BETA nonprofit public democratic european moderated

Search

#InformationWar

Russia’s influence operation arrives ahead of the US midterms With weeks remaining before America's November midterm elections, a familiar type of content has begun appearing online. Videos resembling reports from CNN, the BBC and The New York Times accuse candidates of corruption, antisemitism and misconduct. Hollywood actors appear to denounce Democrats. Other clips claim that warnings about Russian interference are themselves a Democratic disinformation campaign. The reports are fabricated. Graphika, which tracks online influence operations, says it has identified a coordinated campaign targeting candidates in competitive US Senate races. It assesses with high confidence that the material was produced by Operation Overload, also known as Matryoshka – a long-running Russia-aligned influence operation previously active against elections and political debates in Europe and the United States. The activity coincides with a broader warning from American intelligence officials. Classified assessments reported by The New York Times conclude that the Kremlin has authorised another digital influence campaign ahead of the 2026 midterms, aimed primarily at exploiting existing divisions and undermining confidence in American democracy. There is an important distinction. US officials have not reported evidence that Russia is attempting to manipulate voting machines or alter the counting of votes. The operation is about influencing the information environment surrounding the election. Fake scandals for competitive Senate races Graphika traced a concentrated wave of activity between 10 and 14 September. Likely inauthentic or repurposed accounts distributed videos accusing Democratic politicians of corruption, antisemitism and other misconduct. The targets included Senator Jon Ossoff in Georgia, Representative Chris Pappas in New Hampshire and Texas state representative James Talarico, as well as Senate candidates Sherrod Brown in Ohio, Roy Cooper in North Carolina, Mary Peltola in Alaska, Abdul El-Sayed in Michigan, Joshua Turek in Iowa and Troy Jackson in Maine. The selection was not random. These were politicians involved in Senate contests where the result could matter to control of the chamber. The campaign did not rely on a single political narrative. Instead, it attached different accusations to different candidates – corruption, social issues, antisemitism or personal misconduct – while maintaining a consistent production and distribution model. That model is characteristic of Matryoshka: create apparently independent pieces of evidence, disguise them as journalism and distribute them through networks of disposable accounts. Hollywood celebrities who never said what the videos claimed One of the campaign's more distinctive techniques involved genuine footage of American actors. Videos featuring celebrities including Sarah Jessica Parker and Julia Roberts were altered with captions and other material to suggest they were promoting the slogan #AllDemocratsAreCriminals. The technique continued in subsequent material. Fact-checkers identified fabricated New York Times-branded videos using footage of Alyssa Milano, Sean Astin, Rachael Harris, Leonardo DiCaprio, Eric Braeden, Annie Potts and Patrick Fabian. Some of the original footage came from Cameo, where actors record personalised video messages. Their authentic images were retained while fabricated audio, captions or surrounding material changed the meaning entirely. Lead Stories compared several of the clips with the originals and found that the supposed political statements did not appear in the genuine recordings. Eric Braeden's representative separately confirmed that the claim he had joined the anti-Democratic campaign was false. The advantage of the technique is straightforward. Generative AI does not need to create a convincing celebrity from nothing. The operator can begin with authentic footage of a recognisable person and manipulate only the elements necessary to manufacture a political statement. Stealing the authority of real newsrooms Celebrity impersonation was only one layer. The operation repeatedly borrowed the visual identity of established media organisations. Graphika identified material impersonating or falsely citing the BBC, CNN and Politico, alongside references to France's VIGINUM foreign-interference agency and journalist Brandy Zadrozny. Other material reproduced New York Times-style branding. Some fabricated reports made an unusual claim: that Democrats themselves were organising disinformation or “false-flag operations” and then blaming Russia. This creates a defensive layer around the influence operation. Instead of merely distributing false political allegations, the campaign also attempts to discredit future reporting about the manipulation itself. If successful, evidence exposing foreign interference can be reframed as part of the conspiracy. Graphika says it assesses with high confidence that Operation Overload produced these videos. The technique is well established. Earlier investigations by CheckFirst and Reset Tech documented hundreds of falsified pieces of content produced by Operation Overload, often impersonating journalists, institutions and major media brands. AI-generated or manipulated material has increasingly become part of that production system. What US intelligence says Russia is trying to achieve The broader strategic picture comes from American intelligence assessments reported on 18 September. According to US officials familiar with classified findings, the Kremlin has authorised a covert digital influence campaign aimed at Americans during the 2026 election season. Its apparent objective is to seed or amplify domestic divisions and weaken confidence in the political process. Some officials described the principal aim as creating disorder rather than helping a single political party. The publicly identified Matryoshka material examined so far, however, has targeted Democratic candidates. Those two findings should not be treated as contradictory. An operation can exploit partisan divisions while serving the broader objective of making the electoral system appear corrupt, chaotic or illegitimate. US officials also reportedly assess the current Russian campaign as less extensive or coordinated than some previous election operations. Moscow is considered less focused on congressional elections than presidential contests and remains heavily occupied by its war against Ukraine. Russia has denied previous US accusations of election interference. An operation with limited reach – so far There is another reason for caution: producing large quantities of disinformation is not the same as successfully influencing voters. Matryoshka has repeatedly demonstrated an ability to manufacture content at industrial speed, but much of its material receives little genuine engagement. Researchers monitoring the network have previously warned against confusing automated distribution and platform view counts with authentic audience penetration. There are exceptions. A fabricated New York Times-style video featuring Jamie Lee Curtis had accumulated nearly 200,000 views on X by the end of 17 September, according to reporting by The New York Times. Other pieces attracted considerably less attention. There is currently no public evidence demonstrating that the campaign has changed voting intentions or will affect election results. What the September activity demonstrates is something narrower but important: a Russia-aligned influence infrastructure previously used against European elections has now turned significant attention towards the American midterms. The basic method has changed little – impersonate trusted media, manufacture scandals and use networks of inauthentic accounts to distribute them. What has changed is the production technology. Authentic celebrity footage, synthetic voices, manipulated video and rapidly generated fake journalism allow the same operation to produce more tailored material for more candidates at lower cost. The objective does not require Americans to believe every fabrication. Creating uncertainty over which videos, news reports and public statements are authentic can itself degrade trust in the information environment surrounding an election. Sources - Graphika — Russia-Aligned Influence Operation Targets US Midterm Candidates, German State Elections https://www.graphika.com/insights/russia-aligned-influence-operation-targets-us-midterm-candidates-german-state-elections - The New York Times — Russia Aims to Inject Chaos Into Elections, U.S. Intelligence Finds https://www.nytimes.com/2026/09/18/us/politics/russia-election-disinformation-us-intelligence.html - Kathimerini / The New York Times — Russia Aims to Inject Chaos Into Elections https://www.ekathimerini.com/nytimes/1315792/russia-aims-to-inject-chaos-into-elections-us-intelligence-finds/ - CheckFirst — Operation Overload: An AI-fuelled escalation of the Kremlin-linked propaganda effort https://checkfirst.network/operation-overload-an-ai-fuelled-escalation-of-the-kremlin-linked-propaganda-effort/ - CheckFirst — Operation Overload targeting the US election https://checkfirst.network/operation-overload-a-growing-disinformation-threat-now-targeting-the-u-s-presidential-election/ - Lead Stories — Fake NYT videos: Alyssa Milano, Rachael Harris and Sean Astin https://leadstories.com/hoax-alert/2026/09/fact-check-fake-new-york-times-videos-of-alyssa-milano-rachael-harris-sean-astin-falsely-claim-they-support-all-democrats-are-criminals.html - Lead Stories — Fake NYT videos: Leonardo DiCaprio, Eric Braeden and other celebrities https://leadstories.com/hoax-alert/2026/09/fact-check-fake-new-york-times-videos-of-leonardo-dicaprio-eric-braeden-other-celebs-falsely-claim-they-support-all-democrats-are-criminals.html - Brennan Center for Justice — AI Is Changing Foreign Election Influence https://www.brennancenter.org/our-work/analysis-opinion/ai-changing-foreign-election-influence - ODNI — previous US intelligence assessment of foreign election information operations https://www.dni.gov/files/ODNI/documents/assessments/NICM-Declassified-Foreign-Threats-to-US-Elections-After-Voting-Ends-in-2024.pdf - FBI / ODNI / CISA — previous joint assessment of Russian election influence operations https://www.fbi.gov/news/press-releases/joint-odni-fbi-and-cisa-statement-110424 #DISINFORMED #Episode9 #Russia #UnitedStates #USMidterms #Midterms2026 #USElections #ElectionInterference #ForeignInterference #RussianInfluence #RussianDisinformation #OperationOverload #Matryoshka #Disinformation #InformationWarfare #InfluenceOperations #FIMI #ArtificialIntelligence #AI #AIPropaganda #Deepfakes #SyntheticMedia #MediaImpersonation #FakeMedia #FakeNews #PoliticalDisinformation #CelebrityDeepfakes #SocialMediaManipulation #DigitalInfluence #ElectionSecurity #CognitiveWarfare #Graphika #OSINT #Democracy #WRLD

Russia-Aligned Influence Operation Targets US Midterm Candidates, German State Elections | Graphika

#InfoAlert! Another Russian provocation using information-psychological tools. The RIA Novosti agency, which participates in the information war against the West, published and then withdrew an article in which it threatens Lithuania with war. The text suggests that Russia is https://t.co/hsmVT1cq64 #Russia #InformationWar #Lithuania #RU #LT #US

UAE / Sudan – when an influence operation tried to enter the United Nations A network of roughly 300 apparently independent social-media influencers. A human-rights organisation borrowing the identity of a real NGO. Personal dossiers on European politicians and journalists. And testimony prepared for delivery at the United Nations without revealing the state interest behind it. These were elements of an influence operation uncovered by Anthropic and disclosed in September 2026. The company says it linked the activity with high confidence to UAE government officials. Tracked as GTG-84002, the operation targeted several overlapping issues: the Muslim Brotherhood, perceptions of the war in Sudan and international mechanisms examining the United Arab Emirates' role in the conflict. What distinguishes the case is not simply its use of artificial intelligence. It is the attempt to make state-aligned messaging appear to originate from independent influencers, human-rights organisations and potentially witnesses addressing an international institution. An influence network built around 300 fake voices Anthropic identified a single actor using Claude to support a sustained influence campaign. At its centre was an AI persona called “Deadshot”, running on the operator's own platform. A master doctrine file repeatedly instructed the system to support what it described as a coordinated international effort to dismantle the Muslim Brotherhood. The operator simultaneously managed several components of the campaign, including approximately 300 inauthentic influencer accounts across social-media platforms. Internal material examined by Anthropic described the apparent independence of this network as its greatest strategic advantage. That phrase captures the central method. The objective was not simply to broadcast a political position but to conceal where that position originated. One visible example appeared on 4 June 2026, when accounts participated in a coordinated campaign using #SudanIslamists and near-identical graphics connecting Sudanese Islamists and the Muslim Brotherhood with regional instability. Anthropic says the amplification network was centrally funded and coordinated. Its investigation also found that the operator financing the social-media network was connected to the wider influence operation. A human-rights organisation that was not what it appeared to be Social media was only one layer. The operator also created a front NGO that copied the identity of a genuine Swiss organisation and used that borrowed legitimacy to publish human-rights material produced for the campaign. Anthropic's description elsewhere also refers to the identity of a real Sudanese human-rights organisation being used in connection with the preparation of testimony. The public report does not fully clarify whether these references describe the same front or separate elements of the operation, so they should not be treated as definitively identical. The underlying technique, however, is clear: political material was designed to appear as if it originated from independent civil society rather than from actors linked to a government. This is particularly significant in the human-rights environment, where the perceived independence of an organisation or witness can determine how seriously evidence is received by journalists, diplomats and international institutions. The attempt to reach the UN The most consequential part of the operation concerned the 62nd session of the UN Human Rights Council. According to Anthropic, the operator used Claude to ghost-write complete testimony intended to be delivered by two individuals during the session. The texts were prepared under explicit constraints ensuring that neither statement would mention the UAE. This did not amount to a conventional government submission. The intention, according to Anthropic's reconstruction, was for material serving the interests of a party connected to the Sudan conflict to reach an international forum through apparently independent voices. But an important limitation remains: Anthropic could not confirm that the testimony was ultimately delivered. The company similarly could not establish whether other dossiers produced by the operation reached their intended recipients or influenced policy. It therefore assessed the campaign as Category Three on the Brookings Breakout Scale – activity distributed across several platforms, but without evidence of broad public impact sufficient for a higher classification. The distinction matters. The evidence demonstrates a sophisticated attempt to influence international debate; it does not demonstrate that the attempt succeeded. Politicians, journalists and UN investigators became targets The operation was not limited to generating public content. Anthropic found that the operator researched and compiled detailed profiles of 18 members of the European Parliament and prominent journalists. Some material was prepared for direct delivery to senior UAE officials. The network also assembled what Anthropic describes as “counter-accountability dossiers” on UN Special Rapporteurs who had criticised the UAE's conduct in relation to Sudan. This places the campaign in a broader context. Since Sudan's civil war began in April 2023, the role of external powers has become an increasingly important part of international scrutiny. Sudan has accused the UAE of supporting the Rapid Support Forces, allegations Abu Dhabi has repeatedly denied. In 2025, Sudan brought a case against the UAE before the International Court of Justice, accusing it of complicity in genocide against the Masalit through alleged support for the RSF. The UAE rejected the allegations. The ICJ subsequently removed the case from its list after finding that it lacked jurisdiction because of the UAE's reservation to the relevant provision of the Genocide Convention. The ruling therefore did not determine whether Sudan's substantive allegations were true or false. That contested international environment helps explain why narratives about Sudan, human rights and accountability were valuable targets for an influence operation. AI as an operating system for influence The role played by Claude is also important to understand accurately. Anthropic did not find that artificial intelligence independently conceived or directed the campaign. Human operators established the objectives, political doctrine and targets. AI instead helped operationalise them. Across hundreds of sessions, Claude was used to transform predetermined political objectives into social-media narratives, human-rights reports, testimony, intelligence-style briefs and detailed profiles of individuals. The same system could support narrative production, target research and preparation of material for different audiences. That represents a more significant development than simply using generative AI to produce propaganda faster. Traditional influence operations require different teams to research targets, write content, manage personas, adapt messages and prepare briefing material. Generative AI can compress several of those functions into a single operational workflow. The result is not necessarily more convincing propaganda. It is potentially cheaper, faster and more scalable influence infrastructure. From fake influencers to institutional influence Anthropic says it linked the operation to UAE government officials with high confidence. Its assessment was based partly on internal material naming senior Emirati officials as intended recipients of the work, alongside other evidence available to its investigators. That remains an attribution by Anthropic rather than a judicial finding or publicly released forensic attribution by a government agency. The distinction should be retained. The larger significance of GTG-84002 lies in the architecture of the campaign. A network of fake influencers could create the appearance of public opinion. A cloned human-rights organisation could provide institutional credibility. AI-generated reports could give political narratives the appearance of research. Profiles of journalists and politicians could support more precise targeting. And ghost-written testimony could potentially carry the same message into an international institution without revealing the political interest behind it. This is a different model from the familiar troll farm. The objective is no longer simply to make propaganda look popular. It is to make state-aligned messaging look independent – and, if possible, to move it from social media into the institutions where international policy and accountability are debated. SOURCES: Anthropic — Countering misuse of AI: September 2026 https://www.anthropic.com/threat-intelligence-report-september-2026 International Court of Justice — Sudan v. United Arab Emirates https://www.icj-cij.org/case/197 International Court of Justice — press releases and case documents https://www.icj-cij.org/case/197/press-releases United Nations Geneva — Sudan v UAE proceedings at the ICJ https://www.ungeneva.org/en/news-media/news/2025/04/105241/world-court-begins-hearing-sudans-complicity-genocide-case-against UAE Ministry of Foreign Affairs — UAE response to Sudan's allegations https://www.mofa.gov.ae/en/MediaHub/News/2025/4/10/10-4-2025-UAE-UAE UN Digital Library — Sudan's letter concerning alleged UAE support for the RSF https://digitallibrary.un.org/record/4091008?ln=en UN Digital Library — UAE response concerning allegations of support for the RSF https://digitallibrary.un.org/record/4046224?ln=en Ultra Sudan — reporting on Anthropic's UAE-linked influence-operation findings https://ultrasudan.usawtiq.com/أنثروبيك-أحبطنا-عملية-تأثير-إماراتية-استخدمت-الذكاء-الاصطناعي-لاستهداف-السودان/عامر-صالح/أخبار KEYWORDS #DISINFORMED #Episode8 #UAE #Sudan #UnitedArabEmirates #UnitedNations #UNHumanRightsCouncil #HumanRights #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #CoordinatedInauthenticBehaviour #CIB #FakeInfluencers #FakeNGO #NGOImpersonation #Astroturfing #ArtificialIntelligence #AI #AIPropaganda #AIGeneratedContent #SyntheticMedia #SocialMediaManipulation #DigitalInfluence #Propaganda #NarrativeManipulation #InstitutionalInfluence #SudanConflict #SudanWar #MuslimBrotherhood #InternationalRelations #Geopolitics #Anthropic #ClaudeAI #OSINT #WRLD

Countering misuse of AI: September 2026 / Anthropic

Russia’s fake African newsrooms – propaganda designed to look local A Facebook user in Nairobi, Accra, Johannesburg or Luanda encounters what appears to be a local news page. It publishes stories about African politics, Western influence and relations with Russia. The language is tailored to an African audience and the page presents itself not as a foreign broadcaster, but as part of the local information landscape. Behind some of these outlets, however, Meta found operators based in Russia. In its 2026 threat research, the company disclosed a Coordinated Inauthentic Behaviour network targeting audiences in Angola, Ghana, Kenya and South Africa. Meta removed 37 Facebook accounts and 29 Pages connected to the operation. Around 30,000 users followed at least one of the Pages, while the operators spent approximately $7,000 on Facebook and Instagram advertising, mostly in euros and US dollars. The numbers are relatively modest. The method is considerably more important. Rather than openly distributing Russian state messaging, the network posed as local African news sources and grassroots organisations, promoting narratives about Western colonialism and political interference while presenting Russia as a credible economic and political alternative. It was an old geopolitical message delivered through a much more effective identity: not Moscow speaking to Africa, but Africans apparently speaking to one another. A news outlet that was actually an influence operation Meta's investigation found that the network attempted to conceal its Russian origin while creating media brands that appeared indigenous to the countries they targeted. Its content amplified historical grievances against former colonial powers, criticised Western involvement in Africa and promoted closer relations with Russia. One example helps illustrate how the infrastructure was assembled. A Facebook Page targeting Kenya was called Kenya Watchtower. According to OpenAI's subsequent investigation, Facebook transparency records showed that the Page had previously been named “Farmtown5”. It appears to have been acquired or repurposed rather than built from scratch as a Kenyan news organisation. Some Pages also exposed administrator locations in Russia and Ukraine. Other elements of the network had previously targeted audiences in Zambia and Namibia. This use of apparently local identities is particularly important in the African information environment. A story published by RT or another identifiable Russian outlet arrives with an obvious geopolitical provenance. The same narrative presented by something resembling an independent Kenyan, Ghanaian or South African newsroom carries a different kind of credibility. The source appears closer to the reader, and the geopolitical interest behind the message becomes less visible. Then investigators found Dr Manuel Godsin The Facebook operation was only one part of a broader information ecosystem. OpenAI investigated related activity after receiving information from Meta and subsequently banned a ChatGPT account it assessed as likely originating in Russia. OpenAI called the campaign Operation No Bell. The account was being used to generate long-form articles and social-media posts about African geopolitics. Prompts were primarily written in English, but OpenAI also observed Russian-language instructions that the user described as coming from a manager. The operator sometimes explicitly asked the model to make the material appear less AI-generated – including requests to avoid stylistic features associated with machine-generated text and to write more like a human journalist. Many articles appeared under the name “Dr Manuel Godsin”, presented as an academic with a PhD from the University of Bergen and an affiliation with an organisation called the International Centre for Political and Strategic Studies. OpenAI could find no credible evidence that Godsin existed. Searches of Norway's National Research Information Repository and the University of Bergen library produced no record of him. Investigators subsequently discovered that a photograph used to represent Godsin had appeared years earlier on a Russian professional networking site and apparently belonged to a law student in St Petersburg. The fabricated academic identity was nevertheless remarkably productive. OpenAI identified 53 online articles carrying the Godsin byline. The fiction had moved beyond fake social-media pages and into the real media ecosystem. When propaganda enters genuine newsrooms This is the most consequential aspect of the operation. The articles were not confined to websites controlled by the influence network. Some were published by genuine African news organisations, including established South African outlets. The content mixed local political issues with broader geopolitical narratives. Some pieces criticised the United States and Britain or defended Russia's role in Africa. One accused the British NGO Crisis Action of fomenting protests in South Africa. Another praised Russia's presence in the Central African Republic. Other material addressed Kenya, Angola and relations between African governments and Washington. The mechanism represents a significant evolution from the classic troll-farm model. Instead of building an audience entirely on its own platforms, an influence operator can manufacture an apparently credible expert, generate articles in his name and persuade genuine news organisations to publish them. Once this happens, the propaganda acquires something a fake Facebook Page cannot provide: the institutional credibility of a real newsroom. OpenAI assessed No Bell's social-media impact as limited. One Facebook Page had around 3,000 followers before Meta removed it, while several others had very small audiences. But the operation was more successful in placing material in established media. In OpenAI's impact framework, it approached the level at which an influence operation breaks into mainstream media. For information operators, a single article published by a recognised outlet can potentially be more valuable than thousands of impressions generated by an obviously artificial account. A much larger network of ghost journalists Subsequent research suggests that Manuel Godsin was not an isolated experiment. In August 2026, Graphika, working with Code for Africa and with support from Meta, published a much broader investigation into Russian ghostwriting operations across African media. Researchers identified 44 ghost writers and fake experts, 38 of them assessed as high-confidence fabricated personas, operating between 2021 and 2026. Their material appeared or was quoted across 138 websites and was subsequently republished through at least 113 Facebook accounts and Pages, including authentic users, coordinated inauthentic networks and official Russian communication channels. The narratives were strikingly consistent. They included criticism of France, Ukraine and the United States; attacks on organisations such as ECOWAS and the International Criminal Court; positive portrayals of Russian involvement in Africa; praise for Russian paramilitary forces; and support for sovereignty-oriented political projects such as the Alliance of Sahel States. The operation therefore extends beyond creating fake news websites. It attempts to insert Russian-aligned narratives into the legitimate African media ecosystem using identities that appear African, independent or academically authoritative. This also explains why measuring reach through the original Facebook network alone is misleading. A fabricated article may begin with an influence operator, appear in a genuine African publication, be republished elsewhere and eventually circulate without any visible connection to Russia. At that point, the provenance of the narrative has effectively been laundered. An old Russian strategy with increasingly local faces Russia's use of local intermediaries in Africa is not new. Meta documented Russian networks using African nationals as early as 2019. In 2020 it dismantled another operation involving people in Ghana and Nigeria working on behalf of individuals in Russia, with links to previous activity associated with the Internet Research Agency. More recent Meta investigations suggest that this model has continued to evolve. Networks have increasingly relied on local freelancers, social-media managers and authentic media outlets rather than exclusively operating armies of obviously fake Russian-controlled accounts. This decentralisation offers several advantages. Local operators understand language, political sensitivities and cultural references. Authentic accounts are harder to identify than newly created synthetic personas. Local media brands can also deliver narratives without immediately triggering the scepticism associated with Russian state outlets. There is no evidence that every African journalist, freelancer or publication carrying such material knowingly participates in Russian influence activity. Meta explicitly notes in its investigations that some local contractors may not know who ultimately commissioned their work. That distinction is essential. The operation's effectiveness partly depends on precisely this ambiguity between deliberate participation, commercial content placement and unwitting amplification. The objective is to make Russian narratives look African The significance of this network is therefore not its 30,000 Facebook followers or its $7,000 advertising budget. Those figures are small compared with the audiences of major African media organisations. What matters is the distribution model. Traditional foreign propaganda asks an audience to trust a foreign source. These operations attempt to remove the foreign source from the equation altogether. A Russian geopolitical narrative can be generated with AI, attributed to an expert who does not exist, published by a media organisation that does, amplified through a Facebook Page presenting itself as local, and then rediscovered elsewhere as apparently independent African analysis. By the time the reader encounters it, Moscow may have disappeared completely from the chain of attribution. The resulting information operation is therefore less about making Russian propaganda more persuasive than about making it look as though it is no longer Russian propaganda at all. In an increasingly fragmented African media environment, that may be the more important evolution to watch. SOURCES: Meta Threat Research https://threatresearch-team.github.io/indicators/meta-h1-2026-russia-based-cib-network-1/ OpenAI — Operation “No Bell” https://openai.com/index/disrupting-malicious-uses-of-ai-no-bell/ Graphika — Umbrae Ex Machina https://www.graphika.com/reports/umbrae-ex-machina News24 https://www.news24.com/southafrica/news/ai-expert-exposed-fake-kremlin-linked-analyst-planted-stories-in-african-media-20260318-0560 Vanguard https://www.vanguardngr.com/2026/03/ai-expert-exposed-fake-kremlin-linked-analyst-planted-stories-in-african-media/ Meta — Russian Coordinated Inauthentic Behaviour, 2019 https://about.fb.com/news/2019/10/removing-more-coordinated-inauthentic-behavior-from-russia/ Meta — Russian Coordinated Inauthentic Behaviour, 2020 https://about.fb.com/news/2020/03/removing-coordinated-inauthentic-behavior-from-russia/ Meta Threat Research — Russian Use of Authentic Operators in Sub-Saharan Africa https://threatresearch-team.github.io/indicators/meta-h2-2025-russia-based-cib-network-2/ KEYWORDS: #DISINFORMED #Episode7 #Russia #Africa #RussianDisinformation #RussianInfluence #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #CoordinatedInauthenticBehaviour #CIB #FakeNews #FakeMedia #FakeNewsrooms #MediaImpersonation #GrassrootsManipulation #Astroturfing #ArtificialIntelligence #AI #AIPropaganda #SyntheticMedia #FakeInfluencers #SocialMediaManipulation #Facebook #Meta #OperationNoBell #AfricanMedia #MediaManipulation #Propaganda #DigitalInfluence #Angola #Ghana #Kenya #SouthAfrica #OSINT #WRLD

Russia-Based Influence Operation Network Targeting Sub-Saharan Africa

⚠️❗️Russian special services responsible for information warfare against the West are conducting a campaign aimed at intimidating audiences in France. To that end, they invoke Russian activity and presence in Africa. The Russian narrative suggests that French territory is within https://t.co/WxSy586T8J #Russia #InformationWarfare #France #FR #RU #AF

Storm-1516 – Russia’s information war arrives early in France’s 2027 election France will not elect its next president until April 2027, but the information operations surrounding the campaign have already begun. In late July and August 2026, fabricated stories targeted several prominent figures associated with the presidential race, including Raphaël Glucksmann, Gabriel Attal and former prime minister Édouard Philippe. The methods included fake news websites copying established French media, impersonated journalists, AI-generated voices and manipulated video. French authorities identified the Russian operation known as Storm-1516 behind several of these campaigns. Other attacks were linked to Matryoshka, another Russia-aligned influence network. The timing is significant. Storm-1516 began targeting the French presidential environment roughly nine months before the first round, scheduled for 18 April 2027. Rather than a single disinformation campaign, the activity demonstrates how Russian influence networks can establish narratives and infrastructure long before an election reaches its decisive phase. A fake scandal targeting Raphaël Glucksmann One of the clearest examples appeared at the end of July. A website impersonating the French independent outlet Blast published a fabricated investigation claiming that journalist Léa Salamé had attempted to bribe media organisations in exchange for favourable coverage of her partner, Raphaël Glucksmann. The operation went beyond copying the appearance of a legitimate news site. The identities of real journalists were appropriated and a manipulated video used an AI-generated imitation of the voice of Edwy Plenel, founder of Mediapart, supposedly confirming the allegations. The accusation was false. On 4 August, Glucksmann said France's General Secretariat for Defence and National Security, the SGDSN, had informed him that he had been targeted by Storm-1516. Two days later, the Paris prosecutor's office opened an investigation into suspected Russian interference. The importance of the operation was not the quality of one particular deepfake but the construction of several mutually reinforcing elements: a fake media organisation, impersonated journalists, synthetic audio and social-media accounts distributing the material. Together they created the impression that the allegation had been independently corroborated. Different candidates, overlapping Russian networks Édouard Philippe was also targeted by fabricated stories claiming that he suffered from dementia and was medically incapable of running for president. VIGINUM attributed the operation to Storm-1516. Gabriel Attal faced another wave of false content, including fabricated stories mimicking the identities of French outlets such as RFI, BFM TV, France 24, AFP, Le Parisien, Libération and Le Monde. Some claimed that Attal had symptoms of Parkinson's disease or links to drug trafficking. Attribution here is more complicated. French reporting connected at least part of the campaign against Attal to Matryoshka, rather than Storm-1516. A later digitally manipulated video, apparently associated with Storm-1516, used genuine LCI footage from an August debate but added a white earpiece to Attal, suggesting that someone had secretly been feeding him answers. NewsGuard compared the circulating clip with authentic LCI footage and found no earpiece in the original. The distinction is important. France is not facing a single Russian propaganda operation but several overlapping networks using similar techniques and narratives. Treating every manipulation as Storm-1516 would obscure how this ecosystem actually functions. The real weapon is media impersonation The most interesting feature of Storm-1516 is not artificial intelligence itself. It is the systematic appropriation of the credibility of established journalism. Instead of relying only on anonymous Telegram channels or social-media profiles, operators create material that looks as though it originated from organisations audiences already recognise. A fabricated investigation can resemble Blast, a manipulated television report can borrow LCI's visual identity, while fake journalists and social-media accounts provide additional layers of apparent confirmation. VIGINUM has documented this architecture extensively. Its 2025 investigation analysed 77 Storm-1516 information operations and described a mature Russian system using fabricated media, websites and distribution networks to promote anti-Ukrainian and anti-Western narratives. The European External Action Service found that the infrastructure continued to expand. According to its 2026 FIMI Threat Report, Storm-1516 almost doubled its output during 2025. Five networks created that year to target French, German, American, Moldovan and international audiences comprised 453 websites, including fictional news organisations and sites impersonating genuine media or political platforms. A typical operation therefore follows a recognisable pattern: a fabricated allegation is supported by synthetic or manipulated evidence, published through an apparently legitimate source and then distributed by networks of accounts that create the appearance of wider discussion. AI makes this process faster and cheaper, but the fundamental objective remains the same – to manufacture credibility. Why begin nine months before an election? VIGINUM concluded that Storm-1516 is capable both of reacting rapidly to current events and of conducting longer campaigns aimed at discrediting Western institutions and public figures, particularly around elections and other major political events. This provides important context for France. Storm-1516 activity around the presidential race became visible in July 2026, approximately nine months before voting begins. There is no public evidence of a predetermined Russian “nine-month plan”, and the timing should not be presented as such. Early activity nevertheless provides operational advantages: narratives can be tested, websites and accounts established, audience reactions measured and the responses of journalists, authorities and fact-checkers observed. The first operations may therefore also provide information about which themes and techniques are most effective before the campaign enters its decisive months. This remains an analytical interpretation rather than a demonstrated statement of the operators' intentions. Russian operation, but what about the GRU? Attribution requires similar precision. VIGINUM explicitly describes Storm-1516 as a Russian information operation, and French authorities have attributed individual campaigns to it with high confidence. Connections with Russian military intelligence have also been reported. Glucksmann said the SGDSN informed him that the network targeting him was controlled by Russia's GRU, while French media have repeatedly described Storm-1516 as linked to Russian military intelligence. However, VIGINUM's publicly available technical documentation describes Storm-1516 primarily as a Russian information modus operandi, rather than identifying it as a formally established GRU unit. It is therefore well supported to describe Storm-1516 as a Russian influence operation with reported links to military intelligence. Saying simply that Storm-1516 is a GRU unit would go beyond what France's published technical evidence currently establishes. An early warning for the French election There is also no evidence that the operations have so far had a significant effect on French voters. Some of the fabricated material generated only limited engagement, and measuring the real impact of foreign information operations remains extremely difficult. Even a video attracting hundreds of thousands of views does not establish how many viewers believed it or whether it changed political attitudes. The significance of Storm-1516 lies instead in the infrastructure already being deployed. Months before the election, Russian influence networks have been able to test fake newsrooms, synthetic voices, manipulated television footage, candidate-specific narratives and systems for distributing them. The French case illustrates a broader evolution in election interference. The objective is no longer simply to place false claims on social media. Modern operations can manufacture an entire chain of apparent evidence in which a fake journalist cites a fake investigation, synthetic audio appears to confirm it and networks of accounts give the impression that an authentic controversy is unfolding. France still has months to go before its presidential election. The information environment surrounding it is already being contested. Sources: VIGINUM / SGDSN — Storm-1516 analysis https://www.sgdsn.gouv.fr/publications/analyse-du-mode-operatoire-informationnel-russe-storm-1516 VIGINUM / SGDSN — Full Storm-1516 technical report https://www.sgdsn.gouv.fr/files/files/Publications/20250507_TLP-CLEAR_NP_SGDSN_VIGINUM_Technical%20report_Storm-1516.pdf VIGINUM / SGDSN — Storm-1516 operation targeting Emmanuel Macron https://www.sgdsn.gouv.fr/publications/storm-1516-detection-dune-operation-dingerence-numerique-etrangere-ciblant-emmanuel EEAS — 4th Report on FIMI Threats https://www.eeas.europa.eu/sites/default/files/2026/documents/EEAS%204th%20Threat%20Report_web.pdf Le Monde — Russian interference targeting Philippe, Glucksmann and Attal https://www.lemonde.fr/politique/article/2026/08/07/presidentielle-2027-glucksmann-attal-philippe-les-ingerences-russes-s-invitent-dans-la-campagne_6740451_823448.html Le Monde — Storm-1516 and Matryoshka analysis https://www.lemonde.fr/pixels/article/2026/08/06/ingerences-russes-pourquoi-il-ne-faut-pas-nourrir-le-troll_6739956_4408996.html NewsGuard Risk Briefing — Russian activity targeting the French election https://newsguardriskbriefing.substack.com/p/russia-targets-french-elections-iran Euronews — Operation targeting Raphaël Glucksmann https://fr.euronews.com/my-europe/2026/08/04/presidentielle-de-2027-raphael-glucksmann-vise-par-une-operation-de-destabilisation-russe Télérama / AFP — Glucksmann deepfake investigation https://www.telerama.fr/debats-reportages/presidentielle-2027-raphael-glucksmann-vise-par-un-deepfake-d-origine-russe-7032318.php Le Parisien — Operation targeting Gabriel Attal https://www.leparisien.fr/elections/presidentielle/presidentielle-2027-gabriel-attal-a-son-tour-vise-par-une-ingerence-en-provenance-de-russie-05-08-2026-I3Z67Z7ZUBDUVBXUNDARI5KGPA.php Euronews — Paris prosecutor investigations into suspected Russian interference https://fr.euronews.com/my-europe/2026/08/18/soupcons-dingerence-russe-visant-attal-et-philippe-le-parquet-de-paris-ouvre-dune-enquete Keywords: #DISINFORMED #Episode6 #Storm1516 #France #FrenchElection2027 #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #RussianInfluence #RussianDisinformation #Propaganda #Deepfakes #ArtificialIntelligence #AI #SyntheticMedia #FakeNews #MediaImpersonation #FakeMedia #DigitalManipulation #ElectionInterference #PoliticalDisinformation #Matryoshka #VIGINUM #OSINT #CyberInfluence #DigitalInfluence #MediaManipulation #EuropeanSecurity #Democracy #WRLD

Analyse du mode opératoire informationnel russe Storm-1516 | SGDSN

The Ghosts of Zaolzie – how a cyberattack tried to manufacture a conflict between Poland and Czechia At around 5pm on 16 August 2026, an alarming article appeared on the website of Radio PiK, a genuine Polish regional broadcaster. Its headline claimed that Poland was preparing to seize Czech territory and that the Czech Foreign Ministry had received a document outlining Warsaw's demands. Radio PiK had published no such story. An attacker had compromised an employee's credentials, gained access to the station's content management system and replaced a legitimate article with fabricated material. The newsroom quickly removed it and informed the authorities. But the intrusion was only one element of a much larger operation. Investigators subsequently uncovered forged diplomatic documents, accounts impersonating Polish and Czech officials, a cloned Czech news site, AI-generated material, a fictitious local activist and advertising for a demonstration that apparently did not exist. Together, these elements attempted to manufacture the appearance of a new territorial conflict between Poland and Czechia over Zaolzie. A false crisis built around a real territorial issue The operation worked because it did not start entirely with fiction. Poland and Czechia do have an unresolved technical issue concerning approximately 368.44 hectares of territory, originating in post-war changes to the Polish-Czechoslovak border. It is commonly described as the Czech “territorial debt” to Poland. But this is not a Polish claim to Zaolzie and there is no evidence that Warsaw is seeking to annex Czech territory. The operation fused this real issue with a much more powerful historical memory. Zaolzie – the part of Cieszyn Silesia west of the Olza River – was disputed by Poland and Czechoslovakia after the First World War. In 1938, during the crisis created by the Munich Agreement, Poland seized the territory from Czechoslovakia. The manipulation therefore followed a simple logic: a real territorial debt became an alleged Polish territorial demand, which was then transformed into a supposed attempt to reclaim Zaolzie. Fake accounts impersonating Poland's Deputy Foreign Minister Artur Harazim and Czech ambassador Břetislav Dančák helped reinforce the story. Fabricated diplomatic documents circulated alongside them. One early version referred incorrectly to 638.44 hectares; the fake Harazim account then “corrected” the number to the genuine figure of 368.44 hectares. It was an effective form of reverse fact-checking: correcting one false detail could make the larger fabrication appear authentic. Fake media – and one real newsroom The operators also created a website designed to resemble Czech public broadcaster iRozhlas. It published material supporting the same narrative, including claims that Czech residents near the border were becoming concerned about Polish intentions. The result was a manufactured information loop. Forged documents could support fake media reports; impersonated officials could comment on those reports; social-media accounts could then cite both as confirmation. But the Radio PiK hack added something much more valuable: the credibility of a real media organisation. Instead of merely cloning a newsroom, the attackers briefly inserted their fabrication into an authentic one. A familiar domain, logo and established broadcaster could therefore appear to confirm a story manufactured elsewhere. The cyberattack was not simply an accompanying technical incident. It was part of the information operation itself – a way of manufacturing credibility for false information. From a synthetic activist to a real demonstration The operation then attempted to move from the digital world into the physical one. A Facebook account under the name “Adam Sikora” promoted a demonstration in the Czech border city of Třinec under slogans including “Cieszyn Silesia is Czech” and “Here we live, here we stay”. Paid Facebook advertising was reportedly used to promote the event. Yet Třinec authorities said no demonstration had been properly notified. Promotional material used the logo of the Czech KOVO trade union, which denied any involvement. Investigators also identified indications that Sikora's profile photograph and other imagery were AI-generated. The persona even advertised a supposed house for sale in the border region, reinforcing the impression that frightened residents wanted to leave because of Polish territorial ambitions. The property could not be verified and its images also showed signs of artificial generation. This reveals the architecture of the operation: forged document → fake official → cloned media → compromised real media → synthetic local activist → advertised protest → appearance of social tension. The final stage is particularly significant. Had real people attended the demonstration, photographs of an authentic crowd could potentially have been presented as evidence that Czech citizens genuinely feared Polish territorial ambitions. A fabricated online conflict could therefore have begun generating real-world evidence of its own existence. Why Zaolzie? Historical grievances are valuable material for influence operations because the underlying facts are real. Poland and Czechoslovakia genuinely disputed Cieszyn Silesia. Poland genuinely occupied Zaolzie in 1938. A Polish minority genuinely lives in Czechia. And the 368.44-hectare territorial issue genuinely exists. The operator did not need to invent that history. It only needed to suggest that the history was repeating itself. PISM assessed that the operation sought to revive the image of Poland as a revisionist state willing to challenge European borders. Such a narrative could serve a broader purpose: damaging Polish-Czech relations, weakening confidence between NATO and EU allies and portraying Central Europe as a region where historical territorial conflicts remain unresolved. Russia is the leading attribution – but not a proven one The attribution requires more caution than the mechanics of the operation. PISM assessed Russia as the most likely perpetrator, while NASK identified similarities between the campaign and previously observed Russian influence methods. Russian-linked information infrastructure had also shown earlier interest in the Polish-Czech territorial issue. The techniques are familiar: cloned media, forged documents, impersonated officials, synthetic identities, historical grievances and the combination of cyber intrusion with information manipulation. But these indicators are not the same as definitive attribution. As of mid-September 2026, no publicly disclosed forensic evidence had conclusively connected the Radio PiK compromise, fake domains, accounts and financing to a specific Russian intelligence service, government organisation or contractor. Russia can therefore reasonably be described as the leading analytical attribution, but claims that the operation was definitively conducted by the GRU or another named Russian structure go beyond the publicly available evidence. The operation failed. The model remains important The campaign did not create a Polish-Czech diplomatic crisis. Both governments rejected the narrative, the fictitious protest was exposed, journalists reconstructed much of the operation and Radio PiK detected the intrusion quickly. Its observable impact appears to have been limited. But Zaolzie illustrates a broader evolution in information warfare. Modern operations do not have to rely on a single viral fake. They can construct an entire artificial information environment in which different elements appear to confirm one another. A forged document creates the claim. A fake diplomat authenticates it. A cloned newsroom reports it. A hacked real newsroom lends it credibility. An AI-generated citizen reacts to it. Advertising creates the appearance of a grassroots movement. And if real people eventually respond, fiction begins producing genuine events. The objective is no longer simply to persuade people that something happened. It is to create the conditions in which something real starts happening because enough people believed that it did. Sources: Polish Institute of International Affairs (PISM) https://pism.pl/publikacje/dezinformacja-o-relacjach-polsko-czeskich Euronews Polska — Radio PiK cyberattack https://pl.euronews.com/2026/08/20/polska-planuje-zajecie-terytorium-czech-wlamali-sie-na-strone-radia-i-opublikowali-falszyw Demagog https://demagog.org.pl/na-biezaco/skoordynowana-operacja-uderza-w-polsko-czeskie-relacje-czy-stoi-za-nia-rosja/ Robert Lansing Institute https://lansinginstitute.org/2026/08/27/zaolzie-as-an-instrument-of-influence-an-attempt-to-revive-a-polish-czech-territorial-conflict/ Institute for European Security Studies (IESS) https://www.iess.org.ua/analytics/ghosts-of-zaolzie iDNES.cz https://www.idnes.cz/ostrava/zpravy/tesinsko-kampan-lzi-demonstrace-trinec-primatorka-palkovska.A260826_963356_ostrava-zpravy_jog Radio Zachód / PAP https://zachod.pl/1539751/niedzielny-atak-hakerski-na-radio-pik-redaktor-naczelny-podjelismy-niezwloczne-dzialania/ Euronews — territorial debt / NASK assessment https://de.euronews.com/my-europe/2026/08/21/polen-plant-besetzung-tschechischen-gebiets-fake-news TVP World https://tvpworld.com/95036191/-warsaw-warns-against-division-amid-czech-border-disinformation Keywords: #DISINFORMED #Episode5 #GhostsOfZaolzie #Zaolzie #Poland #Czechia #CieszynSilesia #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #Cyberattack #CyberSecurity #HybridWarfare #FakeNews #MediaImpersonation #FakeMedia #ForgedDocuments #DigitalImpersonation #ArtificialIntelligence #AI #Deepfakes #SyntheticMedia #Astroturfing #RussianInfluence #Propaganda #OSINT #NATO #CentralEurope #MediaManipulation #WRLD

Mali – a war where some of the people fighting do not exist In Mali's war, an apparently simple question is becoming increasingly difficult to answer: who exactly is speaking to us? A real person? A rebel organisation? A Russian influence operation? A supporter of the military junta? Or somebody who has never existed at all? In September 2026, the Dakar-based Timbuktu Institute published Des algorithmes en guerre, a report examining the use of generative artificial intelligence by actors involved in the Malian conflict. Its researchers describe the country as a potential laboratory for AI-assisted information warfare. Separatist networks are deploying synthetic fighters on TikTok. Jihadist propagandists are experimenting with AI-generated imagery. Pro-government accounts are producing large quantities of content celebrating the Malian armed forces. Russia, meanwhile, operates the most developed influence infrastructure of all: pseudo-media outlets, inauthentic accounts, AI-generated text, images and video, and systems designed to artificially amplify their visibility. Artificial intelligence did not create Mali's conflict. The war has been under way since 2012, and its participants have always fought with propaganda as well as weapons. What AI has changed is the economics of that struggle. A new “witness”, commentator, fighter, poster or video can now be produced in minutes. For audiences watching from a phone, distinguishing between genuine documentation, propaganda and material created entirely by an algorithm is becoming progressively harder. Azzghim – the fighter who cannot be killed or interrogated The most striking case documented by the Timbuktu Institute involves accounts associated with supporters of the Azawad Liberation Front, or FLA, a Tuareg separatist movement fighting the authorities in Bamako. A figure called “Azzghim” appeared on TikTok. He looks like a Tuareg fighter and regularly features in videos attacking Mali's government and Russia's Africa Corps, commenting on the conflict and promoting the cause of Azawad. There is one problem: Azzghim does not exist. Analysis of the videos identified anomalies characteristic of generative AI, including unnatural body movements, visual inconsistencies, irregular colouring and problems with audio synchronisation. According to the Timbuktu Institute, Azzghim is a synthetic character being used as the digital face of a political narrative. The propaganda advantages are considerable. An organisation no longer needs to expose a real spokesman. A synthetic personality can be designed to look exactly as its creators require, speak the appropriate language and appeal to a particular audience. Different characters could potentially be created for younger viewers, traditional communities or different ethnic and social groups. There is another advantage: a synthetic spokesman cannot be arrested, identified or interrogated. Researchers also identified accounts amplifying the material. At the time of the study, TikTok account @tawri.n.azawad had around 207,000 followers and was almost entirely devoted to publishing or repackaging content involving Azzghim. Another account, @asnan831, used a similar synthetic teenage character. An important distinction is necessary. Researchers describe these profiles as belonging to supporters or individuals associated with the FLA. The available evidence does not establish that every account is part of an operation centrally directed by the Front's leadership. The information effect, however, remains significant: a digital community can be constructed around the Azawad cause in which some of the apparent participants may not be real people at all. The jihadists are learning too The picture is different for Jama'at Nusrat al-Islam wal-Muslimin, or JNIM, the al-Qaeda-affiliated coalition that has become one of the most powerful armed groups in the Sahel. Its confirmed use of generative AI remains considerably less sophisticated. In June 2026, JNIM's Az-Zallaqa media apparatus published AI-generated posters promoting material about previous attacks. The images showed fighters in combat but contained familiar generative artefacts: buildings and vegetation merging unnaturally, blurred details and unnaturally smooth surfaces. More important than JNIM's current capabilities is what AI could add to an already sophisticated propaganda apparatus. The organisation already tailors communications to different audiences. UN reporting has documented its use of media channels for broader propaganda while other outlets increasingly distribute material in local languages, including Bambara. Generative AI could dramatically reduce the cost of this strategy, translating material into Fulfulde, Hausa, Zarma or Tamasheq, generating synthetic dubbing and producing multiple versions of the same message. The Timbuktu Institute also considers the future possibility of AI chatbots being used to personalise recruitment. That should not be presented as a capability JNIM has already demonstrated. At present, it is a risk scenario rather than a confirmed operation. Russia has the most sophisticated machine At the other end of the spectrum lies Russia's influence ecosystem. Here, AI is not an isolated experiment but another component of an infrastructure previously developed by Wagner-linked networks, Russian media operations and influence organisations operating across Africa. After Wagner's withdrawal from Mali in 2025, its military role was taken over by the Russian state-controlled Africa Corps. The information infrastructure evolved alongside it. Of particular importance is African Initiative, which presents itself as a news agency but has been identified by France's VIGINUM, the UK's Foreign, Commonwealth & Development Office and the European External Action Service as an important component of Russia's newer influence architecture in Africa. One of the most interesting elements of this ecosystem is a network researchers call AI-Freak. The operation uses generative AI to produce text, images and videos, places them on fake or apparently independent news websites and distributes them through inauthentic accounts. This is supplemented by so-called Black Hat SEO – techniques intended to artificially increase the visibility of content in search engines. Elements of this infrastructure have previously been identified by Meta and OpenAI. In 2024, OpenAI disrupted Russian accounts using ChatGPT to generate articles and comments in English, French and Russian. Some of the French-language content targeted audiences in West Africa. In a later iteration of the operation, AI models were also used to draft scripts for short videos praising the Russian Africa Corps, translate them into French and generate descriptions optimised for social media. This illustrates an important difference between the Russian approach and Azzghim. The separatist ecosystem uses AI primarily to manufacture convincing digital personalities. The Russian model increasingly resembles an industrial production line: text, image, video, pseudo-news website, distribution account, search optimisation and additional channels amplifying the narrative. The objective is not merely to convince someone of a single claim. It is to occupy as much of the information environment as possible with narratives advantageous to Moscow: Russia as an effective security partner, the West as a neo-colonial aggressor, France as a source of instability and Russian forces as defenders of African sovereignty. Yet VIGINUM also warns against equating technological sophistication with actual impact. Some Russian influence channels still attract relatively small audiences. A sophisticated operation is not automatically a successful one. The junta is building its own digital reality Mali's military authorities operate within the same contested information environment. Since breaking with France and moving closer to Moscow, Bamako has increasingly restricted independent media space while promoting a narrative built around restored sovereignty, military success and the benefits of its Russian partnership. The Timbuktu Institute highlights the TikTok account @6tm_officiel. At the time of the study, it had more than 436,000 followers and published substantial amounts of AI-generated material presenting Mali's armed forces, the FAMa, and the Africa Corps in a favourable light. One video concerning the battle for Kidal accumulated around 4.7 million views. Again, attribution requires care. Researchers describe the account as being operated by an individual based in Bamako; they do not provide evidence that it is officially managed by the Malian government. It is better understood as part of a wider pro-government information ecosystem in which the boundaries between state communications, supporters and co-ordinated propaganda can be difficult to establish. The Africa Center for Strategic Studies has previously identified the military regimes in Mali and Burkina Faso as important sources of disinformation campaigns in West Africa. Recurring narratives target France, the United Nations, ECOWAS, human-rights organisations and independent media, while presenting criticism of the authorities as part of a foreign conspiracy. Generative AI allows such narratives to be produced faster, more cheaply and in far more variations. Everyone is fighting over a different version of the same war What makes Mali particularly revealing is that multiple actors are using similar technology for very different objectives. FLA-linked networks need digital faces capable of humanising the Azawad cause and attacking Russia's presence. JNIM needs propaganda material and increasingly localised communications. The pro-government ecosystem seeks to portray Mali's armed forces as victorious and reinforce the junta's legitimacy. Russia possesses the broadest infrastructure, in which AI is merely one component of a larger system involving media outlets, websites, local partners, social-media profiles and technical amplification. The result is a war taking place simultaneously in two realities. In the first, soldiers and civilians are killed, towns change hands and the army, separatists and jihadists fight for territory. In the second, every side is trying to determine what the first reality will look like on a smartphone screen. Generative AI does not need to create a perfect deepfake to be effective. It merely needs to increase the number of competing versions of events until an ordinary viewer can no longer easily determine which one deserves to be trusted. That is why Mali matters. It is not showing us the future of information warfare. It is showing us its present. One TikTok video may feature a real soldier. Another may feature a propagandist. A third may feature a fighter who has never existed. And all three can tell completely different stories about the same war. Sources Timbuktu Institute – Des algorithmes en guerre: Comment l'IA générative rebat les cartes du conflit malien https://timbuktu-institute.org/index.php/toutes-l-actualites/item/1731-rapport-des-algorithmes-en-guerre-comment-l-ia-generative-rebat-les-cartes-du-conflit-malien AfricaNews/AFP – “Mali's information war is increasingly being shaped by AI” https://www.africanews.com/2026/09/09/malis-information-war-is-increasingly-being-shaped-by-ai/ OpenAI – research on Russia-origin influence activity and Operation Stop News https://openai.com/index/disrupting-malicious-uses-of-ai-stop-news-2024/ VIGINUM / FCDO / EEAS – technical report on African Initiative and the AI-Freak network https://www.sgdsn.gouv.fr/files/files/Publications/20250612_TLP-CLEAR_VIGINUM_FCDO_EEAS_Technical_Report_African_Initiative_EN.pdf Africa Center for Strategic Studies – Mapping a Surge of Disinformation in Africa https://africacenter.org/spotlight/mapping-a-surge-of-disinformation-in-africa/ Timbuktu Institute – analysis of AI use by JNIM https://timbuktu-institute.org/index.php/toutes-l-actualites/item/1735-artificial-intelligence-a-new-propaganda-lever-for-jnim-in-mali?print=1&tmpl=component #Disinformation #Mali #Sahel #Africa #ArtificialIntelligence #AI #GenerativeAI #AIPropaganda #InformationWarfare #InfluenceOperations #Propaganda #Deepfakes #SyntheticMedia #Azawad #FLA #JNIM #AfricaCorps #Russia #RussianInfluence #TikTok #DigitalWarfare #MediaManipulation #WRLD

Rapport - DES ALGORITHMES EN GUERRE : Comment l'IA générative rebat les cartes du conflit malien

Hanover Institute – propaganda designed for artificial intelligence For decades, influence operations had one primary target: people. Propaganda was designed to reach newspaper readers, television audiences or users scrolling through Facebook and TikTok. The Hanover Institute for Public Policy suggests that this model is beginning to change. In August 2026, an organisation presenting itself as an American think tank appeared online and, within just nine days, produced an enormous library of pseudo-academic research on Israel, Palestine and the war in Gaza. Yet the intended audience may not have been people at all. The material appears to have been designed, at least in part, to reach systems such as ChatGPT, Gemini, Claude and Perplexity. The Hanover Institute looked professional. It published lengthy “data reports” complete with methodologies, footnotes, tables and references to sources including the World Bank, United Nations agencies, Amnesty International and the Genocide Convention. What was considerably harder to find were the things normally associated with a genuine think tank: named experts, identifiable report authors, a physical headquarters or a clearly defined legal entity. There was, however, a much more revealing trail. Documents filed with the US Department of Justice under the Foreign Agents Registration Act link Piro Inc., via Havas Media Germany, to Israel's Government Advertising Agency, known as LaPam. Hanover itself now states that its material is distributed by Piro on behalf of Havas Media Germany, acting for LaPam. 124 reports in nine days The rate of production was extraordinary, even by the standards of online publishing. Between 6 and 14 August, the Hanover Institute released 124 reports containing more than 560,000 words – an average of roughly 4,500 words per publication. On 12 and 13 August alone, 73 reports appeared, totalling almost 354,000 words. More revealing than the volume was the way the material was structured. Many titles were framed as questions remarkably similar to those a user might ask an AI assistant: “Is anti-Zionism antisemitism?”, “Did Israel expel Palestinians from their land?”, “Is Israel committing genocide in Gaza?”, “Is there a starvation policy in Gaza?” or “Is the IDF the world's most moral army?” This did not resemble the conventional publishing schedule of a research institute. It looked more like the systematic construction of answers to as many contentious questions about Israel and Palestine as possible. The presentation mattered too. These were not crude propaganda leaflets. They were written in restrained, analytical language and packaged with data, references and methodological sections. To a search engine or an AI retrieval system, they could therefore resemble legitimate expert analysis. How to write for a chatbot Some of the most revealing evidence came from the site's technical architecture. Hanover maintained an llms.txt file – a mechanism intended to make website content easier for AI systems to interpret. Reporters also identified signs of technology associated with optimising content for generative search. Piro's own marketing is equally significant. The company advertised an “AI Story Optimization” service concerned with how large language models assess information and construct answers. Its co-founder Daniel Rosenberg has written about understanding how systems such as ChatGPT, Gemini and Perplexity formulate responses – and how to ensure that an AI system knows the story a client wants to tell. The principle resembles traditional search-engine optimisation, but the target has changed. SEO tries to make a webpage rank highly in Google. Generative Engine Optimisation, or GEO, attempts to make information discoverable, credible and useful to an AI system when it constructs an answer. The chain is potentially straightforward. A user asks a chatbot a question about Israel or Gaza. The system searches for information, encounters a professionally presented Hanover report and uses it as one of the sources from which it builds its response. Propaganda no longer has to reach the user directly. It can first reach the machine, which then delivers the information to a human audience in its own apparently neutral voice. Did it actually work? This is where an important qualification is necessary. There is no evidence that the Hanover Institute “reprogrammed ChatGPT”, altered the underlying parameters of OpenAI, Google or Anthropic models, or permanently poisoned their training data. Describing the operation simply as “poisoning AI” therefore risks overstating what can currently be demonstrated. There is, however, evidence of something more specific. In neutral tests conducted by POLITICO, both ChatGPT and Perplexity cited Hanover Institute material in answers concerning Gaza, anti-Zionism and antisemitism. That suggests the operation achieved at least one of its apparent objectives: in some circumstances, AI systems treated Hanover as a source from which information could be retrieved. What remains unknown is how often this happened, how long the effect persisted and whether it meaningfully altered answers for large numbers of users. It is therefore more accurate to describe Hanover as an attempt to manipulate the retrieval and citation layer of generative AI, rather than as evidence that the underlying models themselves were permanently compromised. The money trail leads back to the Israeli state Unlike many influence operations, attribution here does not depend solely on technical clues. There is a documented financial trail. Piro Inc. registered its US activities under FARA registration number 7732. Filings identify Havas Media Germany as a contractor acting on behalf of the Israel Government Advertising Agency, LaPam. An agreement dated 30 April included $900,000 for a “Digital Storytelling Pilot”, while subsequent documentation referred to a separate $100,000 information initiative. Precision matters. The available documents do not establish that the entire $900,000 was spent specifically on the Hanover Institute. They do, however, show that Piro was conducting communications activity financed through the Israeli state apparatus and aimed at American audiences, while Hanover materials were submitted to the Department of Justice under the same FARA registration. Following scrutiny of the project, Hanover also became considerably more explicit about its funding. Its website now identifies Piro, Havas Media Germany and LaPam. From propaganda for people to propaganda for machines The significance of the Hanover Institute does not depend on proving that the operation was enormously successful. Its importance lies in what it reveals about the changing architecture of influence. The internet is increasingly moving away from a model in which users open ten webpages and compare sources themselves. Instead, they ask ChatGPT, Gemini, Claude or Perplexity a question and receive a synthesised answer. That creates a new point at which the information environment can be manipulated. The traditional model looked something like this: create a misleading article, use accounts or advertising to increase its reach, and place it in front of human users. Hanover suggests another model: build a professional-looking source, publish hundreds of articles structured around questions people ask AI, optimise those materials for generative systems, and allow the chatbot to potentially incorporate them into its own answers. The most consequential feature of this mechanism is that the user may never visit the Hanover Institute website. They may never even know that the organisation exists. Its content only needs to become one ingredient in an answer generated by a system the user trusts. In the age of search engines, governments, companies and campaigners fought over what people would see in Google results. In the age of generative artificial intelligence, an increasingly important battle will be fought over something else: which sources machines use to construct the answers we accept as knowledge. Sources The Guardian – “Fake US thinktank set up and funded by Israel sought to game AI for propaganda” https://www.theguardian.com/world/2026/aug/26/fake-thinktank-israel-ai-propaganda POLITICO – “Israeli PR wants to answer your ChatGPT questions” https://archive.ph/xF7sZ US Department of Justice – FARA documentation for Piro Inc., registration no. 7732 https://efile.fara.gov/docs/7732-Exhibit-AB-20260602-0.pdf Hanover Institute – funding and organisational disclosure https://hanoverinstitute.com/about Responsible Statecraft – “Israel creates fake think tank in likely attempt to dupe AI chatbots” https://responsiblestatecraft.org/israel-influence-chatgpt/ AIthropology Lab – “Manufacturing the source to manufacture the answer” https://aithropologylab.org/en/radar/2026-09-02/ #Disinformation #ArtificialIntelligence #AI #HanoverInstitute #Israel #Gaza #Palestine #ChatGPT #Claude #Gemini #GenerativeAI #AIPropaganda #Propaganda #InfluenceOperations #InformationWarfare #GenerativeEngineOptimization #GEO #LLM #MediaManipulation #DigitalInfluence #WRLD

Fake US thinktank set up and funded by Israel sought to game AI for propaganda

The US is repeating a common Israeli mistake: vacating the information domain and allowing its enemy to dominate it. That usually turns out to be very costly. #InformationWarfare #USIsraelRelations #CyberStrategy #US #IL

Mika Aaltola Jun 10

SORM. Sovereign internet. Deep packet inspection. Russia controls every byte that moves on the Runet. So when Rossiya-1 wheels out Snowden to claim Western tech spies for the US, to a degree true, that is not journalism. It is an FSB information operation. The whistleblower #SORM #Runet #InformationWar #RU

Nico Lange May 26

Russland betreibt gerade viel Aufwand, um im Informationsraum in die Initiative zu kommen, weil es an der Front nicht läuft und weil die Schläge der Ukraine auf Ziele tief in Russland Wirkung haben. Die Ukraine hat Momentum, das wir aktiv unterstützen sollten. #Russland #Ukraine #InformationWar

Russian video games are being used as propaganda tools to promote a distorted narrative of the Ukraine war, exemplified by the recently released game "Ukrainian Warfare: Gostomel Heroes," which inaccurately portrays the Battle of Hostomel and aims to reshape perceptions of Russian soldiers and their actions during the invasion. #VideoGames #Propaganda #InformationWarfare

Guerra na Ucrânia: Rússia utiliza jogos de vídeo para fazer propaganda