</span> Chinese businessman and conspiracy theorist

Guo Wengui, also known under the Cantonese name Ho Wan Kwok (郭浩云), Miles Guo, and Miles Kwok, is an exiled Chinese billionaire businessman who became a political activist and controls Beijing Zenith Holdings, and other assets. At the peak of his career, he was the 73rd richest person in China. Guo was accused of corruption and other misdeeds by the Chinese authorities and moved to the United States in late 2014, after learning he was going to be arrested under allegations of bribery, kidnapping, money laundering, fraud and rape. Guo says the charges are politically motivated and are a product of a campaign of political retribution carried out against him by the Chinese Communist Party government. Guo is a colleague of Steve Bannon and a member of former U.S. President Donald Trump's Mar-a-Lago resort in Florida.

<span class="mw-page-title-main">Internet Research Agency</span> Russian company engaged in online propaganda

The Internet Research Agency, also known as Glavset, and known in Russian Internet slang as the Trolls from Olgino or Kremlinbots, was a Russian company which was engaged in online propaganda and influence operations on behalf of Russian business and political interests. It was linked to Yevgeny Prigozhin, a former Russian oligarch who was leader of the Wagner Group, and based in Saint Petersburg, Russia.

<span class="mw-page-title-main">Democratic National Committee cyber attacks</span> 2015-16 data breaches by Russian hackers as part of US election interference

The Democratic National Committee cyber attacks took place in 2015 and 2016, in which two groups of Russian computer hackers infiltrated the Democratic National Committee (DNC) computer network, leading to a data breach. Cybersecurity experts, as well as the U.S. government, determined that the cyberespionage was the work of Russian intelligence agencies.

Fake news websites are websites on the Internet that deliberately publish fake news—hoaxes, propaganda, and disinformation purporting to be real news—often using social media to drive web traffic and amplify their effect. Unlike news satire, fake news websites deliberately seek to be perceived as legitimate and taken at face value, often for financial or political gain. Such sites have promoted political falsehoods in India, Germany, Indonesia and the Philippines, Sweden, Mexico, Myanmar, and the United States. Many sites originate in, or are promoted by, Russia, or North Macedonia among others. Some media analysts have seen them as a threat to democracy. In 2016, the European Parliament's Committee on Foreign Affairs passed a resolution warning that the Russian government was using "pseudo-news agencies" and Internet trolls as disinformation propaganda to weaken confidence in democratic values.

A troll farm or troll factory is an institutionalised group of internet trolls that seeks to interfere in political opinions and decision-making.

China Global Television Network (CGTN) is one of three branches of state-run China Media Group and the international division of China Central Television (CCTV). Headquartered in Beijing, CGTN broadcasts news in multiple languages. CGTN is under the control of the Central Propaganda Department of the Chinese Communist Party.

<span class="mw-page-title-main">Fake news</span> False or misleading information presented as real

Fake news or information disorder is false or misleading information presented as news. Fake news often has the aim of damaging the reputation of a person or entity, or making money through advertising revenue. Although false news has always been spread throughout history, the term fake news was first used in the 1890s when sensational reports in newspapers were common. Nevertheless, the term does not have a fixed definition and has been applied broadly to any type of false information presented as news. It has also been used by high-profile people to apply to any news unfavorable to them. Further, disinformation involves spreading false information with harmful intent and is sometimes generated and propagated by hostile foreign actors, particularly during elections. In some definitions, fake news includes satirical articles misinterpreted as genuine, and articles that employ sensationalist or clickbait headlines that are not supported in the text. Because of this diversity of types of false news, researchers are beginning to favour information disorder as a more neutral and informative term.

The firehose of falsehood is a propaganda technique in which a large number of messages are broadcast rapidly, repetitively, and continuously over multiple channels without regard for truth or consistency. An outgrowth of Soviet propaganda techniques, the firehose of falsehood is a contemporary model for Russian propaganda under Russian President Vladimir Putin.

<span class="mw-page-title-main">Russian interference in the 2020 United States elections</span>

Russian interference in the 2020 United States elections was a matter of concern at the highest level of national security within the United States government, in addition to the computer and social media industries. In 2020, the RAND Corporation was one of the first to release research describing Russia's playbook for interfering in U.S. elections, developed machine-learning tools to detect the interference, and tested strategies to counter Russian interference. In February and August 2020, United States Intelligence Community (USIC) experts warned members of Congress that Russia was interfering in the 2020 presidential election in then-President Donald Trump's favor. USIC analysis released by the Office of the Director of National Intelligence (DNI) in March 2021 found that proxies of Russian intelligence promoted and laundered misleading or unsubstantiated narratives about Joe Biden "to US media organizations, US officials, and prominent US individuals, including some close to former President Trump and his administration." The New York Times reported in May 2021 that federal investigators in Brooklyn began a criminal investigation late in the Trump administration into possible efforts by several current and former Ukrainian officials to spread unsubstantiated allegations about corruption by Joe Biden, including whether they had used Trump personal attorney Rudy Giuliani as a channel.

Peace Data or PeaceData is a fake news website run by the Internet Research Agency, a Russian outlet connected to the country's government, which publishes in English and Arabic.

<span class="mw-page-title-main">Gettr</span> Social media platform

Gettr is an alt-tech social media platform and microblogging site targeting American conservatives. It was founded by Jason Miller, a former Donald Trump aide, and was officially launched on July 4, 2021. Its user interface and feature set have been described as very similar to those of Twitter.

Russian disinformation campaigns have occurred in many countries. For example, disinformation campaigns led by Yevgeny Prigozhin have been reported in several African countries. Russia, however, denies that it uses disinformation to influence public opinion.

Foreign rivals of the United States, mainly Russia and China, have attempted to weaken American race relations as a geopolitical strategy. This manipulation is primarily done through misinformation posted on social media, targeting mainly African-Americans and Asian-Americans. Russia's social media campaign was thought to have affected the 2016 U.S. presidential election. The practice can be traced back to propaganda efforts of the Soviet Union's Comintern in the 1920s.

Graphika is an American social network analysis company known for tracking online disinformation. It was established in 2013.

References

  1. 1 2 3 4 5 6 O'Sullivan, Donie; Devine, Curt; Gordon, Allison (13 November 2023). "China is using the world's largest known online disinformation operation to harass Americans, a CNN review finds". CNN . Archived from the original on 14 November 2023. Retrieved 6 May 2024.
  2. 1 2 3 4 5 6 7 8 Gilbert, David (April 29, 2024). "Why China Is So Bad at Disinformation". Wired . Archived from the original on 9 May 2024. Retrieved 9 May 2024.
  3. 1 2 3 4 Milmo, Dan (2024-04-05). "China will use AI to disrupt elections in the US, South Korea and India, Microsoft warns". The Guardian . ISSN   0261-3077 . Retrieved 2024-04-07.
  4. 1 2 Hsu, Tiffany; Myers, Steven Lee (1 April 2024). "China's Advancing Efforts to Influence the U.S. Election Raise Alarms". The New York Times . Archived from the original on 3 April 2024. Retrieved 1 April 2024. The accounts sometimes amplified or repeated content from the Chinese influence campaign Spamouflage, which was first identified in 2019 and linked to an arm of the Ministry of Public Security.
  5. 1 2 3 4 5 6 7 Yang, Lin (8 April 2024). "Chinese nationalist trolls pretend to be Trump supporters ahead of US elections". Voice of America . Archived from the original on 9 May 2024. Retrieved 9 May 2024.
  6. 1 2 Milmo, Dan; Hawkins, Amy (2024-05-18). "How China is using AI news anchors to deliver its propaganda". The Guardian . ISSN   0261-3077 . Retrieved 2024-05-20.
  7. 1 2 3 4 5 6 Nimmo, Ben; Hubert, Ira; Yang, Cheng (February 2021). Spamouflage Breakout: Chinese Spam Network Finally Starts to Gain Some Traction (PDF) (Report). Graphika. Archived (PDF) from the original on 2021-03-05. Retrieved 2024-05-09.
  8. 1 2 3 Nimmo, Ben; Eib, C. Shawn; Tamora, L. (September 2019). Cross-Platform Spam Network Targeted Hong Kong Protests (PDF) (Report). Graphika. Archived (PDF) from the original on 2024-05-11. Retrieved 2024-05-06.
  9. 1 2 Nimmo, Ben; Eib, C. Shawn; Camille, François; Léa, Ronzaud (April 2020). Return of the (Spamouflage) Dragon: Pro-Chinese Spam Network Tries Again (PDF) (Report). Graphika. Archived (PDF) from the original on 2024-05-11. Retrieved 2024-05-09.
  10. 1 2 Mandiant Intelligence (26 October 2022). "Pro-PRC DRAGONBRIDGE Influence Campaign Leverages New TTPs to Aggressively Target U.S. Interests, Including Midterm Elections". Archived from the original on 9 May 2024. Retrieved 9 May 2024.
  11. Taylor, Josh (29 August 2023). "Meta closes nearly 9,000 Facebook and Instagram accounts linked to Chinese 'Spamouflage' foreign influence campaign". The Guardian. Retrieved 12 May 2024.
  12. Warren, Patrick; Linvill, Darren; Fecher, Leland; Warren, Jayson; Sheffield, Steven (2023). The 5-year Spam: Tracking a Persistent Chinese Influence Operation (Report). Clemson University. Archived from the original on 2024-05-11. Retrieved 2024-05-09.
  13. 1 2 Fecher, Leland; Reich, Tyler; Taylor, Jack; Warren, Patrick (2022-01-01). Oh, the Places You'll Guo! The Tactics and Impact of a Chinese Multilingual Narrative Flooding Campaign through Political Cartoons (Report). Clemson University. Archived from the original on 2024-05-11. Retrieved 2024-05-09.
  14. 1 2 Allen-Ebrahimian, Bethany (3 June 2022). "China-linked Twitter harassment targets female Asian journalists outside China". Axios . Archived from the original on 21 November 2023. Retrieved 9 May 2024.
  15. 1 2 Timberg, Craig; Harris, Shane (12 August 2020). "Chinese network of fake accounts targets Trump with English-language videos". The Washington Post . Archived from the original on 8 November 2023. Retrieved 11 May 2024.
  16. Sganga, Nicole (26 October 2022). "China-linked influence campaign targeting U.S. midterms, security firm says". CBS News . Archived from the original on 7 November 2022. Retrieved 11 May 2024.
  17. Shen, Nono (1 November 2023). "China critic says he's the target of deepfake 'spamouflage' attack by Beijing". CTV News . The Canadian Press. Archived from the original on 9 November 2023. Retrieved 11 May 2024.
  18. Pan, Che (2023-01-27). "Pro-China spammers flood YouTube with unpopular videos, Google says". South China Morning Post. Retrieved 2024-05-12.
  19. Michelle, Jamrisko; Saraiva, Augusta; Martin, Peter (2024-05-08). "Gaza Is China's New Wedge Issue to Split US From Global South - BNN Bloomberg". BNN Bloomberg. Bloomberg News. Retrieved 2024-05-12.
  20. Serabian, Ryan; Foster, Lee (7 September 2021). "Pro-PRC Influence Campaign Expands to Dozens of Social Media Platforms, Websites, and Forums in at Least Seven Languages, Attempted to Physically Mobilize Protesters in the U.S." Mandiant . Archived from the original on 18 April 2024. Retrieved 11 May 2024.
  21. Murphy, Margi (28 June 2022). "Pro-China Agents Posed as Activists to Protest US, Canada Mines". BNN Bloomberg . Bloomberg News. Archived from the original on 17 August 2022. Retrieved 11 May 2024.
  22. Nimmo, Ben; François, Camille; Eib, C. Shawn; Ronzaud, Léa (12 August 2020). Spamouflage Goes to America (PDF) (Report). Graphika. Archived (PDF) from the original on 19 December 2021. Retrieved 11 May 2024.
  23. Tunney, Catherine (23 October 2023). "China linked to propaganda campaign targeting Trudeau, Poilievre, says Global Affairs". CBC News . Archived from the original on 9 May 2024. Retrieved 9 May 2024.
  24. Martin, Alexander (29 August 2023). "Chinese law enforcement linked to largest covert influence operation ever discovered". The Record. Retrieved 12 May 2024.
  25. Uchill, Joe (25 September 2019). "Bumbling social media scheme hit Hong Kong protestors". Axios . Archived from the original on 5 December 2023. Retrieved 11 May 2024.