BETA nonprofit public democratic european moderated

Search

#Astroturfing

Nigeria – how pro-Russian influence networks sell military rule as the answer When Nigerians took to the streets in August 2024 to protest soaring living costs and frustration with government, some demonstrations acquired an unexpected symbol: the Russian flag. In Kano, Kaduna and other northern cities, protesters were filmed carrying Russian colours and calling for Moscow’s intervention. Some demanded a military takeover. What initially looked like an unusual expression of anger has since become part of a much larger picture. A September 2026 assessment by the Africa Center for Strategic Studies describes Nigeria as a major target of overlapping foreign information operations, with Russia the most active external actor in its information space. The report does not identify a single centrally controlled campaign. Instead, it maps an ecosystem in which genuine dissatisfaction over insecurity, corruption and living standards is repeatedly redirected towards a broader proposition: democratic government has failed, while the military-led regimes of the Sahel offer a more effective alternative. Turning a real protest into a pro-Russian message The clearest example emerged during the 2024 #EndBadGovernance protests. Nigerian investigative reporting found that a Kano-based TikTok influencer with more than 100,000 followers had been paid through a Telegram channel associated with African Initiative, a Moscow-based media operation linked by researchers to Russian influence activity in Africa. The influencer said the channel supplied photographs, videos and talking points for redistribution on TikTok and Instagram. Among the messages provided were phrases such as “Putin please come and save Nigeria” and “The army is the answer for Nigeria”. Influencers were encouraged to use Hausa-language hashtags including #Zangazanga – “protest” – alongside references to Putin and Russia. Investigators identified 38 accounts circulating similar pro-Russian and pro-military narratives during the demonstrations. Russian flags subsequently appeared among protesters in several northern cities. This does not mean the protests themselves were created by Russia. They were driven by genuine economic and political grievances, and Nigerian protesters gave different reasons for carrying Russian flags. The important feature of the influence activity was precisely that it did not need to manufacture the original anger. It could attach a geopolitical message to an existing domestic crisis. From frustration to the idea of military government The narrative fits a wider pattern seen across West Africa. Russia has developed close relations with the military governments of Mali, Burkina Faso and Niger, while pro-Russian media ecosystems routinely portray those states as examples of sovereignty, stability and resistance to Western influence. Nigeria, by contrast, has remained under constitutional civilian government since 1999. Africa Center researchers say information networks targeting Nigerians increasingly contrast these two models. Recurring messages depict elections as wasteful or predetermined, civilian institutions as incapable of protecting citizens and military governments as more decisive on security and development. Some content portrays the Sahelian juntas as delivering better roads, lower prices and stronger security even where available evidence points to continuing or worsening instability. Language is central to the strategy. Hausa is spoken across northern Nigeria and neighbouring Niger, allowing political narratives to travel across borders that are far less important online than they are on maps. HumAngle documented efforts involving Nigerien state-linked actors to cultivate Hausa-speaking journalists and distribute material favourable to Niger’s junta and hostile to France and Western influence. The Russian and Sahelian-junta information ecosystems are not identical, but their narratives frequently reinforce one another. Fake journalists inside real Nigerian media The campaign environment extends beyond social media. A 2026 investigation by Graphika and Code for Africa identified 44 ghost reporters and fake experts whose identities were used to place Russia-aligned narratives in African media. Thirty-eight were assessed with high confidence to be fabricated. Their articles or quotations appeared across 138 websites and were amplified by at least 113 Facebook accounts and Pages. Nigeria was one of the most heavily targeted countries. According to the Africa Center’s analysis of the research, Daily Post Nigeria carried 39 articles involving 14 identified ghost authors. Once published by a genuine Nigerian outlet, such material could then be cited by other websites, social-media accounts or even Russian official channels as though it had originated independently in Africa. This is information laundering rather than simple propaganda: the most valuable asset being borrowed is the credibility of the local newsroom. Generative AI added another layer. OpenAI and Meta separately disrupted a Russia-origin network that produced Africa-focused political content and operated Facebook Pages posing as local media organisations. One fabricated commentator, “Dr Manuel Godsin”, was presented as a European-trained geopolitical expert although investigators found no evidence supporting his academic biography. ChatGPT had been used to generate articles under the persona’s name, while Meta removed 37 Facebook accounts and 29 Pages connected to the broader network. Different networks, similar strategic direction It would be misleading to merge all these activities into a single Russian command structure. The African Initiative-linked influencer campaign, the ghost-reporter network and the AI-enabled operation disrupted by OpenAI and Meta were uncovered separately and used different infrastructure. Public evidence does not demonstrate that every actor reported to the same organisation. What connects them is a recurring set of themes and methods: portraying Western partnerships as exploitative, presenting Russia as an alternative security partner, amplifying failures of civilian government, and giving military-led rule greater legitimacy. Investigative reporting on leaked Russian documents has meanwhile described a much wider influence apparatus operating across Africa, involving political consultants, paid journalists, influencers and locally tailored campaigns intended to reduce Western influence and expand Moscow’s position. The underlying technique is less about inventing dissatisfaction than redirecting it. Nigeria faces real security threats, economic pressure and public frustration. Influence operators do not need to persuade Nigerians that those problems exist. They need only influence the explanation for why they exist – and which political model appears to offer the answer. That is what makes the Nigerian case significant. The most effective propaganda does not necessarily introduce a completely false reality. It takes a real crisis and changes where the audience is encouraged to look for the solution. Sources Africa Center for Strategic Studies — The Raging Information Battle in Nigeria https://africacenter.org/spotlight/the-raging-information-battle-in-nigeria/ Graphika — Umbrae Ex Machina https://www.graphika.com/reports/umbrae-ex-machina OpenAI — Operation “No Bell” https://openai.com/index/disrupting-malicious-uses-of-ai-no-bell/ TheCable — Ghost reporters in African media https://www.thecable.ng/ghost-reporters-how-fabricated-african-voices-carried-pro-russia-narratives/ HumAngle — Nigeria Is Facing an Information War in Its Own Language https://www.humanglemedia.com/nigeria-is-facing-an-information-war-in-its-own-language DAIDAC / CJID — Russian influence during #EndBadGovernance https://daidac.thecjid.org/how-telegram-tiktok-aided-russian-disinformation-that-led-to-incarceration-of-nigerian-minors/ FactCheckHub — How Nigeria’s hunger protest took a radical turn https://factcheckhub.com/from-economic-protests-to-coup-agitation-how-nigerias-hunger-march-took-a-radical-turn/ News24 — Fake Kremlin-linked analyst planted stories in African media https://www.news24.com/southafrica/news/ai-expert-exposed-fake-kremlin-linked-analyst-planted-stories-in-african-media-20260318-0560 Vanguard — AI ‘expert’ exposed https://www.vanguardngr.com/2026/03/ai-expert-exposed-fake-kremlin-linked-analyst-planted-stories-in-african-media/ Africa Confidential — How Moscow wages social media war https://www.africa-confidential.com/article/id/15961/how-moscow-wages-social-media-war Keywords #DISINFORMED #Episode15 #Nigeria #Russia #RussianInfluence #RussianDisinformation #Africa #WestAfrica #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #Propaganda #MilitaryRule #MilitaryGovernment #Democracy #PoliticalManipulation #NarrativeManipulation #AfricanInitiative #EndBadGovernance #Hausa #LocalInfluencers #GhostReporters #FakeExperts #ArtificialIntelligence #AI #AIPersonas #SyntheticMedia #AIPropaganda #Astroturfing #SocialMediaManipulation #Telegram #TikTok #DigitalInfluence #SourceLaundering #NarrativeLaundering #MediaManipulation #Sahel #Geopolitics #OSINT #WRLD

The Raging Information Battle in Nigeria

Brazil’s synthetic voters – when AI manufactures public opinion They look like ordinary street interviews. A reporter approaches a passer-by in a Brazilian square and asks a simple question: who will you vote for? A young voter explains why Luiz Inácio Lula da Silva deserves another term. An elderly woman says Brazil needs Flávio Bolsonaro because he represents political renewal and greater security. The locations look plausible, the microphones are visible and the answers sound much like the brief political opinions heard in television vox pops around the world. None of the people are real. Ahead of Brazil’s presidential election on 4 October, fact-checking organisation Aos Fatos identified at least 50 TikTok videos in which artificial intelligence was used to manufacture voters, reporters and apparently spontaneous political interviews. Together, the videos had accumulated around 7.4 million views by mid-August. Some promoted Lula, others Flávio Bolsonaro, while another group used synthetic characters to ridicule or stereotype supporters of one side. Aos Fatos found no apparent evidence linking the accounts producing the videos to either presidential campaign. The opinion poll that never took place The format is important. These were not conventional deepfakes in which a recognisable politician is made to say something he never said. Instead, the creators reproduced the visual language of the vox pop – the short street interview used by broadcasters and social-media creators to illustrate what ordinary people supposedly think. In pro-Lula videos, synthetic voters described themselves as beneficiaries of social programmes or credited the president with improving their lives. In videos supporting Flávio Bolsonaro, artificial interviewees associated him with political renewal, public security and fighting corruption. Other clips were openly hostile: AI-generated characters presented as poor or living in parts of Brazil’s north-east were shown in dirty clothes or run-down surroundings, declaring support for Lula because they supposedly preferred welfare payments to work. The deception is therefore subtler than fabricating a candidate’s statement. It manufactures something that political communication normally treats as evidence of public sentiment. A real vox pop may be unscientific, but the people interviewed at least exist. These videos created the appearance that identifiable social groups – young people, pensioners, welfare recipients or residents of particular regions – were spontaneously expressing political preferences when no such encounters had taken place. An electoral-law specialist interviewed by Aos Fatos described the technique as the fabrication of a “social fact that never occurred”. That captures the central innovation: AI is being used not merely to falsify political speech, but to manufacture the impression of grassroots opinion. Fifty videos, but not one proven network The available evidence does not support describing the 50 posts as a centrally controlled influence operation. Aos Fatos located them through TikTok searches and recommendations produced by the platform itself, then examined the accounts responsible for publication. Most had relatively small individual audiences, although their combined reach was substantial. The first examples identified by the investigation appeared as early as March 2026. Activity increased in June and was concentrated particularly in July and the first half of August as Brazil’s election calendar intensified. Some accounts specialised in AI-generated videos generally, including fabricated podcast-style material. Others were explicitly political or supportive of a candidate, but Aos Fatos found no apparent links between those profiles and the official Lula or Bolsonaro campaigns. That distinction is essential. The evidence demonstrates a common technique and a shared political environment, not a single command structure. Some creators may have been motivated by ideology, others by engagement or monetisation. Publicly available evidence does not establish who commissioned the individual videos or whether any coordination existed between the accounts. This decentralised model also creates a different enforcement problem from a traditional bot network. There may be no headquarters to expose and no infrastructure whose removal disables the entire operation. The format itself can be copied by anyone with access to inexpensive generative-video tools. When the algorithm mixes real and synthetic citizens Aos Fatos documented another important feature of the phenomenon: TikTok’s recommendation system placed AI-generated interviews alongside genuine street interviews. For a user scrolling quickly through the platform, the transition between an authentic citizen and an entirely fabricated one could therefore be almost invisible. In 18 per cent of the 50 videos analysed, there was no indication that the people shown had been generated using AI. After Aos Fatos provided TikTok with the videos, the company said it had removed all of them for violating its rules on edited and AI-generated media. TikTok said its policies require creators to identify synthetic content and prohibit manipulated media capable of misleading users about matters of public importance or impersonating genuine journalistic material. The issue extends beyond one platform. Factchequeado’s review of Brazil’s 2026 election campaign found that synthetic endorsements and other deepfakes had become one of the most visible forms of AI-assisted electoral misinformation, alongside fabricated candidate statements and invented scenes. Brazil already had rules for synthetic politics Brazil entered the campaign with unusually detailed electoral rules governing artificial intelligence. The Superior Electoral Court, the TSE, requires electoral propaganda using synthetic multimedia to disclose clearly that AI was used. More importantly for the fake-voter videos, its rules prohibit synthetic audio or video used to favour or harm a candidacy when it creates or alters the image or voice of a living, deceased or fictitious person. The difficulty is attribution and enforcement. When a synthetic video is published by an official campaign, responsibility can be relatively straightforward to investigate. When it comes from an apparently independent account with no demonstrated relationship to a candidate, lawyers interviewed by Aos Fatos said responsibility is more likely to fall on the individual creator, while imposing electoral sanctions on a campaign would require evidence of a connection. For the final 72 hours before the election and the 24 hours following it, the TSE has imposed additional restrictions on newly published or republished synthetic material involving candidates or public figures, reflecting the particular difficulty of correcting fabricated content immediately before voting. From deepfake politicians to synthetic electorates The Brazilian case illustrates a broader change in political manipulation. The first generation of electoral deepfakes concentrated on famous people: make a politician appear to say something damaging, or fabricate an endorsement from a celebrity. Synthetic vox pops reverse the perspective. The politician can remain completely authentic; it is the electorate around the politician that is fabricated. That changes the psychological proposition of the message. Instead of saying the candidate believes this, the video suggests people like you believe this. Age, clothing, accent, neighbourhood and social class can all be generated to construct an artificial constituency around almost any political claim. There is no evidence that the 50 Brazilian videos identified by Aos Fatos constitute a single centrally directed campaign, nor evidence that they changed voting intentions. What they demonstrate is a technique whose barrier to entry has become extremely low. AI no longer needs to forge the politician. #DISINFORMED #Episode14 #Brazil #BrazilElection2026 #Elections #ElectionDisinformation #ArtificialIntelligence #AI #GenerativeAI #SyntheticVoters #SyntheticMedia #AIAvatars #AIGeneratedVideo #VoxPop #FakeInterviews #Astroturfing #AIPropaganda #PoliticalDisinformation #InfluenceOperations #InformationWarfare #SocialMediaManipulation #TikTok #PublicOpinion #ManufacturedConsent #SyntheticPublicOpinion #DigitalInfluence #Deepfakes #ElectionIntegrity #TSE #AosFatos #FactChecking #OSINT #MediaManipulation #WRLD (translated)

Eleitores gerados por IA fazem campanha no TikTok e põem em xeque regra do TSE

Disinformation for hire – the network of 70 fake newsrooms sold as a service The websites looked local. Naija Pulse appeared to cover Nigeria, Echo Berlin Germany, The British Daily Britain, Fifty States the United States and Commonwealth Post Australia. Each had its own branding, articles, supposed journalists and matching social-media presence. Taken individually, they resembled small independent news outlets. According to Anthropic, however, they were parts of a single commercial influence network spanning six continents. Anthropic’s September 2026 threat report identifies the operation as GTG-54002, a commercial “influence-as-a-service” network that used Claude to generate and rewrite political content at industrial scale. Investigators linked roughly 70 fabricated news websites to around 70 matching X accounts and more than 250 additional inauthentic commenting accounts designed to create the appearance of genuine public engagement. The network produced at least 8,913 articles in about 20 languages before Anthropic disrupted the activity. The significance of the case is not simply the number of fake sites. It is the business model. The network did not consistently promote one government, party or ideology. Anthropic found that its political position changed according to the apparent interests of different customers. The company therefore described it as a commercial influence operation: political manipulation offered in much the same way as other outsourced digital services. A fake media ecosystem built at scale Anthropic says the infrastructure was created rapidly. Domains were registered from France during a roughly ten-week period in mid-2025 and deployed through shared technical infrastructure, allowing investigators to connect publications that outwardly appeared unrelated. Most of the supporting social-media accounts were also created within a narrow timeframe in June and July 2025. The sites were designed to look like functioning local newsrooms rather than anonymous propaganda pages. Articles carried fabricated bylines belonging to journalists who, according to Anthropic, did not exist. Each outlet had a corresponding account on X, while a second layer of fake profiles commented on and amplified the articles. Many of those accounts used AI-generated profile photographs. The result was a three-tier structure: the newsroom published the story, the branded social account distributed it, and apparently ordinary users supplied the appearance of public reaction. Some of those sites remained publicly visible after the operation was exposed. The British Daily, for example, described itself as providing “conservative insights” on British sovereignty and migration, while Commonwealth Post presented itself as an Australian liberal publication focused on democracy, migration and regional security. Those contrasting editorial identities illustrate the central feature identified by Anthropic: the network was capable of taking different political positions in different markets. Claude as a publishing engine Claude was not simply asked to draft occasional articles. The operators built a structured production pipeline around it. Prompts required fixed JSON outputs, formatted HTML, precise character limits and internal links, allowing articles to move directly into an automated publishing workflow. The system could generate entirely new material or take reporting produced by legitimate journalists and rewrite it to fit a desired political perspective. Anthropic identified three recurring techniques. The same source article could be rewritten in opposite ideological directions for different audiences; a political interpretation could be added to a story that originally contained none; and material could be moved from one country to another after its original context had been removed. The articles were also structured to improve the apparent authority of the sites in search engines, helping the network imitate ordinary digital publishing practices rather than simply broadcasting propaganda. This is where generative AI changes the economics of an influence operation. A conventional network of dozens of supposedly local publications would normally require writers, translators, editors and social-media staff. Here, much of that production could be standardised and automated while human operators concentrated on political direction, customer requirements and distribution. The DRC–Rwanda conflict as a test case The clearest concentration of activity involved the Democratic Republic of Congo. Anthropic identified 318 articles concerning the DRC across the fake-news network. The material generally supported positions aligned with the Congolese government, particularly on regional mineral agreements and tensions with Rwanda. Early in the network’s growth, many of the fake social-media personas following and amplifying its accounts also presented themselves as Congolese. Investigators observed one especially revealing episode on 11 September 2025, when multiple sites published almost identical articles about the DRC–Rwanda conflict within approximately three minutes of one another. The wording and political tone were adjusted for different regional audiences, while associated X accounts distributed the links in a coordinated pattern. Anthropic said the activity contained signals suggesting that one or more customers had interests connected to the DRC–Rwanda conflict. It did not, however, identify those customers and explicitly stated that it found no evidence that any government had directed the operation. That distinction is essential. The content may have benefited a political actor without demonstrating that the actor commissioned or controlled it. Influence without ideology Commercialisation is what distinguishes GTG-54002 from many state-linked information operations. A government propaganda network usually has an identifiable strategic direction. A commercial influence provider does not need one. Its infrastructure can support one position in one country and the opposite position somewhere else, provided different customers are willing to pay. That makes attribution more difficult. Analysts cannot necessarily infer the operator from the ideology of the content because ideology may simply be part of the service package. The enduring asset is the infrastructure: domains, publishing systems, fake journalists, social-media accounts and automated amplification. Anthropic says the operation was disrupted before it achieved significant genuine reach. It classified GTG-54002 as Category Two on the Brookings Breakout Scale: material circulated across the network’s own sites and associated social accounts but showed no evidence of substantial penetration into authentic communities. Most of the 8,913 articles generated little observable engagement from real users. That limited impact is important. The case should not be presented as a successful global manipulation campaign. It is better understood as evidence that the infrastructure required to run such campaigns has become cheaper, faster and increasingly commoditised. The deeper shift is that a fake media ecosystem no longer has to be built around a single political cause. It can be built once, automated and then repurposed for the next customer. Disinformation, in this model, is no longer only a political instrument as it turend into the service. Sources: Anthropic — Countering misuse of AI: September 2026 https://www.anthropic.com/threat-intelligence-report-september-2026 Business Standard — AI scaling fake newsrooms, surveillance and online scams https://www.business-standard.com/technology/tech-news/anthropic-report-ai-fake-newsrooms-dating-surveillance-scams-126091100730_1.html Mimikama — KI baut 70 erfundene Nachrichtenportale https://www.mimikama.org/ki-netzwerk-erfundene-nachrichtenportale-echo-berlin/ Poliscoop Media — Anthropic exposes DRC propaganda network https://www.poliscoopmedia.com/articles/anthropic-exposes-drc-propaganda-network-20260911 The British Daily — example of a fabricated outlet identified in the network https://www.british-daily.com/contact Commonwealth Post — example of a fabricated outlet identified in the network https://commonwealth-post.com/category/science MalPulse — infrastructure references for network domains https://www.malpulse.com/infra-pivots/usom-pivots/list/?page=1105 Keywords: #DISINFORMED #Episode13 #DisinformationAsAService #InfluenceAsAService #FakeNewsrooms #FakeMedia #SyntheticMedia #ArtificialIntelligence #AI #GenerativeAI #ClaudeAI #Anthropic #Disinformation #InfluenceOperations #InformationWarfare #FIMI #CommercialInfluence #PoliticalManipulation #NarrativeManipulation #NarrativeLaundering #SourceLaundering #MediaImpersonation #FakeJournalists #SyntheticPersonas #Astroturfing #SocialMediaManipulation #CoordinatedInauthenticBehaviour #CIB #DigitalInfluence #AutomatedPropaganda #ContentAutomation #AIPropaganda #LKMCompany #NaijaPulse #AxumVoices #JamboJournal #EchoBerlin #TheBritishDaily #FiftyStates #CommonwealthPost #DRC #Rwanda #OSINT #WRLD

Countering misuse of AI: September 2026 / Anthropic

IRAN: MEK/NCRI – when AI impersonated a real activist in live conversations For years, synthetic media has largely meant fabricated images, cloned voices and manipulated video. A case uncovered by Anthropic in September 2026 suggests a more consequential development: artificial intelligence being used not merely to imitate how a person looks or sounds, but to behave as that person in an ongoing conversation. Anthropic says it dismantled a distributed influence operation targeting Iranians inside the country and abroad that it linked to the People’s Mojahedin Organization of Iran, or PMOI/MEK, and its political front, the National Council of Resistance of Iran. The operators used a shared AI-agent platform to support impersonation, audience profiling, coordinated social-media activity, synthetic personas and the laundering of organisational content through apparently independent accounts. At least four people involved in the operation worked for official NCRI media outlets, according to Anthropic. The company also found references to committee approval processes and MEK leadership, but said it could not independently determine the precise level of central control. Cloning a person from 8,400 Telegram posts The most striking part of the operation involved a real activist whose Telegram identity was copied. According to Anthropic, the operators instructed Claude in Persian that it was now that person, then provided approximately 8,400 of the activist’s Telegram posts so the system could learn and reproduce his writing style. The AI-assisted account was subsequently used to conduct live political conversations with the activist’s existing contacts. Anthropic says that, to its knowledge, the people receiving those messages did not know they were interacting with an account being operated with AI assistance. This is materially different from a conventional chatbot or a static deepfake. The system was not simply producing a forged statement attributed to someone else. It was using a large archive of that person’s authentic language as behavioural training material, then applying the resulting imitation interactively. In practical terms, the deception moved from synthetic content to synthetic identity. Anthropic did not publish the identity of the impersonated activist, nor details of his contacts, and the public report does not establish what specific information the conversations produced. What it does establish is that the impersonation was operational rather than experimental: the cloned account was used in real exchanges with real people. From social-media monitoring to psychographic dossiers The impersonation sat inside a much broader targeting system. Anthropic says the network scraped more than 500 social-media channels and categorised individuals by location, age, profession, political orientation and arrest history. It then analysed approximately 51,944 archived messages from conversations to construct detailed psychographic dossiers on dozens of people inside Iran. The system was therefore not limited to broadcasting propaganda. It was also designed to understand specific audiences and individuals. Profiles could be used to decide what kind of message was most likely to resonate with a particular person, which political identity they appeared closest to and how they should be approached. Anthropic describes this as a structured targeting funnel rather than ad hoc social-media activity. That distinction is important in the Iranian context. Political activists, dissidents and opposition contacts inside Iran can face arrest and severe punishment. The report does not show that the dossiers directly led to arrests or other harm, but collecting and organising information such as arrest history and political affiliation adds a surveillance dimension to what would otherwise be described as an influence operation. A shared AI system for an influence network Anthropic found that the actors used a shared Claude-based platform named “Viktor”, with separate workspaces and persistent memory. Those memory files contained approved sources, prohibited words, account-management instructions and methods intended to reduce the risk of detection. One operator loaded MEK founding doctrine into the system as what the report called “strategic base data”, allowing others to reuse it across their work. This persistent-memory structure meant the AI did not have to be briefed from scratch for every task. Once doctrine, stylistic rules and operational constraints had been stored, the system could repeatedly produce material consistent with the network’s objectives. Anthropic says the same general playbook appeared across different workspaces despite the operators not sharing obvious account infrastructure. The network also used automated pipelines to coordinate Instagram posting schedules and tailor messages to different audiences. Some accounts initially avoided mentioning the Mojahedin at all, allowing material aligned with MEK/NCRI narratives to appear as neutral or independent political commentary. Content was distributed through the organisation’s own media ecosystem as well as accounts presented as ordinary news or activist profiles. Anthropic assessed the campaign as Category Two on its Breakout Scale: active on multiple platforms with distribution through NCRI-linked media properties and amplifier accounts, but without evidence of broad authentic penetration. Synthetic citizens and disguised organisational media The same infrastructure generated AI avatars presented as ordinary Iranians, complete with Persian audio, to promote Maryam Rajavi’s political programme. Anthropic says the synthetic nature of these personas was intentionally concealed. Operators also rewrote and redistributed content originating from MEK-affiliated media while stripping identifying features or presenting it through apparently independent accounts. The network’s political messaging targeted the Iranian government but also rival opposition currents, including monarchists and supporters of the Pahlavi camp. Anthropic documented fabricated video material attacking a member of the Pahlavi family and the use of the slogan “Neither Shah Nor Sheikh”, consistent with the NCRI’s broader competition with other opposition movements. That rivalry provides relevant context. Reuters describes the MEK as one of Iran’s principal organised opposition movements in exile and the dominant force behind the NCRI, led by Maryam Rajavi. Its relationship with other opposition currents is often contentious, while the extent of its support inside Iran remains uncertain. What can be attributed – and what cannot Anthropic’s attribution is unusually specific but still needs to be stated carefully. The company says its investigation linked the operation to MEK/NCRI and established that at least four participants worked for official NCRI media organisations. It also found a common operational playbook, committee review structures and repeated references to MEK leadership. On that basis, Anthropic said central tasking was likely. It nevertheless stopped short of saying it had proven that NCRI’s senior leadership directly ordered or managed every component of the operation. That caveat matters. The strongest public evidence supports describing GTG-84006 as a MEK/NCRI-aligned influence operation involving personnel from official NCRI media, rather than asserting that every action was directly commanded by the organisation’s top leadership. The broader significance of the case lies elsewhere. Earlier generations of synthetic media attempted to fabricate evidence: a photograph, a voice recording or a video. Here, AI was used to maintain an identity over time, remember doctrine, analyse targets and speak directly to real people while appearing to be someone they already trusted. The deepfake was no longer merely an artefact. It had become a participant in the conversation. Sources Anthropic — Countering misuse of AI: September 2026 https://www.anthropic.com/threat-intelligence-report-september-2026 AI Misuse Case Library — GTG-84006 activist impersonation case https://www.misuseofai.com/en/cases/gtg-84006-activist-impersonation/ Reuters — Who makes up Iran’s fragmented opposition? https://www.reuters.com/business/media-telecom/who-makes-up-irans-fragmented-opposition-2025-06-18/ Reuters — Iran’s divided opposition senses its moment https://www.reuters.com/world/middle-east/irans-divided-opposition-senses-its-moment-activists-remain-wary-protests-2025-06-19/ Reuters — NCRI and Maryam Rajavi https://www.reuters.com/world/middle-east/dissident-leader-abroad-urges-iranians-bring-down-khamenei-2025-06-24/ Keywords #DISINFORMED #Episode12 #Iran #MEK #PMOI #NCRI #IranianOpposition #Disinformation #InfluenceOperations #InformationWarfare #ArtificialIntelligence #AI #GenerativeAI #ClaudeAI #Anthropic #AIDeception #AIImpersonation #IdentityImpersonation #SyntheticIdentity #InteractiveDeepfake #DigitalImpersonation #PersonaCloning #BehaviouralCloning #Telegram #PsychographicProfiling #TargetProfiling #AudienceTargeting #SocialMediaManipulation #Astroturfing #SyntheticPersonas #NarrativeLaundering #CoordinatedInfluence #PoliticalInfluence #DigitalInfluence #OppositionPolitics #IranPolitics #OSINT #WRLD

Countering misuse of AI: September 2026 / Anthropic

Iran’s cognitive warfare – when AI becomes the operating layer of state propaganda Iranian state-linked influence operators were not using artificial intelligence simply to write faster social-media posts. According to Anthropic’s September 2026 threat intelligence report, three separate operations connected to Iranian propaganda institutions were using Claude to help construct the machinery behind what the operators themselves called “soft war” and “cognitive warfare” – non-military efforts intended to shape public opinion inside Iran and abroad. Anthropic linked the activity to the Islamic Culture and Communications Organization (ICCO), which operates under Iran’s Ministry of Culture and Islamic Guidance; the Islamic Propaganda Office of Khorasan Razavi; and the Bina Cultural Observatory, part of the Islamic Propaganda Organization. The company said each operation was run by someone working within or on behalf of the named institution. The attribution was based on a combination of account telemetry, institutional references disclosed during conversations, branded documents and open-source corroboration. Anthropic subsequently removed the accounts. AI as an operational headquarters The most significant feature of the operation was the role assigned to AI. Claude was used to develop campaign plans, doctrine manuals, coded project portfolios, persona systems, target databases, early-warning protocols, amplification schedules and ministerial planning documents. Anthropic described the model as the principal administrative and operational layer supporting the three campaigns, allowing relatively small groups of operators to create organisational structures and planning material that would otherwise have required a much larger staff. This distinction matters. The reported use of AI went considerably beyond content generation. Operators were using the model to help organise how influence activity should function: which audiences to target, which identities should deliver particular narratives, how official material should be repackaged and when amplification should take place. Human operators still determined objectives and supplied the underlying political doctrine; AI helped translate those decisions into an operational system. Anthropic found that all three operations explicitly connected their activity to Jihad al-Tabyin, often translated as “explanatory jihad”, a concept used within the Iranian state system to frame information activity as both a strategic and ideological responsibility. In internal planning material examined by the company, this doctrine was not merely rhetorical: it informed manuals and campaign structures used by the operators. ‘Not the narrator, but the director’ One sentence contained in the ICCO material captures the model particularly clearly. According to Anthropic, an operator described the role of Iranian cultural attachés as being “not to be the narrator, but the director” of the narrative. The distinction reveals the logic of attribution laundering. Instead of publishing an overt state message and asking foreign audiences to believe it, the operator attempts to create the appearance that the same narrative emerged independently from journalists, activists, foreign writers or ordinary citizens. Anthropic found that Claude was used specifically to make content appear to come from foreign authors or independent media organisations and to design hashtag campaigns that looked grassroots rather than centrally organised. The ICCO operation reportedly used the organisation’s international cultural network as part of this structure. Anthropic found ministerial-level documents carrying official ICCO branding, including a nine-part international influence portfolio. This makes the operation particularly significant because the infrastructure was not limited to anonymous social-media accounts; it intersected with formal state institutions and an existing network of cultural representation abroad. A multilingual content factory A second operation was associated with the Islamic Propaganda Office of Khorasan Razavi and what Anthropic described as a “cognitive warfare command room” operating from a seminary in Mashhad. Its organisers ran a multi-province content production system known internally as Manjanegh, or “Catapult”. According to Anthropic, dozens of activists were involved in repackaging publicly available reporting from Iranian security institutions under different personas so that the material no longer appeared directly connected to those institutions. The network used Claude to transform official government intelligence bulletins into customised material in Farsi, Arabic, Urdu, Malay, Spanish and English, while planning expansion into a total of 20 languages. Distribution extended across Iranian platforms such as Eitaa, Bale and Rubika and international services including X, Instagram, Telegram, TikTok and YouTube. Anthropic also documented paid amplification across more than 100 Iranian channels, including channels associated with IRGC narratives. The scale should nevertheless be interpreted carefully. Anthropic documented production infrastructure and some real-world dissemination, but it did not demonstrate that all planned campaigns were fully deployed or that they meaningfully changed public opinion. The company placed the operation in Category Three of its Breakout Scale, indicating multi-platform activity with content observed in external distribution channels, rather than evidence of strategic impact on entire populations. From security bulletins to apparently independent voices The Bina Cultural Observatory operation provides another example of the same architecture. Anthropic linked a director-level official at Bina to activity in which Claude generated messaging in the voice of an IRGC spokesperson. During the 2026 US–Israel–Iran war, the network also attributed false claims to Western institutions including CSIS, Brookings and RAND. The apparent objective was to make Iranian state-aligned claims look as though they had been independently validated by respected foreign research organisations. That technique is more sophisticated than simply publishing propaganda under a false name. It attempts to manufacture a chain of external validation: official information is transformed into apparently independent commentary, which can then be recirculated as evidence that outside observers have reached the same conclusion. Anthropic also found target databases naming international officials and Iranian opposition figures, as well as aggressive counter-narrative material directed against the Bahá’í community. These findings show that the infrastructure was designed not only for broad messaging but also for targeted influence activity against specific groups and individuals. What AI changed The Iranian operations described by Anthropic did not create a new doctrine of influence. Iran has used cultural institutions, official media, aligned organisations and covert or semi-covert online networks for years. What AI changed was the economics and organisational capacity of that model. A relatively small team could use the system to draft doctrine, create personas, translate material, structure target databases, produce campaign calendars and generate multiple versions of the same message for different audiences. The operator remained responsible for intent, political direction and selection of targets. AI reduced the amount of human labour required to turn those decisions into a functioning influence operation. The most revealing part of the case is therefore not that an Iranian propaganda network used a chatbot. It is that AI was being treated as part of the back office of information warfare – a system for converting state doctrine into apparently decentralised, multilingual and plausibly independent voices. Sources Anthropic — Detecting and countering misuse of AI: September 2026 https://www.anthropic.com/threat-intelligence-report-september-2026 Iran International — Iran state-aligned accounts used Claude to push IRGC narratives https://www.iranintl.com/en/202609105561 BNE IntelliNews — Yemen missile cell used AI to write guidance software, Anthropic says https://new.intellinews.com/articles/yemen-missile-cell-used-ai-to-write-guidance-software-anthropic-says-467296 This is Beirut — Anthropic report details Iranian propaganda operations https://thisisbeirut.com.lb/news/politics/anthropic-report-details-iranian-propaganda-operations-and-yemen-missile-development-using-claude Anthropic report — PDF mirror https://static.foxbusiness.com/foxbusiness.com/content/uploads/2026/09/anthropic-detecting-and-countering-091026-1.pdf Keywords #DISINFORMED #Episode11 #Iran #IranianInfluence #IranianPropaganda #CognitiveWarfare #SoftWar #JihadAlTabyin #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #ArtificialIntelligence #AI #AIPropaganda #GenerativeAI #ClaudeAI #Anthropic #SyntheticMedia #NarrativeManipulation #NarrativeLaundering #AttributionLaundering #PersonaNetworks #Astroturfing #SocialMediaManipulation #DigitalInfluence #StatePropaganda #IslamicCultureAndCommunicationsOrganization #ICCO #IslamicPropagandaOrganization #KhorasanRazavi #IRGC #MultilingualInfluence #Targeting #Amplification #OSINT #WRLD

Countering misuse of AI: September 2026 / Anthropic

UAE / Sudan – when an influence operation tried to enter the United Nations A network of roughly 300 apparently independent social-media influencers. A human-rights organisation borrowing the identity of a real NGO. Personal dossiers on European politicians and journalists. And testimony prepared for delivery at the United Nations without revealing the state interest behind it. These were elements of an influence operation uncovered by Anthropic and disclosed in September 2026. The company says it linked the activity with high confidence to UAE government officials. Tracked as GTG-84002, the operation targeted several overlapping issues: the Muslim Brotherhood, perceptions of the war in Sudan and international mechanisms examining the United Arab Emirates' role in the conflict. What distinguishes the case is not simply its use of artificial intelligence. It is the attempt to make state-aligned messaging appear to originate from independent influencers, human-rights organisations and potentially witnesses addressing an international institution. An influence network built around 300 fake voices Anthropic identified a single actor using Claude to support a sustained influence campaign. At its centre was an AI persona called “Deadshot”, running on the operator's own platform. A master doctrine file repeatedly instructed the system to support what it described as a coordinated international effort to dismantle the Muslim Brotherhood. The operator simultaneously managed several components of the campaign, including approximately 300 inauthentic influencer accounts across social-media platforms. Internal material examined by Anthropic described the apparent independence of this network as its greatest strategic advantage. That phrase captures the central method. The objective was not simply to broadcast a political position but to conceal where that position originated. One visible example appeared on 4 June 2026, when accounts participated in a coordinated campaign using #SudanIslamists and near-identical graphics connecting Sudanese Islamists and the Muslim Brotherhood with regional instability. Anthropic says the amplification network was centrally funded and coordinated. Its investigation also found that the operator financing the social-media network was connected to the wider influence operation. A human-rights organisation that was not what it appeared to be Social media was only one layer. The operator also created a front NGO that copied the identity of a genuine Swiss organisation and used that borrowed legitimacy to publish human-rights material produced for the campaign. Anthropic's description elsewhere also refers to the identity of a real Sudanese human-rights organisation being used in connection with the preparation of testimony. The public report does not fully clarify whether these references describe the same front or separate elements of the operation, so they should not be treated as definitively identical. The underlying technique, however, is clear: political material was designed to appear as if it originated from independent civil society rather than from actors linked to a government. This is particularly significant in the human-rights environment, where the perceived independence of an organisation or witness can determine how seriously evidence is received by journalists, diplomats and international institutions. The attempt to reach the UN The most consequential part of the operation concerned the 62nd session of the UN Human Rights Council. According to Anthropic, the operator used Claude to ghost-write complete testimony intended to be delivered by two individuals during the session. The texts were prepared under explicit constraints ensuring that neither statement would mention the UAE. This did not amount to a conventional government submission. The intention, according to Anthropic's reconstruction, was for material serving the interests of a party connected to the Sudan conflict to reach an international forum through apparently independent voices. But an important limitation remains: Anthropic could not confirm that the testimony was ultimately delivered. The company similarly could not establish whether other dossiers produced by the operation reached their intended recipients or influenced policy. It therefore assessed the campaign as Category Three on the Brookings Breakout Scale – activity distributed across several platforms, but without evidence of broad public impact sufficient for a higher classification. The distinction matters. The evidence demonstrates a sophisticated attempt to influence international debate; it does not demonstrate that the attempt succeeded. Politicians, journalists and UN investigators became targets The operation was not limited to generating public content. Anthropic found that the operator researched and compiled detailed profiles of 18 members of the European Parliament and prominent journalists. Some material was prepared for direct delivery to senior UAE officials. The network also assembled what Anthropic describes as “counter-accountability dossiers” on UN Special Rapporteurs who had criticised the UAE's conduct in relation to Sudan. This places the campaign in a broader context. Since Sudan's civil war began in April 2023, the role of external powers has become an increasingly important part of international scrutiny. Sudan has accused the UAE of supporting the Rapid Support Forces, allegations Abu Dhabi has repeatedly denied. In 2025, Sudan brought a case against the UAE before the International Court of Justice, accusing it of complicity in genocide against the Masalit through alleged support for the RSF. The UAE rejected the allegations. The ICJ subsequently removed the case from its list after finding that it lacked jurisdiction because of the UAE's reservation to the relevant provision of the Genocide Convention. The ruling therefore did not determine whether Sudan's substantive allegations were true or false. That contested international environment helps explain why narratives about Sudan, human rights and accountability were valuable targets for an influence operation. AI as an operating system for influence The role played by Claude is also important to understand accurately. Anthropic did not find that artificial intelligence independently conceived or directed the campaign. Human operators established the objectives, political doctrine and targets. AI instead helped operationalise them. Across hundreds of sessions, Claude was used to transform predetermined political objectives into social-media narratives, human-rights reports, testimony, intelligence-style briefs and detailed profiles of individuals. The same system could support narrative production, target research and preparation of material for different audiences. That represents a more significant development than simply using generative AI to produce propaganda faster. Traditional influence operations require different teams to research targets, write content, manage personas, adapt messages and prepare briefing material. Generative AI can compress several of those functions into a single operational workflow. The result is not necessarily more convincing propaganda. It is potentially cheaper, faster and more scalable influence infrastructure. From fake influencers to institutional influence Anthropic says it linked the operation to UAE government officials with high confidence. Its assessment was based partly on internal material naming senior Emirati officials as intended recipients of the work, alongside other evidence available to its investigators. That remains an attribution by Anthropic rather than a judicial finding or publicly released forensic attribution by a government agency. The distinction should be retained. The larger significance of GTG-84002 lies in the architecture of the campaign. A network of fake influencers could create the appearance of public opinion. A cloned human-rights organisation could provide institutional credibility. AI-generated reports could give political narratives the appearance of research. Profiles of journalists and politicians could support more precise targeting. And ghost-written testimony could potentially carry the same message into an international institution without revealing the political interest behind it. This is a different model from the familiar troll farm. The objective is no longer simply to make propaganda look popular. It is to make state-aligned messaging look independent – and, if possible, to move it from social media into the institutions where international policy and accountability are debated. SOURCES: Anthropic — Countering misuse of AI: September 2026 https://www.anthropic.com/threat-intelligence-report-september-2026 International Court of Justice — Sudan v. United Arab Emirates https://www.icj-cij.org/case/197 International Court of Justice — press releases and case documents https://www.icj-cij.org/case/197/press-releases United Nations Geneva — Sudan v UAE proceedings at the ICJ https://www.ungeneva.org/en/news-media/news/2025/04/105241/world-court-begins-hearing-sudans-complicity-genocide-case-against UAE Ministry of Foreign Affairs — UAE response to Sudan's allegations https://www.mofa.gov.ae/en/MediaHub/News/2025/4/10/10-4-2025-UAE-UAE UN Digital Library — Sudan's letter concerning alleged UAE support for the RSF https://digitallibrary.un.org/record/4091008?ln=en UN Digital Library — UAE response concerning allegations of support for the RSF https://digitallibrary.un.org/record/4046224?ln=en Ultra Sudan — reporting on Anthropic's UAE-linked influence-operation findings https://ultrasudan.usawtiq.com/أنثروبيك-أحبطنا-عملية-تأثير-إماراتية-استخدمت-الذكاء-الاصطناعي-لاستهداف-السودان/عامر-صالح/أخبار KEYWORDS #DISINFORMED #Episode8 #UAE #Sudan #UnitedArabEmirates #UnitedNations #UNHumanRightsCouncil #HumanRights #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #CoordinatedInauthenticBehaviour #CIB #FakeInfluencers #FakeNGO #NGOImpersonation #Astroturfing #ArtificialIntelligence #AI #AIPropaganda #AIGeneratedContent #SyntheticMedia #SocialMediaManipulation #DigitalInfluence #Propaganda #NarrativeManipulation #InstitutionalInfluence #SudanConflict #SudanWar #MuslimBrotherhood #InternationalRelations #Geopolitics #Anthropic #ClaudeAI #OSINT #WRLD

Countering misuse of AI: September 2026 / Anthropic

Russia’s fake African newsrooms – propaganda designed to look local A Facebook user in Nairobi, Accra, Johannesburg or Luanda encounters what appears to be a local news page. It publishes stories about African politics, Western influence and relations with Russia. The language is tailored to an African audience and the page presents itself not as a foreign broadcaster, but as part of the local information landscape. Behind some of these outlets, however, Meta found operators based in Russia. In its 2026 threat research, the company disclosed a Coordinated Inauthentic Behaviour network targeting audiences in Angola, Ghana, Kenya and South Africa. Meta removed 37 Facebook accounts and 29 Pages connected to the operation. Around 30,000 users followed at least one of the Pages, while the operators spent approximately $7,000 on Facebook and Instagram advertising, mostly in euros and US dollars. The numbers are relatively modest. The method is considerably more important. Rather than openly distributing Russian state messaging, the network posed as local African news sources and grassroots organisations, promoting narratives about Western colonialism and political interference while presenting Russia as a credible economic and political alternative. It was an old geopolitical message delivered through a much more effective identity: not Moscow speaking to Africa, but Africans apparently speaking to one another. A news outlet that was actually an influence operation Meta's investigation found that the network attempted to conceal its Russian origin while creating media brands that appeared indigenous to the countries they targeted. Its content amplified historical grievances against former colonial powers, criticised Western involvement in Africa and promoted closer relations with Russia. One example helps illustrate how the infrastructure was assembled. A Facebook Page targeting Kenya was called Kenya Watchtower. According to OpenAI's subsequent investigation, Facebook transparency records showed that the Page had previously been named “Farmtown5”. It appears to have been acquired or repurposed rather than built from scratch as a Kenyan news organisation. Some Pages also exposed administrator locations in Russia and Ukraine. Other elements of the network had previously targeted audiences in Zambia and Namibia. This use of apparently local identities is particularly important in the African information environment. A story published by RT or another identifiable Russian outlet arrives with an obvious geopolitical provenance. The same narrative presented by something resembling an independent Kenyan, Ghanaian or South African newsroom carries a different kind of credibility. The source appears closer to the reader, and the geopolitical interest behind the message becomes less visible. Then investigators found Dr Manuel Godsin The Facebook operation was only one part of a broader information ecosystem. OpenAI investigated related activity after receiving information from Meta and subsequently banned a ChatGPT account it assessed as likely originating in Russia. OpenAI called the campaign Operation No Bell. The account was being used to generate long-form articles and social-media posts about African geopolitics. Prompts were primarily written in English, but OpenAI also observed Russian-language instructions that the user described as coming from a manager. The operator sometimes explicitly asked the model to make the material appear less AI-generated – including requests to avoid stylistic features associated with machine-generated text and to write more like a human journalist. Many articles appeared under the name “Dr Manuel Godsin”, presented as an academic with a PhD from the University of Bergen and an affiliation with an organisation called the International Centre for Political and Strategic Studies. OpenAI could find no credible evidence that Godsin existed. Searches of Norway's National Research Information Repository and the University of Bergen library produced no record of him. Investigators subsequently discovered that a photograph used to represent Godsin had appeared years earlier on a Russian professional networking site and apparently belonged to a law student in St Petersburg. The fabricated academic identity was nevertheless remarkably productive. OpenAI identified 53 online articles carrying the Godsin byline. The fiction had moved beyond fake social-media pages and into the real media ecosystem. When propaganda enters genuine newsrooms This is the most consequential aspect of the operation. The articles were not confined to websites controlled by the influence network. Some were published by genuine African news organisations, including established South African outlets. The content mixed local political issues with broader geopolitical narratives. Some pieces criticised the United States and Britain or defended Russia's role in Africa. One accused the British NGO Crisis Action of fomenting protests in South Africa. Another praised Russia's presence in the Central African Republic. Other material addressed Kenya, Angola and relations between African governments and Washington. The mechanism represents a significant evolution from the classic troll-farm model. Instead of building an audience entirely on its own platforms, an influence operator can manufacture an apparently credible expert, generate articles in his name and persuade genuine news organisations to publish them. Once this happens, the propaganda acquires something a fake Facebook Page cannot provide: the institutional credibility of a real newsroom. OpenAI assessed No Bell's social-media impact as limited. One Facebook Page had around 3,000 followers before Meta removed it, while several others had very small audiences. But the operation was more successful in placing material in established media. In OpenAI's impact framework, it approached the level at which an influence operation breaks into mainstream media. For information operators, a single article published by a recognised outlet can potentially be more valuable than thousands of impressions generated by an obviously artificial account. A much larger network of ghost journalists Subsequent research suggests that Manuel Godsin was not an isolated experiment. In August 2026, Graphika, working with Code for Africa and with support from Meta, published a much broader investigation into Russian ghostwriting operations across African media. Researchers identified 44 ghost writers and fake experts, 38 of them assessed as high-confidence fabricated personas, operating between 2021 and 2026. Their material appeared or was quoted across 138 websites and was subsequently republished through at least 113 Facebook accounts and Pages, including authentic users, coordinated inauthentic networks and official Russian communication channels. The narratives were strikingly consistent. They included criticism of France, Ukraine and the United States; attacks on organisations such as ECOWAS and the International Criminal Court; positive portrayals of Russian involvement in Africa; praise for Russian paramilitary forces; and support for sovereignty-oriented political projects such as the Alliance of Sahel States. The operation therefore extends beyond creating fake news websites. It attempts to insert Russian-aligned narratives into the legitimate African media ecosystem using identities that appear African, independent or academically authoritative. This also explains why measuring reach through the original Facebook network alone is misleading. A fabricated article may begin with an influence operator, appear in a genuine African publication, be republished elsewhere and eventually circulate without any visible connection to Russia. At that point, the provenance of the narrative has effectively been laundered. An old Russian strategy with increasingly local faces Russia's use of local intermediaries in Africa is not new. Meta documented Russian networks using African nationals as early as 2019. In 2020 it dismantled another operation involving people in Ghana and Nigeria working on behalf of individuals in Russia, with links to previous activity associated with the Internet Research Agency. More recent Meta investigations suggest that this model has continued to evolve. Networks have increasingly relied on local freelancers, social-media managers and authentic media outlets rather than exclusively operating armies of obviously fake Russian-controlled accounts. This decentralisation offers several advantages. Local operators understand language, political sensitivities and cultural references. Authentic accounts are harder to identify than newly created synthetic personas. Local media brands can also deliver narratives without immediately triggering the scepticism associated with Russian state outlets. There is no evidence that every African journalist, freelancer or publication carrying such material knowingly participates in Russian influence activity. Meta explicitly notes in its investigations that some local contractors may not know who ultimately commissioned their work. That distinction is essential. The operation's effectiveness partly depends on precisely this ambiguity between deliberate participation, commercial content placement and unwitting amplification. The objective is to make Russian narratives look African The significance of this network is therefore not its 30,000 Facebook followers or its $7,000 advertising budget. Those figures are small compared with the audiences of major African media organisations. What matters is the distribution model. Traditional foreign propaganda asks an audience to trust a foreign source. These operations attempt to remove the foreign source from the equation altogether. A Russian geopolitical narrative can be generated with AI, attributed to an expert who does not exist, published by a media organisation that does, amplified through a Facebook Page presenting itself as local, and then rediscovered elsewhere as apparently independent African analysis. By the time the reader encounters it, Moscow may have disappeared completely from the chain of attribution. The resulting information operation is therefore less about making Russian propaganda more persuasive than about making it look as though it is no longer Russian propaganda at all. In an increasingly fragmented African media environment, that may be the more important evolution to watch. SOURCES: Meta Threat Research https://threatresearch-team.github.io/indicators/meta-h1-2026-russia-based-cib-network-1/ OpenAI — Operation “No Bell” https://openai.com/index/disrupting-malicious-uses-of-ai-no-bell/ Graphika — Umbrae Ex Machina https://www.graphika.com/reports/umbrae-ex-machina News24 https://www.news24.com/southafrica/news/ai-expert-exposed-fake-kremlin-linked-analyst-planted-stories-in-african-media-20260318-0560 Vanguard https://www.vanguardngr.com/2026/03/ai-expert-exposed-fake-kremlin-linked-analyst-planted-stories-in-african-media/ Meta — Russian Coordinated Inauthentic Behaviour, 2019 https://about.fb.com/news/2019/10/removing-more-coordinated-inauthentic-behavior-from-russia/ Meta — Russian Coordinated Inauthentic Behaviour, 2020 https://about.fb.com/news/2020/03/removing-coordinated-inauthentic-behavior-from-russia/ Meta Threat Research — Russian Use of Authentic Operators in Sub-Saharan Africa https://threatresearch-team.github.io/indicators/meta-h2-2025-russia-based-cib-network-2/ KEYWORDS: #DISINFORMED #Episode7 #Russia #Africa #RussianDisinformation #RussianInfluence #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #CoordinatedInauthenticBehaviour #CIB #FakeNews #FakeMedia #FakeNewsrooms #MediaImpersonation #GrassrootsManipulation #Astroturfing #ArtificialIntelligence #AI #AIPropaganda #SyntheticMedia #FakeInfluencers #SocialMediaManipulation #Facebook #Meta #OperationNoBell #AfricanMedia #MediaManipulation #Propaganda #DigitalInfluence #Angola #Ghana #Kenya #SouthAfrica #OSINT #WRLD

Russia-Based Influence Operation Network Targeting Sub-Saharan Africa

The Ghosts of Zaolzie – how a cyberattack tried to manufacture a conflict between Poland and Czechia At around 5pm on 16 August 2026, an alarming article appeared on the website of Radio PiK, a genuine Polish regional broadcaster. Its headline claimed that Poland was preparing to seize Czech territory and that the Czech Foreign Ministry had received a document outlining Warsaw's demands. Radio PiK had published no such story. An attacker had compromised an employee's credentials, gained access to the station's content management system and replaced a legitimate article with fabricated material. The newsroom quickly removed it and informed the authorities. But the intrusion was only one element of a much larger operation. Investigators subsequently uncovered forged diplomatic documents, accounts impersonating Polish and Czech officials, a cloned Czech news site, AI-generated material, a fictitious local activist and advertising for a demonstration that apparently did not exist. Together, these elements attempted to manufacture the appearance of a new territorial conflict between Poland and Czechia over Zaolzie. A false crisis built around a real territorial issue The operation worked because it did not start entirely with fiction. Poland and Czechia do have an unresolved technical issue concerning approximately 368.44 hectares of territory, originating in post-war changes to the Polish-Czechoslovak border. It is commonly described as the Czech “territorial debt” to Poland. But this is not a Polish claim to Zaolzie and there is no evidence that Warsaw is seeking to annex Czech territory. The operation fused this real issue with a much more powerful historical memory. Zaolzie – the part of Cieszyn Silesia west of the Olza River – was disputed by Poland and Czechoslovakia after the First World War. In 1938, during the crisis created by the Munich Agreement, Poland seized the territory from Czechoslovakia. The manipulation therefore followed a simple logic: a real territorial debt became an alleged Polish territorial demand, which was then transformed into a supposed attempt to reclaim Zaolzie. Fake accounts impersonating Poland's Deputy Foreign Minister Artur Harazim and Czech ambassador Břetislav Dančák helped reinforce the story. Fabricated diplomatic documents circulated alongside them. One early version referred incorrectly to 638.44 hectares; the fake Harazim account then “corrected” the number to the genuine figure of 368.44 hectares. It was an effective form of reverse fact-checking: correcting one false detail could make the larger fabrication appear authentic. Fake media – and one real newsroom The operators also created a website designed to resemble Czech public broadcaster iRozhlas. It published material supporting the same narrative, including claims that Czech residents near the border were becoming concerned about Polish intentions. The result was a manufactured information loop. Forged documents could support fake media reports; impersonated officials could comment on those reports; social-media accounts could then cite both as confirmation. But the Radio PiK hack added something much more valuable: the credibility of a real media organisation. Instead of merely cloning a newsroom, the attackers briefly inserted their fabrication into an authentic one. A familiar domain, logo and established broadcaster could therefore appear to confirm a story manufactured elsewhere. The cyberattack was not simply an accompanying technical incident. It was part of the information operation itself – a way of manufacturing credibility for false information. From a synthetic activist to a real demonstration The operation then attempted to move from the digital world into the physical one. A Facebook account under the name “Adam Sikora” promoted a demonstration in the Czech border city of Třinec under slogans including “Cieszyn Silesia is Czech” and “Here we live, here we stay”. Paid Facebook advertising was reportedly used to promote the event. Yet Třinec authorities said no demonstration had been properly notified. Promotional material used the logo of the Czech KOVO trade union, which denied any involvement. Investigators also identified indications that Sikora's profile photograph and other imagery were AI-generated. The persona even advertised a supposed house for sale in the border region, reinforcing the impression that frightened residents wanted to leave because of Polish territorial ambitions. The property could not be verified and its images also showed signs of artificial generation. This reveals the architecture of the operation: forged document → fake official → cloned media → compromised real media → synthetic local activist → advertised protest → appearance of social tension. The final stage is particularly significant. Had real people attended the demonstration, photographs of an authentic crowd could potentially have been presented as evidence that Czech citizens genuinely feared Polish territorial ambitions. A fabricated online conflict could therefore have begun generating real-world evidence of its own existence. Why Zaolzie? Historical grievances are valuable material for influence operations because the underlying facts are real. Poland and Czechoslovakia genuinely disputed Cieszyn Silesia. Poland genuinely occupied Zaolzie in 1938. A Polish minority genuinely lives in Czechia. And the 368.44-hectare territorial issue genuinely exists. The operator did not need to invent that history. It only needed to suggest that the history was repeating itself. PISM assessed that the operation sought to revive the image of Poland as a revisionist state willing to challenge European borders. Such a narrative could serve a broader purpose: damaging Polish-Czech relations, weakening confidence between NATO and EU allies and portraying Central Europe as a region where historical territorial conflicts remain unresolved. Russia is the leading attribution – but not a proven one The attribution requires more caution than the mechanics of the operation. PISM assessed Russia as the most likely perpetrator, while NASK identified similarities between the campaign and previously observed Russian influence methods. Russian-linked information infrastructure had also shown earlier interest in the Polish-Czech territorial issue. The techniques are familiar: cloned media, forged documents, impersonated officials, synthetic identities, historical grievances and the combination of cyber intrusion with information manipulation. But these indicators are not the same as definitive attribution. As of mid-September 2026, no publicly disclosed forensic evidence had conclusively connected the Radio PiK compromise, fake domains, accounts and financing to a specific Russian intelligence service, government organisation or contractor. Russia can therefore reasonably be described as the leading analytical attribution, but claims that the operation was definitively conducted by the GRU or another named Russian structure go beyond the publicly available evidence. The operation failed. The model remains important The campaign did not create a Polish-Czech diplomatic crisis. Both governments rejected the narrative, the fictitious protest was exposed, journalists reconstructed much of the operation and Radio PiK detected the intrusion quickly. Its observable impact appears to have been limited. But Zaolzie illustrates a broader evolution in information warfare. Modern operations do not have to rely on a single viral fake. They can construct an entire artificial information environment in which different elements appear to confirm one another. A forged document creates the claim. A fake diplomat authenticates it. A cloned newsroom reports it. A hacked real newsroom lends it credibility. An AI-generated citizen reacts to it. Advertising creates the appearance of a grassroots movement. And if real people eventually respond, fiction begins producing genuine events. The objective is no longer simply to persuade people that something happened. It is to create the conditions in which something real starts happening because enough people believed that it did. Sources: Polish Institute of International Affairs (PISM) https://pism.pl/publikacje/dezinformacja-o-relacjach-polsko-czeskich Euronews Polska — Radio PiK cyberattack https://pl.euronews.com/2026/08/20/polska-planuje-zajecie-terytorium-czech-wlamali-sie-na-strone-radia-i-opublikowali-falszyw Demagog https://demagog.org.pl/na-biezaco/skoordynowana-operacja-uderza-w-polsko-czeskie-relacje-czy-stoi-za-nia-rosja/ Robert Lansing Institute https://lansinginstitute.org/2026/08/27/zaolzie-as-an-instrument-of-influence-an-attempt-to-revive-a-polish-czech-territorial-conflict/ Institute for European Security Studies (IESS) https://www.iess.org.ua/analytics/ghosts-of-zaolzie iDNES.cz https://www.idnes.cz/ostrava/zpravy/tesinsko-kampan-lzi-demonstrace-trinec-primatorka-palkovska.A260826_963356_ostrava-zpravy_jog Radio Zachód / PAP https://zachod.pl/1539751/niedzielny-atak-hakerski-na-radio-pik-redaktor-naczelny-podjelismy-niezwloczne-dzialania/ Euronews — territorial debt / NASK assessment https://de.euronews.com/my-europe/2026/08/21/polen-plant-besetzung-tschechischen-gebiets-fake-news TVP World https://tvpworld.com/95036191/-warsaw-warns-against-division-amid-czech-border-disinformation Keywords: #DISINFORMED #Episode5 #GhostsOfZaolzie #Zaolzie #Poland #Czechia #CieszynSilesia #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #Cyberattack #CyberSecurity #HybridWarfare #FakeNews #MediaImpersonation #FakeMedia #ForgedDocuments #DigitalImpersonation #ArtificialIntelligence #AI #Deepfakes #SyntheticMedia #Astroturfing #RussianInfluence #Propaganda #OSINT #NATO #CentralEurope #MediaManipulation #WRLD

Der er et stort problem, at det er den RUC-uddannede pressechef hos Folkekirkens Nødhjælp Poul Kjar, der står bag Baronessen af Nilen: 1/ Har han skrevet på profilen i arbejdstiden, således at det er skatteyderne, der helt eller delvis har betalt hans løn, mens han er gået efter @oresundsbaron? 2/ Er hans chef sekretariatschef Jonas Nøddekær indforstået med, at Baronessen af Nilen er en del af Poul Kjars arbejdsområde? 3/ Ved at skjule at han er pressechef i Folkekirkens Nødhjælp, har Poul Kjar gjort sig skyldig i det, der hedder "astroturfing" opkaldt efter det mest almindelige amerikanske mærke for kunstgræs. Poul Kjar præsenterer Baronessen fra Nilen som et initiativ fra en almindelig borger, altså fra en af "græsrødderne". Det er det bare ikke. Det en pressechef fra en millionkoncern, der cosplayer som almindelig borger, altså en falsk græsrod, en såkaldt "astroturfer". 4/ Er det i overensstemmelse med Folkekirkens Nødhjælps etiske retningslinjer og kommunikationsretningslinjer, at pressechefen cosplayer som almindelig borger i arbejdstiden? 5/ Hvorfor skulle Baronessen af Nilen være anonym? Der er trods alt tale om et partsindlæg fra en millionkoncern som har en væsentlig interesse i at lukke munden på kritiske borgerjournalister som Baronen af Øresund. 6/ Har Folkekirkens Nødhjælp andre anonyme konti andre steder på nettet, der skal påvirke den offentlige mening på en måde, som Folkekirkens Nødhjælp vil have? #dkpol #dkpol #astroturfing #etiskkommunikation

2
20minutes Aug 14

Le 15 août, une nouvelle vague d'appels à traverser vers Ceuta, alimentée par des rumeurs sur les réseaux sociaux et des comptes suspects, semble être une opération d'astroturfing, une technique de manipulation visant à donner l'illusion d'un mouvement citoyen orchestré par un acteur anonyme, souvent au service d'intérêts commerciaux. #Astroturfing #Immigration #Ceuta

Crise à Ceuta : C’est quoi l’astroturfing, cette technique de manipulation qui a probablement été utilisée ?

📣 Την προσοχή σας παρακαλώ 🔥 Χθες στη Χαλκιδική έγινε χαμός. Και αυτή η μαρτυρία είναι κόλαφος. 🚨 Είναι η στιγμή που αυτοί οι 2 κάτοικοι φεύγουν πανικόβλητοι απ'το χωριό που καίγεται. Οι δρόμοι είναι «μπλοκαρισμένοι» και η αστυνομία ΠΟΥΘΕΝΑ. Ξανά: Παρότι έφυγαν απ'τους τελευταίους, δεν είδαν αστυνομία ΠΟΥΘΕΝΑ. 🛣️ Προσπαθούν μέσω του OPEN να ενημερώσουν ανθρώπους να πάνε από άλλο δρομολόγιο για να μην ακινητοποιηθούν τα οχήματά τους ενώ πλησιάζει μια πυρκαγιά. 📺 Δηλαδή 2 άνθρωποι προσπαθούν, μέσω τηλεόρασης, να κάνουν ότι δεν έκανε ο κρατικός μηχανισμός. 🏖️ Που γνώριζε ότι είναι μια περιοχή με πολλούς κατοίκους και τουρίστες αλλά δεν έλαβε τα αναγκαία μέτρα για να οργανώνει την κίνηση. Και να ενημερώνει διαρκώς στον δρόμο και στα αγγλικά. 📰 Την καταγγελία των κατοίκων επιβεβαίωσαν στη συνέχεια και δημοσιογράφοι. ✍️ Προσωπικά μετέφερα χθες την καταγγελία με πηγή, χωρίς να ανεβάσω το βίντεο, καθώς δεν είχε ακόμα ανέβει μαγνητοσκοπημένο. 🤥 Αμέσως μπήκαν ταυτόχρονα διαφορετικοί λογαριασμοί και άρχισαν να με βγάζουν ψεύτη, λέγοντας ότι και καλά ήταν πυρόπληκτοι και υποστηρίζοντας αόριστα ότι τους βοηθούσε η αστυνομία κτλ κτλ ✨ Σαν από θαύμα βρέθηκαν μέσα στην πυρκαγιά λογαριασμοί να βάλουν βασική τους προτεραιότητα να γράψουν στο twitter. 🔵 Και σαν από θαύμα οι ίδιοι λογαριασμοί είναι γεμάτοι με δημοσιεύσεις υπέρ του Κυριάκου Μητσοτάκη. 👥 Στη συνέχεια σαν από θαύμα πλάκωσαν και άλλοι λογαριασμοί που υποστηρίζουν Νέα Δημοκρατία και άρχισαν να αφισβητούν αυτό που λέω. 🎧 Αυτό το σοκαριστικό ηχητικό, καταρρίπτει κάθε «αυθόρμητη» αντίδραση αγανακτισμένων τουιτεράδων (κατοίκων ήθελα να πω). 📚 Η τεχνική αυτή έχει όνομα. Και τη συναντά κανείς στα εγχειρίδια προπαγάνδας. 🌱 Το πρώτο κομμάτι της λέγεται "astroturfing": οργανωμένες παρεμβάσεις που επιχειρούν να εμφανιστούν ως αυθόρμητες αντιδράσεις απλών πολιτών. ⚠️ Αλλά υπάρχει και ένα δεύτερο, ακόμη πιο σημαντικό επίπεδο. ☠️ Λέγεται "poisoning the well — δηλητηρίαση της πηγής". 📰 Δεν χρειάζεται να διαψεύσεις τις εκατοντάδες ειδήσεις που μεταδίδει ένας δημοσιογράφος κάθε χρόνο. 🎯 Αρκεί να πιαστείς από μία ή δύο περιπτώσεις, να μην απαντήσεις επί της ουσίας, αλλά να χτυπήσεις τον ίδιο τον δημοσιογράφο. 🔨 Να υπονομεύσεις την προσωπικότητά του, την επαγγελματική του υπόσταση και κυρίως την αξιοπιστία του. 🔮 Και αυτό γίνεται με το βλέμμα στραμμένο όχι μόνο στο σήμερα, αλλά κυρίως στο αύριο. 💬 Το μήνυμα είναι απλό: 🗣️ «Αν τον μειώσουμε σήμερα, στην επόμενη καταγγελία που θα δημοσιοποιήσει, λιγότεροι άνθρωποι θα τον πιστέψουν». ♟️ Δεν χρειάζεται, δηλαδή, να κερδίσεις κάθε μάχη πάνω στα γεγονότα. 💥 Προσπαθείς να καταστρέψεις εκ των προτέρων την αξιοπιστία του ανθρώπου που τα μεταφέρει. ☠️ Να δηλητηριάσεις την πηγή. 🧠 Ώστε την επόμενη φορά που θα φέρει στοιχεία, ένα κομμάτι του κόσμου να μη μπει καν στον κόπο να εξετάσει αν είναι αληθινά. 🚫 Να έχει ήδη αποφασίσει ότι «αυτός λέει ψέματα». 🎯 Αυτό είναι ένα προληπτικό χτύπημα αξιοπιστίας. 👤 Και φυσικά δεν είναι κάτι προσωπικό. 📢 Είναι τεχνική πολιτικής επικοινωνίας. 🏛️ Εδώ την κάνει ακόμη και ο εκπρόσωπος της κυβέρνησης. Δεν θα την κάνουν τα ανώνυμα τρολάκια; 🎯 Ο στόχος είναι πολύ συγκεκριμένος. 🎓 Την επόμενη φορά που θα αποδείξουμε ότι το «έρχεται η Σορβόννη στην Ελλάδα» ήταν ψέμα, να μας πιστέψουν λιγότεροι. 🚆 Την επόμενη φορά που θα φέρουμε στοιχεία ότι τα τρένα μας παραμένουν επικίνδυνα, να μας πιστέψουν λιγότεροι. 📣 Την επόμενη φορά που ένας κάτοικος, ένας εργαζόμενος ή ένας πολίτης θα καταγγείλει κάτι που ενοχλεί την εξουσία, μέσω ενός δημοσιογράφου, να υπάρχει ήδη μέσα στο κεφάλι ενός μέρους της κοινωνίας η αμφιβολία: 🤔 «Μήπως αυτός τα βγάζει από το μυαλό του;» 🎯 Αυτός είναι ο πραγματικός στόχος. ⚔️ Όχι να κερδίσουν μόνο τη σημερινή αντιπαράθεση. 🔇 Να αποδυναμώσουν την επόμενη αποκάλυψη. 🛑 Να εξουδετερώσουν, όσο μπορούν, όσους ασκούν έλεγχο στην εξουσία. 📱 Με αυτές τις σκέψεις στο μυαλό άνοιξα σήμερα το Twitter και είδα ότι, ενώ γράφω για το Βατερλώ στα ιδιωτικά πανεπιστήμια, συνεχίζουν να εμφανίζονται λογαριασμοί που υποστηρίζουν τη ΝΔ και να μου γράφουν σε άσχετα ποστ: 💬 «Για τη Χαλκιδική δεν λες τίποτα μετά το φιάσκο;» 📢 Να λοιπόν που λέω. 👉 Για την ακρίβεια, όχι εγώ. 👥 Οι κάτοικοι το λένε. 📰 Και οι δημοσιογράφοι το επιβεβαιώνουν. ☠️ Είναι πεισματάρικα πράματα τα γεγονότα. Όσο κι αν κάποιοι προσπαθούν να δηλητηριάσουν την πηγή που τα μεταφέρει. #φωτιες #πυρκαγιες #φωτιές #πυρκαγιές #Χαλκιδική

Digi24 Jul 2

Un raport al New Strategy Center evidențiază cum rețelele de boți și troli ale Kremlinului s-au activat pe rețelele sociale pentru a disemina mesaje de dezinformare și a submina încrederea românilor în autorități, după atacurile cu drone de la Galați și Constanța, folosind tehnici de astroturfing pentru a crea false impresii de consens public. #RăzboiCognitiv #Dezinformare #Troli

Cum s-au activat rețelele de boți și troli ale Kremlinului, după episoadele cu dronele de la Galați și Constanța (experți)

"So please understand. You are witnessing the biggest financial bubble in all of human history based on deceptive marketing, astroturfing, and cult dynamics. You are not witnessing the birth of a new intelligence." #FinancialBubble #DeceptiveMarketing #Astroturfing #Nocountrycodesarepresentinthetweet.