BETA nonprofit public democratic european moderated

Search

#SyntheticMedia

Russia’s war propaganda gets a soundtrack – how AI-generated songs reached global streaming platforms Russian war propaganda is no longer confined to television broadcasts, Telegram channels or political videos. A study by the Ukrainian threat-intelligence organisation Terrecon has identified 981 songs combining signs of AI generation with pro-Russian military narratives, distributed through an ecosystem that reaches YouTube, Spotify, Apple Music, Deezer and SoundCloud. The songs range from sentimental ballads to rock and heavy metal. Their recurring themes are familiar from conventional Russian wartime propaganda: the heroisation of Russian soldiers, romanticisation of the war, mobilisation, the “Russian world”, commemoration of fallen troops and attacks on Ukraine and its armed forces. Some contain derogatory or dehumanising references to Ukrainians. What is new is not necessarily the message, but the production and distribution model: generative AI allows propagandistic music to be produced rapidly, cheaply and in quantities that would previously have required musicians, studios and producers. Nearly 1,000 tracks identified Terrecon examined 3,725 tracks collected from YouTube, YouTube Music, SoundCloud and the AI music platform Suno. After manual review, researchers classified 981 as showing both indications of AI generation and pro-Russian war propaganda. In 681 tracks they identified 728 propaganda-related keywords or phrases. The largest category was the glorification of the Russian military, followed by romanticised treatment of Moscow’s so-called “special military operation”, mobilisation appeals, narratives about the “Russian world”, and the cult of fallen soldiers and the state. The reach was not merely theoretical. Listening or viewing statistics were available for 608 of the identified tracks; together they had accumulated 86.8 million plays and views, according to Terrecon. A smaller group of 13 high-performing songs accounted for more than 53 million YouTube views and more than 67 million when YouTube Music was included. Among the better-known examples is “Power of Artillery”, a Russian-language rock song praising artillery weapons that passed two million views on YouTube. Most of the tracks for which publication dates could be established appeared after 2024, broadly coinciding with the rapid expansion of consumer AI music generators such as Suno and Udio. That correlation does not prove that AI alone caused the increase, but it illustrates how drastically the economics of production have changed. A propaganda song for as little as $11 Terrecon also tested how difficult it would be to commission such material. Researchers approached 25 creators producing AI-assisted militaristic music; 15 agreed to take commissions. Prices ranged from approximately $11 to $330, while delivery times ranged from two hours to three days. According to Terrecon, some were prepared to produce highly aggressive anti-Ukrainian material, including content intended for audiences involving children from occupied Ukrainian territories. Some creators used Russian intermediary services that provided access to Western AI tools such as Suno and Udio despite restrictions. The researchers then tested several AI generators themselves. Across 40 prompts submitted to Suno, Udio, Mureka, Google Flow Music and ElevenLabs, 25 resulted in successful generations, while safeguards were circumvented in 15 cases. Terrecon reported that four of the five services tested produced Russian-language material containing wartime narratives, although technical problems prevented comparable testing on some systems. In one Udio experiment, the researchers said the model itself introduced more explicit violent language than had appeared in the original promp These tests do not demonstrate that the commercial platforms knowingly support Russian propaganda. They show something narrower: existing safeguards can be inconsistent when political messaging is packaged as music. From generation to Spotify The distribution experiment may be the most revealing part of Terrecon’s research. The team deliberately uploaded test tracks containing explicit hostile language to YouTube, SoundCloud, Spotify and Deezer. Terrecon says none was blocked during the experiment. On SoundCloud, researchers used an account identifying its location as Moscow, disclosed the use of AI and added markers including references to the Russian military and the war. The platform accepted the upload and subsequently offered paid promotional and distribution tools. This does not prove that streaming recommendation systems systematically promote pro-war music. There is currently insufficient public evidence to make that claim. It does demonstrate that material can enter the same commercial distribution infrastructure as ordinary music and, once there, potentially benefit from playlists, searches, sharing and recommendation mechanisms available to other releases. That distinction is important. Propaganda no longer has to announce itself as political communication. On a streaming platform it can look like another song. Culture as a delivery mechanism Music has always been used in wartime propaganda. What generative AI changes is scale. Instead of investing heavily in a limited number of patriotic performers or officially commissioned productions, creators can generate variations across styles, audiences and emotional registers at very low cost. Terrecon found material ranging from war rock to sentimental songs and content styled for younger audiences. Some creators also experimented with cloned celebrity voices and stylistic imitation of established musicians. The format also offers a different relationship with the audience. A political video asks a viewer to consume an argument. Music can accompany commuting, exercise or entertainment and may be encountered outside explicitly political spaces. This does not automatically make it more persuasive, and Terrecon’s research does not establish measurable effects on political attitudes. It does, however, place wartime narratives inside a cultural environment where users may not initially perceive themselves as consuming political messaging. An ecosystem, not a proven Kremlin command structure The strongest evidence supports describing this as a growing AI-assisted pro-Russian propaganda-music ecosystem, not a single operation controlled from Moscow. Terrecon did not establish that the Russian government created, financed or coordinated all 981 tracks. Reporting on the study likewise notes that the extent of direct state involvement remains unclear. There is broader evidence that the Russian state finances cultural projects and digital content supporting the war, including through state-backed funding bodies. That context matters, but it does not allow individual songs in Terrecon’s dataset to be attributed to the Kremlin without additional evidence. The significance of the case lies elsewhere. AI has reduced the cost of producing ideological content, intermediaries can help creators access generation tools, and global platforms can provide distribution. The result is a pipeline in which wartime propaganda no longer has to resemble propaganda at all. It can simply appear in a playlist. Sources Terrecon / Ukrainska Pravda — Daria Verbytska on the research https://www.pravda.com.ua/columns/2026/10/05/8056229/ Suspilne Culture — detailed breakdown of Terrecon findings https://suspilne.media/culture/1417933-rosijsku-voennu-propagandu-maskuut-pid-anime-karaoke-ta-rok-doslidzenna-si-pisen-vid-terrecon/ The Insider — AI-generated Russian war propaganda music https://theins.ru/news/297839 Institute of Mass Information — summary of New York Times reporting https://imi.org.ua/en/news/doslidzhennya-rf-masovo-stvoryu%D1%94-propagandistski-pisni-za-dopomogoyu-shi The Bridge Media — AI-generated songs and Russian military propaganda https://thebridgemedia.com.ua/en/ai-generated-songs-russian-military-propaganda/ Center for Strategic Communication — cost and production of AI propaganda music https://spravdi.org/propaganda-za-11-yak-rosiya-shtampuye-shi-pisni-z-miljonamy-prosluhovuvan/ Times of India — AI-generated Russian war songs https://timesofindia.indiatimes.com/world/europe/ai-sings-russias-war-story-inside-the-rise-of-generative-songs-about-ukraine-conflict/articleshow/134650594.cms EU Council / EUR-Lex — Presidential Foundation for Cultural Initiatives https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026D1351 Human Rights Watch — Russian state funding of digital and patriotic content https://www.hrw.org/report/2025/07/30/disrupted-throttled-and-blocked/state-censorship-control-and-increasing-isolation #DISINFORMED #Episode16 #Russia #Ukraine #RussianPropaganda #WarPropaganda #MusicPropaganda #AIMusic #ArtificialIntelligence #AI #GenerativeAI #SyntheticMedia #AIPropaganda #Disinformation #InformationWarfare #InfluenceOperations #CulturalPropaganda #DigitalInfluence #NarrativeManipulation #PropagandaMusic #StreamingPlatforms #Spotify #AppleMusic #YouTube #YouTubeMusic #Deezer #SoundCloud #Suno #Udio #RussianWorld #RusskiyMir #MilitaryPropaganda #WarNarratives #Mobilisation #AlgorithmicDistribution #RecommendationAlgorithms #MusicStreaming #PlatformManipulation #Terrecon #OSINT #MediaManipulation #WRLD

Nigeria – how pro-Russian influence networks sell military rule as the answer When Nigerians took to the streets in August 2024 to protest soaring living costs and frustration with government, some demonstrations acquired an unexpected symbol: the Russian flag. In Kano, Kaduna and other northern cities, protesters were filmed carrying Russian colours and calling for Moscow’s intervention. Some demanded a military takeover. What initially looked like an unusual expression of anger has since become part of a much larger picture. A September 2026 assessment by the Africa Center for Strategic Studies describes Nigeria as a major target of overlapping foreign information operations, with Russia the most active external actor in its information space. The report does not identify a single centrally controlled campaign. Instead, it maps an ecosystem in which genuine dissatisfaction over insecurity, corruption and living standards is repeatedly redirected towards a broader proposition: democratic government has failed, while the military-led regimes of the Sahel offer a more effective alternative. Turning a real protest into a pro-Russian message The clearest example emerged during the 2024 #EndBadGovernance protests. Nigerian investigative reporting found that a Kano-based TikTok influencer with more than 100,000 followers had been paid through a Telegram channel associated with African Initiative, a Moscow-based media operation linked by researchers to Russian influence activity in Africa. The influencer said the channel supplied photographs, videos and talking points for redistribution on TikTok and Instagram. Among the messages provided were phrases such as “Putin please come and save Nigeria” and “The army is the answer for Nigeria”. Influencers were encouraged to use Hausa-language hashtags including #Zangazanga – “protest” – alongside references to Putin and Russia. Investigators identified 38 accounts circulating similar pro-Russian and pro-military narratives during the demonstrations. Russian flags subsequently appeared among protesters in several northern cities. This does not mean the protests themselves were created by Russia. They were driven by genuine economic and political grievances, and Nigerian protesters gave different reasons for carrying Russian flags. The important feature of the influence activity was precisely that it did not need to manufacture the original anger. It could attach a geopolitical message to an existing domestic crisis. From frustration to the idea of military government The narrative fits a wider pattern seen across West Africa. Russia has developed close relations with the military governments of Mali, Burkina Faso and Niger, while pro-Russian media ecosystems routinely portray those states as examples of sovereignty, stability and resistance to Western influence. Nigeria, by contrast, has remained under constitutional civilian government since 1999. Africa Center researchers say information networks targeting Nigerians increasingly contrast these two models. Recurring messages depict elections as wasteful or predetermined, civilian institutions as incapable of protecting citizens and military governments as more decisive on security and development. Some content portrays the Sahelian juntas as delivering better roads, lower prices and stronger security even where available evidence points to continuing or worsening instability. Language is central to the strategy. Hausa is spoken across northern Nigeria and neighbouring Niger, allowing political narratives to travel across borders that are far less important online than they are on maps. HumAngle documented efforts involving Nigerien state-linked actors to cultivate Hausa-speaking journalists and distribute material favourable to Niger’s junta and hostile to France and Western influence. The Russian and Sahelian-junta information ecosystems are not identical, but their narratives frequently reinforce one another. Fake journalists inside real Nigerian media The campaign environment extends beyond social media. A 2026 investigation by Graphika and Code for Africa identified 44 ghost reporters and fake experts whose identities were used to place Russia-aligned narratives in African media. Thirty-eight were assessed with high confidence to be fabricated. Their articles or quotations appeared across 138 websites and were amplified by at least 113 Facebook accounts and Pages. Nigeria was one of the most heavily targeted countries. According to the Africa Center’s analysis of the research, Daily Post Nigeria carried 39 articles involving 14 identified ghost authors. Once published by a genuine Nigerian outlet, such material could then be cited by other websites, social-media accounts or even Russian official channels as though it had originated independently in Africa. This is information laundering rather than simple propaganda: the most valuable asset being borrowed is the credibility of the local newsroom. Generative AI added another layer. OpenAI and Meta separately disrupted a Russia-origin network that produced Africa-focused political content and operated Facebook Pages posing as local media organisations. One fabricated commentator, “Dr Manuel Godsin”, was presented as a European-trained geopolitical expert although investigators found no evidence supporting his academic biography. ChatGPT had been used to generate articles under the persona’s name, while Meta removed 37 Facebook accounts and 29 Pages connected to the broader network. Different networks, similar strategic direction It would be misleading to merge all these activities into a single Russian command structure. The African Initiative-linked influencer campaign, the ghost-reporter network and the AI-enabled operation disrupted by OpenAI and Meta were uncovered separately and used different infrastructure. Public evidence does not demonstrate that every actor reported to the same organisation. What connects them is a recurring set of themes and methods: portraying Western partnerships as exploitative, presenting Russia as an alternative security partner, amplifying failures of civilian government, and giving military-led rule greater legitimacy. Investigative reporting on leaked Russian documents has meanwhile described a much wider influence apparatus operating across Africa, involving political consultants, paid journalists, influencers and locally tailored campaigns intended to reduce Western influence and expand Moscow’s position. The underlying technique is less about inventing dissatisfaction than redirecting it. Nigeria faces real security threats, economic pressure and public frustration. Influence operators do not need to persuade Nigerians that those problems exist. They need only influence the explanation for why they exist – and which political model appears to offer the answer. That is what makes the Nigerian case significant. The most effective propaganda does not necessarily introduce a completely false reality. It takes a real crisis and changes where the audience is encouraged to look for the solution. Sources Africa Center for Strategic Studies — The Raging Information Battle in Nigeria https://africacenter.org/spotlight/the-raging-information-battle-in-nigeria/ Graphika — Umbrae Ex Machina https://www.graphika.com/reports/umbrae-ex-machina OpenAI — Operation “No Bell” https://openai.com/index/disrupting-malicious-uses-of-ai-no-bell/ TheCable — Ghost reporters in African media https://www.thecable.ng/ghost-reporters-how-fabricated-african-voices-carried-pro-russia-narratives/ HumAngle — Nigeria Is Facing an Information War in Its Own Language https://www.humanglemedia.com/nigeria-is-facing-an-information-war-in-its-own-language DAIDAC / CJID — Russian influence during #EndBadGovernance https://daidac.thecjid.org/how-telegram-tiktok-aided-russian-disinformation-that-led-to-incarceration-of-nigerian-minors/ FactCheckHub — How Nigeria’s hunger protest took a radical turn https://factcheckhub.com/from-economic-protests-to-coup-agitation-how-nigerias-hunger-march-took-a-radical-turn/ News24 — Fake Kremlin-linked analyst planted stories in African media https://www.news24.com/southafrica/news/ai-expert-exposed-fake-kremlin-linked-analyst-planted-stories-in-african-media-20260318-0560 Vanguard — AI ‘expert’ exposed https://www.vanguardngr.com/2026/03/ai-expert-exposed-fake-kremlin-linked-analyst-planted-stories-in-african-media/ Africa Confidential — How Moscow wages social media war https://www.africa-confidential.com/article/id/15961/how-moscow-wages-social-media-war Keywords #DISINFORMED #Episode15 #Nigeria #Russia #RussianInfluence #RussianDisinformation #Africa #WestAfrica #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #Propaganda #MilitaryRule #MilitaryGovernment #Democracy #PoliticalManipulation #NarrativeManipulation #AfricanInitiative #EndBadGovernance #Hausa #LocalInfluencers #GhostReporters #FakeExperts #ArtificialIntelligence #AI #AIPersonas #SyntheticMedia #AIPropaganda #Astroturfing #SocialMediaManipulation #Telegram #TikTok #DigitalInfluence #SourceLaundering #NarrativeLaundering #MediaManipulation #Sahel #Geopolitics #OSINT #WRLD

The Raging Information Battle in Nigeria

Brazil’s synthetic voters – when AI manufactures public opinion They look like ordinary street interviews. A reporter approaches a passer-by in a Brazilian square and asks a simple question: who will you vote for? A young voter explains why Luiz Inácio Lula da Silva deserves another term. An elderly woman says Brazil needs Flávio Bolsonaro because he represents political renewal and greater security. The locations look plausible, the microphones are visible and the answers sound much like the brief political opinions heard in television vox pops around the world. None of the people are real. Ahead of Brazil’s presidential election on 4 October, fact-checking organisation Aos Fatos identified at least 50 TikTok videos in which artificial intelligence was used to manufacture voters, reporters and apparently spontaneous political interviews. Together, the videos had accumulated around 7.4 million views by mid-August. Some promoted Lula, others Flávio Bolsonaro, while another group used synthetic characters to ridicule or stereotype supporters of one side. Aos Fatos found no apparent evidence linking the accounts producing the videos to either presidential campaign. The opinion poll that never took place The format is important. These were not conventional deepfakes in which a recognisable politician is made to say something he never said. Instead, the creators reproduced the visual language of the vox pop – the short street interview used by broadcasters and social-media creators to illustrate what ordinary people supposedly think. In pro-Lula videos, synthetic voters described themselves as beneficiaries of social programmes or credited the president with improving their lives. In videos supporting Flávio Bolsonaro, artificial interviewees associated him with political renewal, public security and fighting corruption. Other clips were openly hostile: AI-generated characters presented as poor or living in parts of Brazil’s north-east were shown in dirty clothes or run-down surroundings, declaring support for Lula because they supposedly preferred welfare payments to work. The deception is therefore subtler than fabricating a candidate’s statement. It manufactures something that political communication normally treats as evidence of public sentiment. A real vox pop may be unscientific, but the people interviewed at least exist. These videos created the appearance that identifiable social groups – young people, pensioners, welfare recipients or residents of particular regions – were spontaneously expressing political preferences when no such encounters had taken place. An electoral-law specialist interviewed by Aos Fatos described the technique as the fabrication of a “social fact that never occurred”. That captures the central innovation: AI is being used not merely to falsify political speech, but to manufacture the impression of grassroots opinion. Fifty videos, but not one proven network The available evidence does not support describing the 50 posts as a centrally controlled influence operation. Aos Fatos located them through TikTok searches and recommendations produced by the platform itself, then examined the accounts responsible for publication. Most had relatively small individual audiences, although their combined reach was substantial. The first examples identified by the investigation appeared as early as March 2026. Activity increased in June and was concentrated particularly in July and the first half of August as Brazil’s election calendar intensified. Some accounts specialised in AI-generated videos generally, including fabricated podcast-style material. Others were explicitly political or supportive of a candidate, but Aos Fatos found no apparent links between those profiles and the official Lula or Bolsonaro campaigns. That distinction is essential. The evidence demonstrates a common technique and a shared political environment, not a single command structure. Some creators may have been motivated by ideology, others by engagement or monetisation. Publicly available evidence does not establish who commissioned the individual videos or whether any coordination existed between the accounts. This decentralised model also creates a different enforcement problem from a traditional bot network. There may be no headquarters to expose and no infrastructure whose removal disables the entire operation. The format itself can be copied by anyone with access to inexpensive generative-video tools. When the algorithm mixes real and synthetic citizens Aos Fatos documented another important feature of the phenomenon: TikTok’s recommendation system placed AI-generated interviews alongside genuine street interviews. For a user scrolling quickly through the platform, the transition between an authentic citizen and an entirely fabricated one could therefore be almost invisible. In 18 per cent of the 50 videos analysed, there was no indication that the people shown had been generated using AI. After Aos Fatos provided TikTok with the videos, the company said it had removed all of them for violating its rules on edited and AI-generated media. TikTok said its policies require creators to identify synthetic content and prohibit manipulated media capable of misleading users about matters of public importance or impersonating genuine journalistic material. The issue extends beyond one platform. Factchequeado’s review of Brazil’s 2026 election campaign found that synthetic endorsements and other deepfakes had become one of the most visible forms of AI-assisted electoral misinformation, alongside fabricated candidate statements and invented scenes. Brazil already had rules for synthetic politics Brazil entered the campaign with unusually detailed electoral rules governing artificial intelligence. The Superior Electoral Court, the TSE, requires electoral propaganda using synthetic multimedia to disclose clearly that AI was used. More importantly for the fake-voter videos, its rules prohibit synthetic audio or video used to favour or harm a candidacy when it creates or alters the image or voice of a living, deceased or fictitious person. The difficulty is attribution and enforcement. When a synthetic video is published by an official campaign, responsibility can be relatively straightforward to investigate. When it comes from an apparently independent account with no demonstrated relationship to a candidate, lawyers interviewed by Aos Fatos said responsibility is more likely to fall on the individual creator, while imposing electoral sanctions on a campaign would require evidence of a connection. For the final 72 hours before the election and the 24 hours following it, the TSE has imposed additional restrictions on newly published or republished synthetic material involving candidates or public figures, reflecting the particular difficulty of correcting fabricated content immediately before voting. From deepfake politicians to synthetic electorates The Brazilian case illustrates a broader change in political manipulation. The first generation of electoral deepfakes concentrated on famous people: make a politician appear to say something damaging, or fabricate an endorsement from a celebrity. Synthetic vox pops reverse the perspective. The politician can remain completely authentic; it is the electorate around the politician that is fabricated. That changes the psychological proposition of the message. Instead of saying the candidate believes this, the video suggests people like you believe this. Age, clothing, accent, neighbourhood and social class can all be generated to construct an artificial constituency around almost any political claim. There is no evidence that the 50 Brazilian videos identified by Aos Fatos constitute a single centrally directed campaign, nor evidence that they changed voting intentions. What they demonstrate is a technique whose barrier to entry has become extremely low. AI no longer needs to forge the politician. #DISINFORMED #Episode14 #Brazil #BrazilElection2026 #Elections #ElectionDisinformation #ArtificialIntelligence #AI #GenerativeAI #SyntheticVoters #SyntheticMedia #AIAvatars #AIGeneratedVideo #VoxPop #FakeInterviews #Astroturfing #AIPropaganda #PoliticalDisinformation #InfluenceOperations #InformationWarfare #SocialMediaManipulation #TikTok #PublicOpinion #ManufacturedConsent #SyntheticPublicOpinion #DigitalInfluence #Deepfakes #ElectionIntegrity #TSE #AosFatos #FactChecking #OSINT #MediaManipulation #WRLD (translated)

Eleitores gerados por IA fazem campanha no TikTok e põem em xeque regra do TSE

Disinformation for hire – the network of 70 fake newsrooms sold as a service The websites looked local. Naija Pulse appeared to cover Nigeria, Echo Berlin Germany, The British Daily Britain, Fifty States the United States and Commonwealth Post Australia. Each had its own branding, articles, supposed journalists and matching social-media presence. Taken individually, they resembled small independent news outlets. According to Anthropic, however, they were parts of a single commercial influence network spanning six continents. Anthropic’s September 2026 threat report identifies the operation as GTG-54002, a commercial “influence-as-a-service” network that used Claude to generate and rewrite political content at industrial scale. Investigators linked roughly 70 fabricated news websites to around 70 matching X accounts and more than 250 additional inauthentic commenting accounts designed to create the appearance of genuine public engagement. The network produced at least 8,913 articles in about 20 languages before Anthropic disrupted the activity. The significance of the case is not simply the number of fake sites. It is the business model. The network did not consistently promote one government, party or ideology. Anthropic found that its political position changed according to the apparent interests of different customers. The company therefore described it as a commercial influence operation: political manipulation offered in much the same way as other outsourced digital services. A fake media ecosystem built at scale Anthropic says the infrastructure was created rapidly. Domains were registered from France during a roughly ten-week period in mid-2025 and deployed through shared technical infrastructure, allowing investigators to connect publications that outwardly appeared unrelated. Most of the supporting social-media accounts were also created within a narrow timeframe in June and July 2025. The sites were designed to look like functioning local newsrooms rather than anonymous propaganda pages. Articles carried fabricated bylines belonging to journalists who, according to Anthropic, did not exist. Each outlet had a corresponding account on X, while a second layer of fake profiles commented on and amplified the articles. Many of those accounts used AI-generated profile photographs. The result was a three-tier structure: the newsroom published the story, the branded social account distributed it, and apparently ordinary users supplied the appearance of public reaction. Some of those sites remained publicly visible after the operation was exposed. The British Daily, for example, described itself as providing “conservative insights” on British sovereignty and migration, while Commonwealth Post presented itself as an Australian liberal publication focused on democracy, migration and regional security. Those contrasting editorial identities illustrate the central feature identified by Anthropic: the network was capable of taking different political positions in different markets. Claude as a publishing engine Claude was not simply asked to draft occasional articles. The operators built a structured production pipeline around it. Prompts required fixed JSON outputs, formatted HTML, precise character limits and internal links, allowing articles to move directly into an automated publishing workflow. The system could generate entirely new material or take reporting produced by legitimate journalists and rewrite it to fit a desired political perspective. Anthropic identified three recurring techniques. The same source article could be rewritten in opposite ideological directions for different audiences; a political interpretation could be added to a story that originally contained none; and material could be moved from one country to another after its original context had been removed. The articles were also structured to improve the apparent authority of the sites in search engines, helping the network imitate ordinary digital publishing practices rather than simply broadcasting propaganda. This is where generative AI changes the economics of an influence operation. A conventional network of dozens of supposedly local publications would normally require writers, translators, editors and social-media staff. Here, much of that production could be standardised and automated while human operators concentrated on political direction, customer requirements and distribution. The DRC–Rwanda conflict as a test case The clearest concentration of activity involved the Democratic Republic of Congo. Anthropic identified 318 articles concerning the DRC across the fake-news network. The material generally supported positions aligned with the Congolese government, particularly on regional mineral agreements and tensions with Rwanda. Early in the network’s growth, many of the fake social-media personas following and amplifying its accounts also presented themselves as Congolese. Investigators observed one especially revealing episode on 11 September 2025, when multiple sites published almost identical articles about the DRC–Rwanda conflict within approximately three minutes of one another. The wording and political tone were adjusted for different regional audiences, while associated X accounts distributed the links in a coordinated pattern. Anthropic said the activity contained signals suggesting that one or more customers had interests connected to the DRC–Rwanda conflict. It did not, however, identify those customers and explicitly stated that it found no evidence that any government had directed the operation. That distinction is essential. The content may have benefited a political actor without demonstrating that the actor commissioned or controlled it. Influence without ideology Commercialisation is what distinguishes GTG-54002 from many state-linked information operations. A government propaganda network usually has an identifiable strategic direction. A commercial influence provider does not need one. Its infrastructure can support one position in one country and the opposite position somewhere else, provided different customers are willing to pay. That makes attribution more difficult. Analysts cannot necessarily infer the operator from the ideology of the content because ideology may simply be part of the service package. The enduring asset is the infrastructure: domains, publishing systems, fake journalists, social-media accounts and automated amplification. Anthropic says the operation was disrupted before it achieved significant genuine reach. It classified GTG-54002 as Category Two on the Brookings Breakout Scale: material circulated across the network’s own sites and associated social accounts but showed no evidence of substantial penetration into authentic communities. Most of the 8,913 articles generated little observable engagement from real users. That limited impact is important. The case should not be presented as a successful global manipulation campaign. It is better understood as evidence that the infrastructure required to run such campaigns has become cheaper, faster and increasingly commoditised. The deeper shift is that a fake media ecosystem no longer has to be built around a single political cause. It can be built once, automated and then repurposed for the next customer. Disinformation, in this model, is no longer only a political instrument as it turend into the service. Sources: Anthropic — Countering misuse of AI: September 2026 https://www.anthropic.com/threat-intelligence-report-september-2026 Business Standard — AI scaling fake newsrooms, surveillance and online scams https://www.business-standard.com/technology/tech-news/anthropic-report-ai-fake-newsrooms-dating-surveillance-scams-126091100730_1.html Mimikama — KI baut 70 erfundene Nachrichtenportale https://www.mimikama.org/ki-netzwerk-erfundene-nachrichtenportale-echo-berlin/ Poliscoop Media — Anthropic exposes DRC propaganda network https://www.poliscoopmedia.com/articles/anthropic-exposes-drc-propaganda-network-20260911 The British Daily — example of a fabricated outlet identified in the network https://www.british-daily.com/contact Commonwealth Post — example of a fabricated outlet identified in the network https://commonwealth-post.com/category/science MalPulse — infrastructure references for network domains https://www.malpulse.com/infra-pivots/usom-pivots/list/?page=1105 Keywords: #DISINFORMED #Episode13 #DisinformationAsAService #InfluenceAsAService #FakeNewsrooms #FakeMedia #SyntheticMedia #ArtificialIntelligence #AI #GenerativeAI #ClaudeAI #Anthropic #Disinformation #InfluenceOperations #InformationWarfare #FIMI #CommercialInfluence #PoliticalManipulation #NarrativeManipulation #NarrativeLaundering #SourceLaundering #MediaImpersonation #FakeJournalists #SyntheticPersonas #Astroturfing #SocialMediaManipulation #CoordinatedInauthenticBehaviour #CIB #DigitalInfluence #AutomatedPropaganda #ContentAutomation #AIPropaganda #LKMCompany #NaijaPulse #AxumVoices #JamboJournal #EchoBerlin #TheBritishDaily #FiftyStates #CommonwealthPost #DRC #Rwanda #OSINT #WRLD

Countering misuse of AI: September 2026 / Anthropic

Iran’s cognitive warfare – when AI becomes the operating layer of state propaganda Iranian state-linked influence operators were not using artificial intelligence simply to write faster social-media posts. According to Anthropic’s September 2026 threat intelligence report, three separate operations connected to Iranian propaganda institutions were using Claude to help construct the machinery behind what the operators themselves called “soft war” and “cognitive warfare” – non-military efforts intended to shape public opinion inside Iran and abroad. Anthropic linked the activity to the Islamic Culture and Communications Organization (ICCO), which operates under Iran’s Ministry of Culture and Islamic Guidance; the Islamic Propaganda Office of Khorasan Razavi; and the Bina Cultural Observatory, part of the Islamic Propaganda Organization. The company said each operation was run by someone working within or on behalf of the named institution. The attribution was based on a combination of account telemetry, institutional references disclosed during conversations, branded documents and open-source corroboration. Anthropic subsequently removed the accounts. AI as an operational headquarters The most significant feature of the operation was the role assigned to AI. Claude was used to develop campaign plans, doctrine manuals, coded project portfolios, persona systems, target databases, early-warning protocols, amplification schedules and ministerial planning documents. Anthropic described the model as the principal administrative and operational layer supporting the three campaigns, allowing relatively small groups of operators to create organisational structures and planning material that would otherwise have required a much larger staff. This distinction matters. The reported use of AI went considerably beyond content generation. Operators were using the model to help organise how influence activity should function: which audiences to target, which identities should deliver particular narratives, how official material should be repackaged and when amplification should take place. Human operators still determined objectives and supplied the underlying political doctrine; AI helped translate those decisions into an operational system. Anthropic found that all three operations explicitly connected their activity to Jihad al-Tabyin, often translated as “explanatory jihad”, a concept used within the Iranian state system to frame information activity as both a strategic and ideological responsibility. In internal planning material examined by the company, this doctrine was not merely rhetorical: it informed manuals and campaign structures used by the operators. ‘Not the narrator, but the director’ One sentence contained in the ICCO material captures the model particularly clearly. According to Anthropic, an operator described the role of Iranian cultural attachés as being “not to be the narrator, but the director” of the narrative. The distinction reveals the logic of attribution laundering. Instead of publishing an overt state message and asking foreign audiences to believe it, the operator attempts to create the appearance that the same narrative emerged independently from journalists, activists, foreign writers or ordinary citizens. Anthropic found that Claude was used specifically to make content appear to come from foreign authors or independent media organisations and to design hashtag campaigns that looked grassroots rather than centrally organised. The ICCO operation reportedly used the organisation’s international cultural network as part of this structure. Anthropic found ministerial-level documents carrying official ICCO branding, including a nine-part international influence portfolio. This makes the operation particularly significant because the infrastructure was not limited to anonymous social-media accounts; it intersected with formal state institutions and an existing network of cultural representation abroad. A multilingual content factory A second operation was associated with the Islamic Propaganda Office of Khorasan Razavi and what Anthropic described as a “cognitive warfare command room” operating from a seminary in Mashhad. Its organisers ran a multi-province content production system known internally as Manjanegh, or “Catapult”. According to Anthropic, dozens of activists were involved in repackaging publicly available reporting from Iranian security institutions under different personas so that the material no longer appeared directly connected to those institutions. The network used Claude to transform official government intelligence bulletins into customised material in Farsi, Arabic, Urdu, Malay, Spanish and English, while planning expansion into a total of 20 languages. Distribution extended across Iranian platforms such as Eitaa, Bale and Rubika and international services including X, Instagram, Telegram, TikTok and YouTube. Anthropic also documented paid amplification across more than 100 Iranian channels, including channels associated with IRGC narratives. The scale should nevertheless be interpreted carefully. Anthropic documented production infrastructure and some real-world dissemination, but it did not demonstrate that all planned campaigns were fully deployed or that they meaningfully changed public opinion. The company placed the operation in Category Three of its Breakout Scale, indicating multi-platform activity with content observed in external distribution channels, rather than evidence of strategic impact on entire populations. From security bulletins to apparently independent voices The Bina Cultural Observatory operation provides another example of the same architecture. Anthropic linked a director-level official at Bina to activity in which Claude generated messaging in the voice of an IRGC spokesperson. During the 2026 US–Israel–Iran war, the network also attributed false claims to Western institutions including CSIS, Brookings and RAND. The apparent objective was to make Iranian state-aligned claims look as though they had been independently validated by respected foreign research organisations. That technique is more sophisticated than simply publishing propaganda under a false name. It attempts to manufacture a chain of external validation: official information is transformed into apparently independent commentary, which can then be recirculated as evidence that outside observers have reached the same conclusion. Anthropic also found target databases naming international officials and Iranian opposition figures, as well as aggressive counter-narrative material directed against the Bahá’í community. These findings show that the infrastructure was designed not only for broad messaging but also for targeted influence activity against specific groups and individuals. What AI changed The Iranian operations described by Anthropic did not create a new doctrine of influence. Iran has used cultural institutions, official media, aligned organisations and covert or semi-covert online networks for years. What AI changed was the economics and organisational capacity of that model. A relatively small team could use the system to draft doctrine, create personas, translate material, structure target databases, produce campaign calendars and generate multiple versions of the same message for different audiences. The operator remained responsible for intent, political direction and selection of targets. AI reduced the amount of human labour required to turn those decisions into a functioning influence operation. The most revealing part of the case is therefore not that an Iranian propaganda network used a chatbot. It is that AI was being treated as part of the back office of information warfare – a system for converting state doctrine into apparently decentralised, multilingual and plausibly independent voices. Sources Anthropic — Detecting and countering misuse of AI: September 2026 https://www.anthropic.com/threat-intelligence-report-september-2026 Iran International — Iran state-aligned accounts used Claude to push IRGC narratives https://www.iranintl.com/en/202609105561 BNE IntelliNews — Yemen missile cell used AI to write guidance software, Anthropic says https://new.intellinews.com/articles/yemen-missile-cell-used-ai-to-write-guidance-software-anthropic-says-467296 This is Beirut — Anthropic report details Iranian propaganda operations https://thisisbeirut.com.lb/news/politics/anthropic-report-details-iranian-propaganda-operations-and-yemen-missile-development-using-claude Anthropic report — PDF mirror https://static.foxbusiness.com/foxbusiness.com/content/uploads/2026/09/anthropic-detecting-and-countering-091026-1.pdf Keywords #DISINFORMED #Episode11 #Iran #IranianInfluence #IranianPropaganda #CognitiveWarfare #SoftWar #JihadAlTabyin #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #ArtificialIntelligence #AI #AIPropaganda #GenerativeAI #ClaudeAI #Anthropic #SyntheticMedia #NarrativeManipulation #NarrativeLaundering #AttributionLaundering #PersonaNetworks #Astroturfing #SocialMediaManipulation #DigitalInfluence #StatePropaganda #IslamicCultureAndCommunicationsOrganization #ICCO #IslamicPropagandaOrganization #KhorasanRazavi #IRGC #MultilingualInfluence #Targeting #Amplification #OSINT #WRLD

Countering misuse of AI: September 2026 / Anthropic

Fake NV – how a cloned newsroom turned an AI video into a $140 million corruption scandal For two days in September, a website that looked almost indistinguishable from one of Ukraine’s best-known news organisations carried an extraordinary corruption story. It claimed that Ukraine’s National Anti-Corruption Bureau had raided former defence procurement chief Arsen Zhumadilov and discovered more than $140 million in cash packed inside refrigerator boxes. One box supposedly carried the words “For the Servant of the People” – an apparent reference to President Volodymyr Zelenskyy’s political party. The raid never happened. The photographs and video presented as evidence were fabricated, and the news organisation reporting the story was not the New Voice of Ukraine but a cloned version of it. The episode is a compact example of an increasingly effective disinformation technique. Rather than inventing a new propaganda outlet and trying to build its credibility from scratch, an operator can simply steal the identity of an established newsroom and place fabricated material inside an otherwise convincing copy of its editorial environment. A newsroom copied almost in full The counterfeit site appeared at nvukraine.com, while the authentic New Voice of Ukraine operates at nv.ua and english.nv.ua. Registration records examined by fact-checkers show that the false domain was created on 21 September 2026, two days before the fabricated article appeared. According to NV’s own investigation, the imitation went much further than copying a logo: the operators reproduced the site’s visual design, sections, branding, contact information and genuine editorial material. A snapshot of legitimate NV content from 23 September appears to have been copied onto the counterfeit site, into which the operators inserted a single false article. That article claimed that NABU had searched premises connected to Zhumadilov, who had headed Ukraine’s Defence Procurement Agency until August, and seized $140 million in cash. The story was published in several languages, including Ukrainian and English, suggesting that the operation was intended not only for Ukraine’s domestic information space but also for foreign audiences following the war and Western support for Kyiv. AI supplied the supposed evidence The false article was supported by a video purportedly showing the money discovered during the raid. NABU said no such search or procedural action had taken place and identified the footage as fabricated using artificial intelligence. Independent fact-checker Lead Stories found no credible Ukrainian or international reporting confirming either the raid or the alleged seizure, while searches of NABU’s own published material produced no evidence supporting the claim. The operation therefore combined two separate forms of synthetic credibility. The AI-generated footage supplied what looked like visual proof, while the cloned NV website supplied institutional proof: an apparently reputable Ukrainian newsroom supposedly confirming that the event had happened. Neither element needed to withstand close scrutiny for long. Together, they only needed to appear credible enough to be copied, quoted and redistributed before the deception was exposed. From a fake Ukrainian source into the Russian information ecosystem On 24 September, the story began moving through large pro-Russian Telegram channels. Ukraine’s Center for Strategic Communications traced early amplification to Golos Mordora, with roughly 149,000 subscribers, and Militarist, with around 277,000. Within less than an hour, other channels including VOBLA, Rossiya Seychas and Ostashko! Vazhnoye were circulating versions of the same claim. It subsequently appeared on X and on Russian-language websites including e-news.su and pressa24.ru. Babel calculated that posts carrying the fabrication had accumulated approximately 370,000 views by the morning of 25 September. The story also moved beyond the Russian-language ecosystem. English-language versions appeared in online communities including Lemmy and Hexbear, while accounts on X shared direct links to the counterfeit NV article. NV later reported that larger Russian media and propaganda outlets, including RIA Novosti, Life, Vesti, Ukraina.ru and Mail.ru, had reproduced or discussed the claim. Kirill Dmitriev, head of the Russian Direct Investment Fund and a Kremlin representative involved in contacts with the United States, also shared it on 25 September. This amplification is significant, but it should not be confused with proof of authorship. Publicly available evidence shows how the false story entered and spread through a Russian and pro-Russian information ecosystem. It does not establish which organisation registered the cloned domain, generated the video or directed the operation from the outset. Why copy NV? The operation relied on source laundering. A claim originating directly from a Russian Telegram channel that Ukraine’s defence procurement system had concealed $140 million would immediately carry an obvious political context. A claim apparently uncovered by an established Ukrainian newsroom looks very different. Once the fabricated NV article existed, subsequent accounts could cite what appeared to be an independent Ukrainian source rather than present the allegation as their own. Each repost moved the story another step away from its manufactured origin. The use of an English-language version strengthened that mechanism for audiences outside Ukraine. The underlying narrative was also carefully chosen. Corruption in Ukrainian defence procurement is a genuine subject of public scrutiny and investigative reporting, so the fabricated story did not require audiences to accept an entirely unfamiliar premise. It inserted a false event into a real area of political concern. That mixture of authentic context and fabricated evidence can be more persuasive than a completely invented story because much of the surrounding information feels recognisable. What can – and cannot – be attributed Ukrainian authorities and NV describe the episode as a Russian information operation, and its distribution can be documented extensively across pro-Russian and Russian media channels. The available public evidence, however, does not identify the organisation that created the counterfeit website, nor does it link the operation forensically to a named Russian intelligence service, military unit or state contractor. The most precise description is therefore a Russian-aligned disinformation operation whose fabricated material was systematically amplified through the Russian information ecosystem. That distinction matters. Distribution can be observed directly; command-and-control is harder to establish and should not be inferred without evidence. The newsroom itself becomes the deepfake The most important feature of the operation was not the $140 million figure or even the AI-generated video. It was the counterfeit newsroom surrounding them. The operators copied a real publication, populated it largely with genuine material and inserted a single false story, allowing the fabrication to borrow the accumulated credibility of journalists who had nothing to do with it. This points to a broader evolution in synthetic media. AI can fabricate an image, a voice or a video, but an influence operation can now fabricate something larger: the source that supposedly verified the evidence. In the Fake NV operation, the article, the video and the website reinforced one another, creating not simply a false story but a manufactured chain of credibility. Sources The New Voice of Ukraine — investigation into the cloned website https://english.nv.ua/nation/nv-discovers-fake-copy-of-website-with-planted-story-cites-russian-links-50644601.html The New Voice of Ukraine — Russian amplification of the $140 million fabrication https://english.nv.ua/russia-spreads-fake-140-million-ukraine-corruption-story-during-dmitriev-u-s-talks-50644647.html Lead Stories — independent fact-check https://leadstories.com/hoax-alert/2026/09/fact-check-fake-story-claims-140-million-found-at-home-of-ukraines-zhumadilov-marked-servant-of-the-people-nv-website-originated-it.html Babel — AI video and distribution analysis https://babel.ua/en/news/130469-a-video-is-sharing-online-about-140-million-found-in-the-possession-of-the-ex-head-of-the-defense-procurement-agency-this-is-an-ai-video-distributed-by-a-clone-of-ukrainian-media Center for Strategic Communications and Information Security — initial debunk https://spravdi.org/en/ai-fake-about-140-million-amid-us-talks-how-russians-impose-the-image-of-corrupt-ukraine-on-the-west/ Center for Strategic Communications and Information Security — NABU confirmation https://spravdi.org/u-merezhi-poshyryuyut-shi-fejk-pro-nibyto-obshuky-nabu-v-eksgolovy-agencziyi-oboronnyh-zakupivel/ Detector Media — distribution and NABU response https://detector.media/infospace/article/252806/2026-09-25-u-merezhi-pidrobyly-sayt-nv-dlya-poshyrennya-feyku-pro-obshuky-v-eksochilnyka-agentsii-oboronnykh-zakupivel/ Keywords #DISINFORMED #Episode10 #FakeNV #NewVoiceOfUkraine #Ukraine #Russia #RussianDisinformation #RussianInfluence #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #MediaImpersonation #ClonedMedia #FakeMedia #FakeNews #ArtificialIntelligence #AI #AIGeneratedContent #SyntheticMedia #AIVideo #SourceLaundering #NarrativeLaundering #CorruptionNarrative #UkraineCorruption #DefenceProcurement #NABU #ArsenZhumadilov #Telegram #SocialMediaManipulation #DigitalInfluence #Propaganda #OSINT #MediaManipulation #WRLD

Russia’s influence operation arrives ahead of the US midterms With weeks remaining before America's November midterm elections, a familiar type of content has begun appearing online. Videos resembling reports from CNN, the BBC and The New York Times accuse candidates of corruption, antisemitism and misconduct. Hollywood actors appear to denounce Democrats. Other clips claim that warnings about Russian interference are themselves a Democratic disinformation campaign. The reports are fabricated. Graphika, which tracks online influence operations, says it has identified a coordinated campaign targeting candidates in competitive US Senate races. It assesses with high confidence that the material was produced by Operation Overload, also known as Matryoshka – a long-running Russia-aligned influence operation previously active against elections and political debates in Europe and the United States. The activity coincides with a broader warning from American intelligence officials. Classified assessments reported by The New York Times conclude that the Kremlin has authorised another digital influence campaign ahead of the 2026 midterms, aimed primarily at exploiting existing divisions and undermining confidence in American democracy. There is an important distinction. US officials have not reported evidence that Russia is attempting to manipulate voting machines or alter the counting of votes. The operation is about influencing the information environment surrounding the election. Fake scandals for competitive Senate races Graphika traced a concentrated wave of activity between 10 and 14 September. Likely inauthentic or repurposed accounts distributed videos accusing Democratic politicians of corruption, antisemitism and other misconduct. The targets included Senator Jon Ossoff in Georgia, Representative Chris Pappas in New Hampshire and Texas state representative James Talarico, as well as Senate candidates Sherrod Brown in Ohio, Roy Cooper in North Carolina, Mary Peltola in Alaska, Abdul El-Sayed in Michigan, Joshua Turek in Iowa and Troy Jackson in Maine. The selection was not random. These were politicians involved in Senate contests where the result could matter to control of the chamber. The campaign did not rely on a single political narrative. Instead, it attached different accusations to different candidates – corruption, social issues, antisemitism or personal misconduct – while maintaining a consistent production and distribution model. That model is characteristic of Matryoshka: create apparently independent pieces of evidence, disguise them as journalism and distribute them through networks of disposable accounts. Hollywood celebrities who never said what the videos claimed One of the campaign's more distinctive techniques involved genuine footage of American actors. Videos featuring celebrities including Sarah Jessica Parker and Julia Roberts were altered with captions and other material to suggest they were promoting the slogan #AllDemocratsAreCriminals. The technique continued in subsequent material. Fact-checkers identified fabricated New York Times-branded videos using footage of Alyssa Milano, Sean Astin, Rachael Harris, Leonardo DiCaprio, Eric Braeden, Annie Potts and Patrick Fabian. Some of the original footage came from Cameo, where actors record personalised video messages. Their authentic images were retained while fabricated audio, captions or surrounding material changed the meaning entirely. Lead Stories compared several of the clips with the originals and found that the supposed political statements did not appear in the genuine recordings. Eric Braeden's representative separately confirmed that the claim he had joined the anti-Democratic campaign was false. The advantage of the technique is straightforward. Generative AI does not need to create a convincing celebrity from nothing. The operator can begin with authentic footage of a recognisable person and manipulate only the elements necessary to manufacture a political statement. Stealing the authority of real newsrooms Celebrity impersonation was only one layer. The operation repeatedly borrowed the visual identity of established media organisations. Graphika identified material impersonating or falsely citing the BBC, CNN and Politico, alongside references to France's VIGINUM foreign-interference agency and journalist Brandy Zadrozny. Other material reproduced New York Times-style branding. Some fabricated reports made an unusual claim: that Democrats themselves were organising disinformation or “false-flag operations” and then blaming Russia. This creates a defensive layer around the influence operation. Instead of merely distributing false political allegations, the campaign also attempts to discredit future reporting about the manipulation itself. If successful, evidence exposing foreign interference can be reframed as part of the conspiracy. Graphika says it assesses with high confidence that Operation Overload produced these videos. The technique is well established. Earlier investigations by CheckFirst and Reset Tech documented hundreds of falsified pieces of content produced by Operation Overload, often impersonating journalists, institutions and major media brands. AI-generated or manipulated material has increasingly become part of that production system. What US intelligence says Russia is trying to achieve The broader strategic picture comes from American intelligence assessments reported on 18 September. According to US officials familiar with classified findings, the Kremlin has authorised a covert digital influence campaign aimed at Americans during the 2026 election season. Its apparent objective is to seed or amplify domestic divisions and weaken confidence in the political process. Some officials described the principal aim as creating disorder rather than helping a single political party. The publicly identified Matryoshka material examined so far, however, has targeted Democratic candidates. Those two findings should not be treated as contradictory. An operation can exploit partisan divisions while serving the broader objective of making the electoral system appear corrupt, chaotic or illegitimate. US officials also reportedly assess the current Russian campaign as less extensive or coordinated than some previous election operations. Moscow is considered less focused on congressional elections than presidential contests and remains heavily occupied by its war against Ukraine. Russia has denied previous US accusations of election interference. An operation with limited reach – so far There is another reason for caution: producing large quantities of disinformation is not the same as successfully influencing voters. Matryoshka has repeatedly demonstrated an ability to manufacture content at industrial speed, but much of its material receives little genuine engagement. Researchers monitoring the network have previously warned against confusing automated distribution and platform view counts with authentic audience penetration. There are exceptions. A fabricated New York Times-style video featuring Jamie Lee Curtis had accumulated nearly 200,000 views on X by the end of 17 September, according to reporting by The New York Times. Other pieces attracted considerably less attention. There is currently no public evidence demonstrating that the campaign has changed voting intentions or will affect election results. What the September activity demonstrates is something narrower but important: a Russia-aligned influence infrastructure previously used against European elections has now turned significant attention towards the American midterms. The basic method has changed little – impersonate trusted media, manufacture scandals and use networks of inauthentic accounts to distribute them. What has changed is the production technology. Authentic celebrity footage, synthetic voices, manipulated video and rapidly generated fake journalism allow the same operation to produce more tailored material for more candidates at lower cost. The objective does not require Americans to believe every fabrication. Creating uncertainty over which videos, news reports and public statements are authentic can itself degrade trust in the information environment surrounding an election. Sources - Graphika — Russia-Aligned Influence Operation Targets US Midterm Candidates, German State Elections https://www.graphika.com/insights/russia-aligned-influence-operation-targets-us-midterm-candidates-german-state-elections - The New York Times — Russia Aims to Inject Chaos Into Elections, U.S. Intelligence Finds https://www.nytimes.com/2026/09/18/us/politics/russia-election-disinformation-us-intelligence.html - Kathimerini / The New York Times — Russia Aims to Inject Chaos Into Elections https://www.ekathimerini.com/nytimes/1315792/russia-aims-to-inject-chaos-into-elections-us-intelligence-finds/ - CheckFirst — Operation Overload: An AI-fuelled escalation of the Kremlin-linked propaganda effort https://checkfirst.network/operation-overload-an-ai-fuelled-escalation-of-the-kremlin-linked-propaganda-effort/ - CheckFirst — Operation Overload targeting the US election https://checkfirst.network/operation-overload-a-growing-disinformation-threat-now-targeting-the-u-s-presidential-election/ - Lead Stories — Fake NYT videos: Alyssa Milano, Rachael Harris and Sean Astin https://leadstories.com/hoax-alert/2026/09/fact-check-fake-new-york-times-videos-of-alyssa-milano-rachael-harris-sean-astin-falsely-claim-they-support-all-democrats-are-criminals.html - Lead Stories — Fake NYT videos: Leonardo DiCaprio, Eric Braeden and other celebrities https://leadstories.com/hoax-alert/2026/09/fact-check-fake-new-york-times-videos-of-leonardo-dicaprio-eric-braeden-other-celebs-falsely-claim-they-support-all-democrats-are-criminals.html - Brennan Center for Justice — AI Is Changing Foreign Election Influence https://www.brennancenter.org/our-work/analysis-opinion/ai-changing-foreign-election-influence - ODNI — previous US intelligence assessment of foreign election information operations https://www.dni.gov/files/ODNI/documents/assessments/NICM-Declassified-Foreign-Threats-to-US-Elections-After-Voting-Ends-in-2024.pdf - FBI / ODNI / CISA — previous joint assessment of Russian election influence operations https://www.fbi.gov/news/press-releases/joint-odni-fbi-and-cisa-statement-110424 #DISINFORMED #Episode9 #Russia #UnitedStates #USMidterms #Midterms2026 #USElections #ElectionInterference #ForeignInterference #RussianInfluence #RussianDisinformation #OperationOverload #Matryoshka #Disinformation #InformationWarfare #InfluenceOperations #FIMI #ArtificialIntelligence #AI #AIPropaganda #Deepfakes #SyntheticMedia #MediaImpersonation #FakeMedia #FakeNews #PoliticalDisinformation #CelebrityDeepfakes #SocialMediaManipulation #DigitalInfluence #ElectionSecurity #CognitiveWarfare #Graphika #OSINT #Democracy #WRLD

Russia-Aligned Influence Operation Targets US Midterm Candidates, German State Elections | Graphika

UAE / Sudan – when an influence operation tried to enter the United Nations A network of roughly 300 apparently independent social-media influencers. A human-rights organisation borrowing the identity of a real NGO. Personal dossiers on European politicians and journalists. And testimony prepared for delivery at the United Nations without revealing the state interest behind it. These were elements of an influence operation uncovered by Anthropic and disclosed in September 2026. The company says it linked the activity with high confidence to UAE government officials. Tracked as GTG-84002, the operation targeted several overlapping issues: the Muslim Brotherhood, perceptions of the war in Sudan and international mechanisms examining the United Arab Emirates' role in the conflict. What distinguishes the case is not simply its use of artificial intelligence. It is the attempt to make state-aligned messaging appear to originate from independent influencers, human-rights organisations and potentially witnesses addressing an international institution. An influence network built around 300 fake voices Anthropic identified a single actor using Claude to support a sustained influence campaign. At its centre was an AI persona called “Deadshot”, running on the operator's own platform. A master doctrine file repeatedly instructed the system to support what it described as a coordinated international effort to dismantle the Muslim Brotherhood. The operator simultaneously managed several components of the campaign, including approximately 300 inauthentic influencer accounts across social-media platforms. Internal material examined by Anthropic described the apparent independence of this network as its greatest strategic advantage. That phrase captures the central method. The objective was not simply to broadcast a political position but to conceal where that position originated. One visible example appeared on 4 June 2026, when accounts participated in a coordinated campaign using #SudanIslamists and near-identical graphics connecting Sudanese Islamists and the Muslim Brotherhood with regional instability. Anthropic says the amplification network was centrally funded and coordinated. Its investigation also found that the operator financing the social-media network was connected to the wider influence operation. A human-rights organisation that was not what it appeared to be Social media was only one layer. The operator also created a front NGO that copied the identity of a genuine Swiss organisation and used that borrowed legitimacy to publish human-rights material produced for the campaign. Anthropic's description elsewhere also refers to the identity of a real Sudanese human-rights organisation being used in connection with the preparation of testimony. The public report does not fully clarify whether these references describe the same front or separate elements of the operation, so they should not be treated as definitively identical. The underlying technique, however, is clear: political material was designed to appear as if it originated from independent civil society rather than from actors linked to a government. This is particularly significant in the human-rights environment, where the perceived independence of an organisation or witness can determine how seriously evidence is received by journalists, diplomats and international institutions. The attempt to reach the UN The most consequential part of the operation concerned the 62nd session of the UN Human Rights Council. According to Anthropic, the operator used Claude to ghost-write complete testimony intended to be delivered by two individuals during the session. The texts were prepared under explicit constraints ensuring that neither statement would mention the UAE. This did not amount to a conventional government submission. The intention, according to Anthropic's reconstruction, was for material serving the interests of a party connected to the Sudan conflict to reach an international forum through apparently independent voices. But an important limitation remains: Anthropic could not confirm that the testimony was ultimately delivered. The company similarly could not establish whether other dossiers produced by the operation reached their intended recipients or influenced policy. It therefore assessed the campaign as Category Three on the Brookings Breakout Scale – activity distributed across several platforms, but without evidence of broad public impact sufficient for a higher classification. The distinction matters. The evidence demonstrates a sophisticated attempt to influence international debate; it does not demonstrate that the attempt succeeded. Politicians, journalists and UN investigators became targets The operation was not limited to generating public content. Anthropic found that the operator researched and compiled detailed profiles of 18 members of the European Parliament and prominent journalists. Some material was prepared for direct delivery to senior UAE officials. The network also assembled what Anthropic describes as “counter-accountability dossiers” on UN Special Rapporteurs who had criticised the UAE's conduct in relation to Sudan. This places the campaign in a broader context. Since Sudan's civil war began in April 2023, the role of external powers has become an increasingly important part of international scrutiny. Sudan has accused the UAE of supporting the Rapid Support Forces, allegations Abu Dhabi has repeatedly denied. In 2025, Sudan brought a case against the UAE before the International Court of Justice, accusing it of complicity in genocide against the Masalit through alleged support for the RSF. The UAE rejected the allegations. The ICJ subsequently removed the case from its list after finding that it lacked jurisdiction because of the UAE's reservation to the relevant provision of the Genocide Convention. The ruling therefore did not determine whether Sudan's substantive allegations were true or false. That contested international environment helps explain why narratives about Sudan, human rights and accountability were valuable targets for an influence operation. AI as an operating system for influence The role played by Claude is also important to understand accurately. Anthropic did not find that artificial intelligence independently conceived or directed the campaign. Human operators established the objectives, political doctrine and targets. AI instead helped operationalise them. Across hundreds of sessions, Claude was used to transform predetermined political objectives into social-media narratives, human-rights reports, testimony, intelligence-style briefs and detailed profiles of individuals. The same system could support narrative production, target research and preparation of material for different audiences. That represents a more significant development than simply using generative AI to produce propaganda faster. Traditional influence operations require different teams to research targets, write content, manage personas, adapt messages and prepare briefing material. Generative AI can compress several of those functions into a single operational workflow. The result is not necessarily more convincing propaganda. It is potentially cheaper, faster and more scalable influence infrastructure. From fake influencers to institutional influence Anthropic says it linked the operation to UAE government officials with high confidence. Its assessment was based partly on internal material naming senior Emirati officials as intended recipients of the work, alongside other evidence available to its investigators. That remains an attribution by Anthropic rather than a judicial finding or publicly released forensic attribution by a government agency. The distinction should be retained. The larger significance of GTG-84002 lies in the architecture of the campaign. A network of fake influencers could create the appearance of public opinion. A cloned human-rights organisation could provide institutional credibility. AI-generated reports could give political narratives the appearance of research. Profiles of journalists and politicians could support more precise targeting. And ghost-written testimony could potentially carry the same message into an international institution without revealing the political interest behind it. This is a different model from the familiar troll farm. The objective is no longer simply to make propaganda look popular. It is to make state-aligned messaging look independent – and, if possible, to move it from social media into the institutions where international policy and accountability are debated. SOURCES: Anthropic — Countering misuse of AI: September 2026 https://www.anthropic.com/threat-intelligence-report-september-2026 International Court of Justice — Sudan v. United Arab Emirates https://www.icj-cij.org/case/197 International Court of Justice — press releases and case documents https://www.icj-cij.org/case/197/press-releases United Nations Geneva — Sudan v UAE proceedings at the ICJ https://www.ungeneva.org/en/news-media/news/2025/04/105241/world-court-begins-hearing-sudans-complicity-genocide-case-against UAE Ministry of Foreign Affairs — UAE response to Sudan's allegations https://www.mofa.gov.ae/en/MediaHub/News/2025/4/10/10-4-2025-UAE-UAE UN Digital Library — Sudan's letter concerning alleged UAE support for the RSF https://digitallibrary.un.org/record/4091008?ln=en UN Digital Library — UAE response concerning allegations of support for the RSF https://digitallibrary.un.org/record/4046224?ln=en Ultra Sudan — reporting on Anthropic's UAE-linked influence-operation findings https://ultrasudan.usawtiq.com/أنثروبيك-أحبطنا-عملية-تأثير-إماراتية-استخدمت-الذكاء-الاصطناعي-لاستهداف-السودان/عامر-صالح/أخبار KEYWORDS #DISINFORMED #Episode8 #UAE #Sudan #UnitedArabEmirates #UnitedNations #UNHumanRightsCouncil #HumanRights #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #CoordinatedInauthenticBehaviour #CIB #FakeInfluencers #FakeNGO #NGOImpersonation #Astroturfing #ArtificialIntelligence #AI #AIPropaganda #AIGeneratedContent #SyntheticMedia #SocialMediaManipulation #DigitalInfluence #Propaganda #NarrativeManipulation #InstitutionalInfluence #SudanConflict #SudanWar #MuslimBrotherhood #InternationalRelations #Geopolitics #Anthropic #ClaudeAI #OSINT #WRLD

Countering misuse of AI: September 2026 / Anthropic

Russia’s fake African newsrooms – propaganda designed to look local A Facebook user in Nairobi, Accra, Johannesburg or Luanda encounters what appears to be a local news page. It publishes stories about African politics, Western influence and relations with Russia. The language is tailored to an African audience and the page presents itself not as a foreign broadcaster, but as part of the local information landscape. Behind some of these outlets, however, Meta found operators based in Russia. In its 2026 threat research, the company disclosed a Coordinated Inauthentic Behaviour network targeting audiences in Angola, Ghana, Kenya and South Africa. Meta removed 37 Facebook accounts and 29 Pages connected to the operation. Around 30,000 users followed at least one of the Pages, while the operators spent approximately $7,000 on Facebook and Instagram advertising, mostly in euros and US dollars. The numbers are relatively modest. The method is considerably more important. Rather than openly distributing Russian state messaging, the network posed as local African news sources and grassroots organisations, promoting narratives about Western colonialism and political interference while presenting Russia as a credible economic and political alternative. It was an old geopolitical message delivered through a much more effective identity: not Moscow speaking to Africa, but Africans apparently speaking to one another. A news outlet that was actually an influence operation Meta's investigation found that the network attempted to conceal its Russian origin while creating media brands that appeared indigenous to the countries they targeted. Its content amplified historical grievances against former colonial powers, criticised Western involvement in Africa and promoted closer relations with Russia. One example helps illustrate how the infrastructure was assembled. A Facebook Page targeting Kenya was called Kenya Watchtower. According to OpenAI's subsequent investigation, Facebook transparency records showed that the Page had previously been named “Farmtown5”. It appears to have been acquired or repurposed rather than built from scratch as a Kenyan news organisation. Some Pages also exposed administrator locations in Russia and Ukraine. Other elements of the network had previously targeted audiences in Zambia and Namibia. This use of apparently local identities is particularly important in the African information environment. A story published by RT or another identifiable Russian outlet arrives with an obvious geopolitical provenance. The same narrative presented by something resembling an independent Kenyan, Ghanaian or South African newsroom carries a different kind of credibility. The source appears closer to the reader, and the geopolitical interest behind the message becomes less visible. Then investigators found Dr Manuel Godsin The Facebook operation was only one part of a broader information ecosystem. OpenAI investigated related activity after receiving information from Meta and subsequently banned a ChatGPT account it assessed as likely originating in Russia. OpenAI called the campaign Operation No Bell. The account was being used to generate long-form articles and social-media posts about African geopolitics. Prompts were primarily written in English, but OpenAI also observed Russian-language instructions that the user described as coming from a manager. The operator sometimes explicitly asked the model to make the material appear less AI-generated – including requests to avoid stylistic features associated with machine-generated text and to write more like a human journalist. Many articles appeared under the name “Dr Manuel Godsin”, presented as an academic with a PhD from the University of Bergen and an affiliation with an organisation called the International Centre for Political and Strategic Studies. OpenAI could find no credible evidence that Godsin existed. Searches of Norway's National Research Information Repository and the University of Bergen library produced no record of him. Investigators subsequently discovered that a photograph used to represent Godsin had appeared years earlier on a Russian professional networking site and apparently belonged to a law student in St Petersburg. The fabricated academic identity was nevertheless remarkably productive. OpenAI identified 53 online articles carrying the Godsin byline. The fiction had moved beyond fake social-media pages and into the real media ecosystem. When propaganda enters genuine newsrooms This is the most consequential aspect of the operation. The articles were not confined to websites controlled by the influence network. Some were published by genuine African news organisations, including established South African outlets. The content mixed local political issues with broader geopolitical narratives. Some pieces criticised the United States and Britain or defended Russia's role in Africa. One accused the British NGO Crisis Action of fomenting protests in South Africa. Another praised Russia's presence in the Central African Republic. Other material addressed Kenya, Angola and relations between African governments and Washington. The mechanism represents a significant evolution from the classic troll-farm model. Instead of building an audience entirely on its own platforms, an influence operator can manufacture an apparently credible expert, generate articles in his name and persuade genuine news organisations to publish them. Once this happens, the propaganda acquires something a fake Facebook Page cannot provide: the institutional credibility of a real newsroom. OpenAI assessed No Bell's social-media impact as limited. One Facebook Page had around 3,000 followers before Meta removed it, while several others had very small audiences. But the operation was more successful in placing material in established media. In OpenAI's impact framework, it approached the level at which an influence operation breaks into mainstream media. For information operators, a single article published by a recognised outlet can potentially be more valuable than thousands of impressions generated by an obviously artificial account. A much larger network of ghost journalists Subsequent research suggests that Manuel Godsin was not an isolated experiment. In August 2026, Graphika, working with Code for Africa and with support from Meta, published a much broader investigation into Russian ghostwriting operations across African media. Researchers identified 44 ghost writers and fake experts, 38 of them assessed as high-confidence fabricated personas, operating between 2021 and 2026. Their material appeared or was quoted across 138 websites and was subsequently republished through at least 113 Facebook accounts and Pages, including authentic users, coordinated inauthentic networks and official Russian communication channels. The narratives were strikingly consistent. They included criticism of France, Ukraine and the United States; attacks on organisations such as ECOWAS and the International Criminal Court; positive portrayals of Russian involvement in Africa; praise for Russian paramilitary forces; and support for sovereignty-oriented political projects such as the Alliance of Sahel States. The operation therefore extends beyond creating fake news websites. It attempts to insert Russian-aligned narratives into the legitimate African media ecosystem using identities that appear African, independent or academically authoritative. This also explains why measuring reach through the original Facebook network alone is misleading. A fabricated article may begin with an influence operator, appear in a genuine African publication, be republished elsewhere and eventually circulate without any visible connection to Russia. At that point, the provenance of the narrative has effectively been laundered. An old Russian strategy with increasingly local faces Russia's use of local intermediaries in Africa is not new. Meta documented Russian networks using African nationals as early as 2019. In 2020 it dismantled another operation involving people in Ghana and Nigeria working on behalf of individuals in Russia, with links to previous activity associated with the Internet Research Agency. More recent Meta investigations suggest that this model has continued to evolve. Networks have increasingly relied on local freelancers, social-media managers and authentic media outlets rather than exclusively operating armies of obviously fake Russian-controlled accounts. This decentralisation offers several advantages. Local operators understand language, political sensitivities and cultural references. Authentic accounts are harder to identify than newly created synthetic personas. Local media brands can also deliver narratives without immediately triggering the scepticism associated with Russian state outlets. There is no evidence that every African journalist, freelancer or publication carrying such material knowingly participates in Russian influence activity. Meta explicitly notes in its investigations that some local contractors may not know who ultimately commissioned their work. That distinction is essential. The operation's effectiveness partly depends on precisely this ambiguity between deliberate participation, commercial content placement and unwitting amplification. The objective is to make Russian narratives look African The significance of this network is therefore not its 30,000 Facebook followers or its $7,000 advertising budget. Those figures are small compared with the audiences of major African media organisations. What matters is the distribution model. Traditional foreign propaganda asks an audience to trust a foreign source. These operations attempt to remove the foreign source from the equation altogether. A Russian geopolitical narrative can be generated with AI, attributed to an expert who does not exist, published by a media organisation that does, amplified through a Facebook Page presenting itself as local, and then rediscovered elsewhere as apparently independent African analysis. By the time the reader encounters it, Moscow may have disappeared completely from the chain of attribution. The resulting information operation is therefore less about making Russian propaganda more persuasive than about making it look as though it is no longer Russian propaganda at all. In an increasingly fragmented African media environment, that may be the more important evolution to watch. SOURCES: Meta Threat Research https://threatresearch-team.github.io/indicators/meta-h1-2026-russia-based-cib-network-1/ OpenAI — Operation “No Bell” https://openai.com/index/disrupting-malicious-uses-of-ai-no-bell/ Graphika — Umbrae Ex Machina https://www.graphika.com/reports/umbrae-ex-machina News24 https://www.news24.com/southafrica/news/ai-expert-exposed-fake-kremlin-linked-analyst-planted-stories-in-african-media-20260318-0560 Vanguard https://www.vanguardngr.com/2026/03/ai-expert-exposed-fake-kremlin-linked-analyst-planted-stories-in-african-media/ Meta — Russian Coordinated Inauthentic Behaviour, 2019 https://about.fb.com/news/2019/10/removing-more-coordinated-inauthentic-behavior-from-russia/ Meta — Russian Coordinated Inauthentic Behaviour, 2020 https://about.fb.com/news/2020/03/removing-coordinated-inauthentic-behavior-from-russia/ Meta Threat Research — Russian Use of Authentic Operators in Sub-Saharan Africa https://threatresearch-team.github.io/indicators/meta-h2-2025-russia-based-cib-network-2/ KEYWORDS: #DISINFORMED #Episode7 #Russia #Africa #RussianDisinformation #RussianInfluence #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #CoordinatedInauthenticBehaviour #CIB #FakeNews #FakeMedia #FakeNewsrooms #MediaImpersonation #GrassrootsManipulation #Astroturfing #ArtificialIntelligence #AI #AIPropaganda #SyntheticMedia #FakeInfluencers #SocialMediaManipulation #Facebook #Meta #OperationNoBell #AfricanMedia #MediaManipulation #Propaganda #DigitalInfluence #Angola #Ghana #Kenya #SouthAfrica #OSINT #WRLD

Russia-Based Influence Operation Network Targeting Sub-Saharan Africa

Storm-1516 – Russia’s information war arrives early in France’s 2027 election France will not elect its next president until April 2027, but the information operations surrounding the campaign have already begun. In late July and August 2026, fabricated stories targeted several prominent figures associated with the presidential race, including Raphaël Glucksmann, Gabriel Attal and former prime minister Édouard Philippe. The methods included fake news websites copying established French media, impersonated journalists, AI-generated voices and manipulated video. French authorities identified the Russian operation known as Storm-1516 behind several of these campaigns. Other attacks were linked to Matryoshka, another Russia-aligned influence network. The timing is significant. Storm-1516 began targeting the French presidential environment roughly nine months before the first round, scheduled for 18 April 2027. Rather than a single disinformation campaign, the activity demonstrates how Russian influence networks can establish narratives and infrastructure long before an election reaches its decisive phase. A fake scandal targeting Raphaël Glucksmann One of the clearest examples appeared at the end of July. A website impersonating the French independent outlet Blast published a fabricated investigation claiming that journalist Léa Salamé had attempted to bribe media organisations in exchange for favourable coverage of her partner, Raphaël Glucksmann. The operation went beyond copying the appearance of a legitimate news site. The identities of real journalists were appropriated and a manipulated video used an AI-generated imitation of the voice of Edwy Plenel, founder of Mediapart, supposedly confirming the allegations. The accusation was false. On 4 August, Glucksmann said France's General Secretariat for Defence and National Security, the SGDSN, had informed him that he had been targeted by Storm-1516. Two days later, the Paris prosecutor's office opened an investigation into suspected Russian interference. The importance of the operation was not the quality of one particular deepfake but the construction of several mutually reinforcing elements: a fake media organisation, impersonated journalists, synthetic audio and social-media accounts distributing the material. Together they created the impression that the allegation had been independently corroborated. Different candidates, overlapping Russian networks Édouard Philippe was also targeted by fabricated stories claiming that he suffered from dementia and was medically incapable of running for president. VIGINUM attributed the operation to Storm-1516. Gabriel Attal faced another wave of false content, including fabricated stories mimicking the identities of French outlets such as RFI, BFM TV, France 24, AFP, Le Parisien, Libération and Le Monde. Some claimed that Attal had symptoms of Parkinson's disease or links to drug trafficking. Attribution here is more complicated. French reporting connected at least part of the campaign against Attal to Matryoshka, rather than Storm-1516. A later digitally manipulated video, apparently associated with Storm-1516, used genuine LCI footage from an August debate but added a white earpiece to Attal, suggesting that someone had secretly been feeding him answers. NewsGuard compared the circulating clip with authentic LCI footage and found no earpiece in the original. The distinction is important. France is not facing a single Russian propaganda operation but several overlapping networks using similar techniques and narratives. Treating every manipulation as Storm-1516 would obscure how this ecosystem actually functions. The real weapon is media impersonation The most interesting feature of Storm-1516 is not artificial intelligence itself. It is the systematic appropriation of the credibility of established journalism. Instead of relying only on anonymous Telegram channels or social-media profiles, operators create material that looks as though it originated from organisations audiences already recognise. A fabricated investigation can resemble Blast, a manipulated television report can borrow LCI's visual identity, while fake journalists and social-media accounts provide additional layers of apparent confirmation. VIGINUM has documented this architecture extensively. Its 2025 investigation analysed 77 Storm-1516 information operations and described a mature Russian system using fabricated media, websites and distribution networks to promote anti-Ukrainian and anti-Western narratives. The European External Action Service found that the infrastructure continued to expand. According to its 2026 FIMI Threat Report, Storm-1516 almost doubled its output during 2025. Five networks created that year to target French, German, American, Moldovan and international audiences comprised 453 websites, including fictional news organisations and sites impersonating genuine media or political platforms. A typical operation therefore follows a recognisable pattern: a fabricated allegation is supported by synthetic or manipulated evidence, published through an apparently legitimate source and then distributed by networks of accounts that create the appearance of wider discussion. AI makes this process faster and cheaper, but the fundamental objective remains the same – to manufacture credibility. Why begin nine months before an election? VIGINUM concluded that Storm-1516 is capable both of reacting rapidly to current events and of conducting longer campaigns aimed at discrediting Western institutions and public figures, particularly around elections and other major political events. This provides important context for France. Storm-1516 activity around the presidential race became visible in July 2026, approximately nine months before voting begins. There is no public evidence of a predetermined Russian “nine-month plan”, and the timing should not be presented as such. Early activity nevertheless provides operational advantages: narratives can be tested, websites and accounts established, audience reactions measured and the responses of journalists, authorities and fact-checkers observed. The first operations may therefore also provide information about which themes and techniques are most effective before the campaign enters its decisive months. This remains an analytical interpretation rather than a demonstrated statement of the operators' intentions. Russian operation, but what about the GRU? Attribution requires similar precision. VIGINUM explicitly describes Storm-1516 as a Russian information operation, and French authorities have attributed individual campaigns to it with high confidence. Connections with Russian military intelligence have also been reported. Glucksmann said the SGDSN informed him that the network targeting him was controlled by Russia's GRU, while French media have repeatedly described Storm-1516 as linked to Russian military intelligence. However, VIGINUM's publicly available technical documentation describes Storm-1516 primarily as a Russian information modus operandi, rather than identifying it as a formally established GRU unit. It is therefore well supported to describe Storm-1516 as a Russian influence operation with reported links to military intelligence. Saying simply that Storm-1516 is a GRU unit would go beyond what France's published technical evidence currently establishes. An early warning for the French election There is also no evidence that the operations have so far had a significant effect on French voters. Some of the fabricated material generated only limited engagement, and measuring the real impact of foreign information operations remains extremely difficult. Even a video attracting hundreds of thousands of views does not establish how many viewers believed it or whether it changed political attitudes. The significance of Storm-1516 lies instead in the infrastructure already being deployed. Months before the election, Russian influence networks have been able to test fake newsrooms, synthetic voices, manipulated television footage, candidate-specific narratives and systems for distributing them. The French case illustrates a broader evolution in election interference. The objective is no longer simply to place false claims on social media. Modern operations can manufacture an entire chain of apparent evidence in which a fake journalist cites a fake investigation, synthetic audio appears to confirm it and networks of accounts give the impression that an authentic controversy is unfolding. France still has months to go before its presidential election. The information environment surrounding it is already being contested. Sources: VIGINUM / SGDSN — Storm-1516 analysis https://www.sgdsn.gouv.fr/publications/analyse-du-mode-operatoire-informationnel-russe-storm-1516 VIGINUM / SGDSN — Full Storm-1516 technical report https://www.sgdsn.gouv.fr/files/files/Publications/20250507_TLP-CLEAR_NP_SGDSN_VIGINUM_Technical%20report_Storm-1516.pdf VIGINUM / SGDSN — Storm-1516 operation targeting Emmanuel Macron https://www.sgdsn.gouv.fr/publications/storm-1516-detection-dune-operation-dingerence-numerique-etrangere-ciblant-emmanuel EEAS — 4th Report on FIMI Threats https://www.eeas.europa.eu/sites/default/files/2026/documents/EEAS%204th%20Threat%20Report_web.pdf Le Monde — Russian interference targeting Philippe, Glucksmann and Attal https://www.lemonde.fr/politique/article/2026/08/07/presidentielle-2027-glucksmann-attal-philippe-les-ingerences-russes-s-invitent-dans-la-campagne_6740451_823448.html Le Monde — Storm-1516 and Matryoshka analysis https://www.lemonde.fr/pixels/article/2026/08/06/ingerences-russes-pourquoi-il-ne-faut-pas-nourrir-le-troll_6739956_4408996.html NewsGuard Risk Briefing — Russian activity targeting the French election https://newsguardriskbriefing.substack.com/p/russia-targets-french-elections-iran Euronews — Operation targeting Raphaël Glucksmann https://fr.euronews.com/my-europe/2026/08/04/presidentielle-de-2027-raphael-glucksmann-vise-par-une-operation-de-destabilisation-russe Télérama / AFP — Glucksmann deepfake investigation https://www.telerama.fr/debats-reportages/presidentielle-2027-raphael-glucksmann-vise-par-un-deepfake-d-origine-russe-7032318.php Le Parisien — Operation targeting Gabriel Attal https://www.leparisien.fr/elections/presidentielle/presidentielle-2027-gabriel-attal-a-son-tour-vise-par-une-ingerence-en-provenance-de-russie-05-08-2026-I3Z67Z7ZUBDUVBXUNDARI5KGPA.php Euronews — Paris prosecutor investigations into suspected Russian interference https://fr.euronews.com/my-europe/2026/08/18/soupcons-dingerence-russe-visant-attal-et-philippe-le-parquet-de-paris-ouvre-dune-enquete Keywords: #DISINFORMED #Episode6 #Storm1516 #France #FrenchElection2027 #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #RussianInfluence #RussianDisinformation #Propaganda #Deepfakes #ArtificialIntelligence #AI #SyntheticMedia #FakeNews #MediaImpersonation #FakeMedia #DigitalManipulation #ElectionInterference #PoliticalDisinformation #Matryoshka #VIGINUM #OSINT #CyberInfluence #DigitalInfluence #MediaManipulation #EuropeanSecurity #Democracy #WRLD

Analyse du mode opératoire informationnel russe Storm-1516 | SGDSN

The Ghosts of Zaolzie – how a cyberattack tried to manufacture a conflict between Poland and Czechia At around 5pm on 16 August 2026, an alarming article appeared on the website of Radio PiK, a genuine Polish regional broadcaster. Its headline claimed that Poland was preparing to seize Czech territory and that the Czech Foreign Ministry had received a document outlining Warsaw's demands. Radio PiK had published no such story. An attacker had compromised an employee's credentials, gained access to the station's content management system and replaced a legitimate article with fabricated material. The newsroom quickly removed it and informed the authorities. But the intrusion was only one element of a much larger operation. Investigators subsequently uncovered forged diplomatic documents, accounts impersonating Polish and Czech officials, a cloned Czech news site, AI-generated material, a fictitious local activist and advertising for a demonstration that apparently did not exist. Together, these elements attempted to manufacture the appearance of a new territorial conflict between Poland and Czechia over Zaolzie. A false crisis built around a real territorial issue The operation worked because it did not start entirely with fiction. Poland and Czechia do have an unresolved technical issue concerning approximately 368.44 hectares of territory, originating in post-war changes to the Polish-Czechoslovak border. It is commonly described as the Czech “territorial debt” to Poland. But this is not a Polish claim to Zaolzie and there is no evidence that Warsaw is seeking to annex Czech territory. The operation fused this real issue with a much more powerful historical memory. Zaolzie – the part of Cieszyn Silesia west of the Olza River – was disputed by Poland and Czechoslovakia after the First World War. In 1938, during the crisis created by the Munich Agreement, Poland seized the territory from Czechoslovakia. The manipulation therefore followed a simple logic: a real territorial debt became an alleged Polish territorial demand, which was then transformed into a supposed attempt to reclaim Zaolzie. Fake accounts impersonating Poland's Deputy Foreign Minister Artur Harazim and Czech ambassador Břetislav Dančák helped reinforce the story. Fabricated diplomatic documents circulated alongside them. One early version referred incorrectly to 638.44 hectares; the fake Harazim account then “corrected” the number to the genuine figure of 368.44 hectares. It was an effective form of reverse fact-checking: correcting one false detail could make the larger fabrication appear authentic. Fake media – and one real newsroom The operators also created a website designed to resemble Czech public broadcaster iRozhlas. It published material supporting the same narrative, including claims that Czech residents near the border were becoming concerned about Polish intentions. The result was a manufactured information loop. Forged documents could support fake media reports; impersonated officials could comment on those reports; social-media accounts could then cite both as confirmation. But the Radio PiK hack added something much more valuable: the credibility of a real media organisation. Instead of merely cloning a newsroom, the attackers briefly inserted their fabrication into an authentic one. A familiar domain, logo and established broadcaster could therefore appear to confirm a story manufactured elsewhere. The cyberattack was not simply an accompanying technical incident. It was part of the information operation itself – a way of manufacturing credibility for false information. From a synthetic activist to a real demonstration The operation then attempted to move from the digital world into the physical one. A Facebook account under the name “Adam Sikora” promoted a demonstration in the Czech border city of Třinec under slogans including “Cieszyn Silesia is Czech” and “Here we live, here we stay”. Paid Facebook advertising was reportedly used to promote the event. Yet Třinec authorities said no demonstration had been properly notified. Promotional material used the logo of the Czech KOVO trade union, which denied any involvement. Investigators also identified indications that Sikora's profile photograph and other imagery were AI-generated. The persona even advertised a supposed house for sale in the border region, reinforcing the impression that frightened residents wanted to leave because of Polish territorial ambitions. The property could not be verified and its images also showed signs of artificial generation. This reveals the architecture of the operation: forged document → fake official → cloned media → compromised real media → synthetic local activist → advertised protest → appearance of social tension. The final stage is particularly significant. Had real people attended the demonstration, photographs of an authentic crowd could potentially have been presented as evidence that Czech citizens genuinely feared Polish territorial ambitions. A fabricated online conflict could therefore have begun generating real-world evidence of its own existence. Why Zaolzie? Historical grievances are valuable material for influence operations because the underlying facts are real. Poland and Czechoslovakia genuinely disputed Cieszyn Silesia. Poland genuinely occupied Zaolzie in 1938. A Polish minority genuinely lives in Czechia. And the 368.44-hectare territorial issue genuinely exists. The operator did not need to invent that history. It only needed to suggest that the history was repeating itself. PISM assessed that the operation sought to revive the image of Poland as a revisionist state willing to challenge European borders. Such a narrative could serve a broader purpose: damaging Polish-Czech relations, weakening confidence between NATO and EU allies and portraying Central Europe as a region where historical territorial conflicts remain unresolved. Russia is the leading attribution – but not a proven one The attribution requires more caution than the mechanics of the operation. PISM assessed Russia as the most likely perpetrator, while NASK identified similarities between the campaign and previously observed Russian influence methods. Russian-linked information infrastructure had also shown earlier interest in the Polish-Czech territorial issue. The techniques are familiar: cloned media, forged documents, impersonated officials, synthetic identities, historical grievances and the combination of cyber intrusion with information manipulation. But these indicators are not the same as definitive attribution. As of mid-September 2026, no publicly disclosed forensic evidence had conclusively connected the Radio PiK compromise, fake domains, accounts and financing to a specific Russian intelligence service, government organisation or contractor. Russia can therefore reasonably be described as the leading analytical attribution, but claims that the operation was definitively conducted by the GRU or another named Russian structure go beyond the publicly available evidence. The operation failed. The model remains important The campaign did not create a Polish-Czech diplomatic crisis. Both governments rejected the narrative, the fictitious protest was exposed, journalists reconstructed much of the operation and Radio PiK detected the intrusion quickly. Its observable impact appears to have been limited. But Zaolzie illustrates a broader evolution in information warfare. Modern operations do not have to rely on a single viral fake. They can construct an entire artificial information environment in which different elements appear to confirm one another. A forged document creates the claim. A fake diplomat authenticates it. A cloned newsroom reports it. A hacked real newsroom lends it credibility. An AI-generated citizen reacts to it. Advertising creates the appearance of a grassroots movement. And if real people eventually respond, fiction begins producing genuine events. The objective is no longer simply to persuade people that something happened. It is to create the conditions in which something real starts happening because enough people believed that it did. Sources: Polish Institute of International Affairs (PISM) https://pism.pl/publikacje/dezinformacja-o-relacjach-polsko-czeskich Euronews Polska — Radio PiK cyberattack https://pl.euronews.com/2026/08/20/polska-planuje-zajecie-terytorium-czech-wlamali-sie-na-strone-radia-i-opublikowali-falszyw Demagog https://demagog.org.pl/na-biezaco/skoordynowana-operacja-uderza-w-polsko-czeskie-relacje-czy-stoi-za-nia-rosja/ Robert Lansing Institute https://lansinginstitute.org/2026/08/27/zaolzie-as-an-instrument-of-influence-an-attempt-to-revive-a-polish-czech-territorial-conflict/ Institute for European Security Studies (IESS) https://www.iess.org.ua/analytics/ghosts-of-zaolzie iDNES.cz https://www.idnes.cz/ostrava/zpravy/tesinsko-kampan-lzi-demonstrace-trinec-primatorka-palkovska.A260826_963356_ostrava-zpravy_jog Radio Zachód / PAP https://zachod.pl/1539751/niedzielny-atak-hakerski-na-radio-pik-redaktor-naczelny-podjelismy-niezwloczne-dzialania/ Euronews — territorial debt / NASK assessment https://de.euronews.com/my-europe/2026/08/21/polen-plant-besetzung-tschechischen-gebiets-fake-news TVP World https://tvpworld.com/95036191/-warsaw-warns-against-division-amid-czech-border-disinformation Keywords: #DISINFORMED #Episode5 #GhostsOfZaolzie #Zaolzie #Poland #Czechia #CieszynSilesia #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #Cyberattack #CyberSecurity #HybridWarfare #FakeNews #MediaImpersonation #FakeMedia #ForgedDocuments #DigitalImpersonation #ArtificialIntelligence #AI #Deepfakes #SyntheticMedia #Astroturfing #RussianInfluence #Propaganda #OSINT #NATO #CentralEurope #MediaManipulation #WRLD

Mali – a war where some of the people fighting do not exist In Mali's war, an apparently simple question is becoming increasingly difficult to answer: who exactly is speaking to us? A real person? A rebel organisation? A Russian influence operation? A supporter of the military junta? Or somebody who has never existed at all? In September 2026, the Dakar-based Timbuktu Institute published Des algorithmes en guerre, a report examining the use of generative artificial intelligence by actors involved in the Malian conflict. Its researchers describe the country as a potential laboratory for AI-assisted information warfare. Separatist networks are deploying synthetic fighters on TikTok. Jihadist propagandists are experimenting with AI-generated imagery. Pro-government accounts are producing large quantities of content celebrating the Malian armed forces. Russia, meanwhile, operates the most developed influence infrastructure of all: pseudo-media outlets, inauthentic accounts, AI-generated text, images and video, and systems designed to artificially amplify their visibility. Artificial intelligence did not create Mali's conflict. The war has been under way since 2012, and its participants have always fought with propaganda as well as weapons. What AI has changed is the economics of that struggle. A new “witness”, commentator, fighter, poster or video can now be produced in minutes. For audiences watching from a phone, distinguishing between genuine documentation, propaganda and material created entirely by an algorithm is becoming progressively harder. Azzghim – the fighter who cannot be killed or interrogated The most striking case documented by the Timbuktu Institute involves accounts associated with supporters of the Azawad Liberation Front, or FLA, a Tuareg separatist movement fighting the authorities in Bamako. A figure called “Azzghim” appeared on TikTok. He looks like a Tuareg fighter and regularly features in videos attacking Mali's government and Russia's Africa Corps, commenting on the conflict and promoting the cause of Azawad. There is one problem: Azzghim does not exist. Analysis of the videos identified anomalies characteristic of generative AI, including unnatural body movements, visual inconsistencies, irregular colouring and problems with audio synchronisation. According to the Timbuktu Institute, Azzghim is a synthetic character being used as the digital face of a political narrative. The propaganda advantages are considerable. An organisation no longer needs to expose a real spokesman. A synthetic personality can be designed to look exactly as its creators require, speak the appropriate language and appeal to a particular audience. Different characters could potentially be created for younger viewers, traditional communities or different ethnic and social groups. There is another advantage: a synthetic spokesman cannot be arrested, identified or interrogated. Researchers also identified accounts amplifying the material. At the time of the study, TikTok account @tawri.n.azawad had around 207,000 followers and was almost entirely devoted to publishing or repackaging content involving Azzghim. Another account, @asnan831, used a similar synthetic teenage character. An important distinction is necessary. Researchers describe these profiles as belonging to supporters or individuals associated with the FLA. The available evidence does not establish that every account is part of an operation centrally directed by the Front's leadership. The information effect, however, remains significant: a digital community can be constructed around the Azawad cause in which some of the apparent participants may not be real people at all. The jihadists are learning too The picture is different for Jama'at Nusrat al-Islam wal-Muslimin, or JNIM, the al-Qaeda-affiliated coalition that has become one of the most powerful armed groups in the Sahel. Its confirmed use of generative AI remains considerably less sophisticated. In June 2026, JNIM's Az-Zallaqa media apparatus published AI-generated posters promoting material about previous attacks. The images showed fighters in combat but contained familiar generative artefacts: buildings and vegetation merging unnaturally, blurred details and unnaturally smooth surfaces. More important than JNIM's current capabilities is what AI could add to an already sophisticated propaganda apparatus. The organisation already tailors communications to different audiences. UN reporting has documented its use of media channels for broader propaganda while other outlets increasingly distribute material in local languages, including Bambara. Generative AI could dramatically reduce the cost of this strategy, translating material into Fulfulde, Hausa, Zarma or Tamasheq, generating synthetic dubbing and producing multiple versions of the same message. The Timbuktu Institute also considers the future possibility of AI chatbots being used to personalise recruitment. That should not be presented as a capability JNIM has already demonstrated. At present, it is a risk scenario rather than a confirmed operation. Russia has the most sophisticated machine At the other end of the spectrum lies Russia's influence ecosystem. Here, AI is not an isolated experiment but another component of an infrastructure previously developed by Wagner-linked networks, Russian media operations and influence organisations operating across Africa. After Wagner's withdrawal from Mali in 2025, its military role was taken over by the Russian state-controlled Africa Corps. The information infrastructure evolved alongside it. Of particular importance is African Initiative, which presents itself as a news agency but has been identified by France's VIGINUM, the UK's Foreign, Commonwealth & Development Office and the European External Action Service as an important component of Russia's newer influence architecture in Africa. One of the most interesting elements of this ecosystem is a network researchers call AI-Freak. The operation uses generative AI to produce text, images and videos, places them on fake or apparently independent news websites and distributes them through inauthentic accounts. This is supplemented by so-called Black Hat SEO – techniques intended to artificially increase the visibility of content in search engines. Elements of this infrastructure have previously been identified by Meta and OpenAI. In 2024, OpenAI disrupted Russian accounts using ChatGPT to generate articles and comments in English, French and Russian. Some of the French-language content targeted audiences in West Africa. In a later iteration of the operation, AI models were also used to draft scripts for short videos praising the Russian Africa Corps, translate them into French and generate descriptions optimised for social media. This illustrates an important difference between the Russian approach and Azzghim. The separatist ecosystem uses AI primarily to manufacture convincing digital personalities. The Russian model increasingly resembles an industrial production line: text, image, video, pseudo-news website, distribution account, search optimisation and additional channels amplifying the narrative. The objective is not merely to convince someone of a single claim. It is to occupy as much of the information environment as possible with narratives advantageous to Moscow: Russia as an effective security partner, the West as a neo-colonial aggressor, France as a source of instability and Russian forces as defenders of African sovereignty. Yet VIGINUM also warns against equating technological sophistication with actual impact. Some Russian influence channels still attract relatively small audiences. A sophisticated operation is not automatically a successful one. The junta is building its own digital reality Mali's military authorities operate within the same contested information environment. Since breaking with France and moving closer to Moscow, Bamako has increasingly restricted independent media space while promoting a narrative built around restored sovereignty, military success and the benefits of its Russian partnership. The Timbuktu Institute highlights the TikTok account @6tm_officiel. At the time of the study, it had more than 436,000 followers and published substantial amounts of AI-generated material presenting Mali's armed forces, the FAMa, and the Africa Corps in a favourable light. One video concerning the battle for Kidal accumulated around 4.7 million views. Again, attribution requires care. Researchers describe the account as being operated by an individual based in Bamako; they do not provide evidence that it is officially managed by the Malian government. It is better understood as part of a wider pro-government information ecosystem in which the boundaries between state communications, supporters and co-ordinated propaganda can be difficult to establish. The Africa Center for Strategic Studies has previously identified the military regimes in Mali and Burkina Faso as important sources of disinformation campaigns in West Africa. Recurring narratives target France, the United Nations, ECOWAS, human-rights organisations and independent media, while presenting criticism of the authorities as part of a foreign conspiracy. Generative AI allows such narratives to be produced faster, more cheaply and in far more variations. Everyone is fighting over a different version of the same war What makes Mali particularly revealing is that multiple actors are using similar technology for very different objectives. FLA-linked networks need digital faces capable of humanising the Azawad cause and attacking Russia's presence. JNIM needs propaganda material and increasingly localised communications. The pro-government ecosystem seeks to portray Mali's armed forces as victorious and reinforce the junta's legitimacy. Russia possesses the broadest infrastructure, in which AI is merely one component of a larger system involving media outlets, websites, local partners, social-media profiles and technical amplification. The result is a war taking place simultaneously in two realities. In the first, soldiers and civilians are killed, towns change hands and the army, separatists and jihadists fight for territory. In the second, every side is trying to determine what the first reality will look like on a smartphone screen. Generative AI does not need to create a perfect deepfake to be effective. It merely needs to increase the number of competing versions of events until an ordinary viewer can no longer easily determine which one deserves to be trusted. That is why Mali matters. It is not showing us the future of information warfare. It is showing us its present. One TikTok video may feature a real soldier. Another may feature a propagandist. A third may feature a fighter who has never existed. And all three can tell completely different stories about the same war. Sources Timbuktu Institute – Des algorithmes en guerre: Comment l'IA générative rebat les cartes du conflit malien https://timbuktu-institute.org/index.php/toutes-l-actualites/item/1731-rapport-des-algorithmes-en-guerre-comment-l-ia-generative-rebat-les-cartes-du-conflit-malien AfricaNews/AFP – “Mali's information war is increasingly being shaped by AI” https://www.africanews.com/2026/09/09/malis-information-war-is-increasingly-being-shaped-by-ai/ OpenAI – research on Russia-origin influence activity and Operation Stop News https://openai.com/index/disrupting-malicious-uses-of-ai-stop-news-2024/ VIGINUM / FCDO / EEAS – technical report on African Initiative and the AI-Freak network https://www.sgdsn.gouv.fr/files/files/Publications/20250612_TLP-CLEAR_VIGINUM_FCDO_EEAS_Technical_Report_African_Initiative_EN.pdf Africa Center for Strategic Studies – Mapping a Surge of Disinformation in Africa https://africacenter.org/spotlight/mapping-a-surge-of-disinformation-in-africa/ Timbuktu Institute – analysis of AI use by JNIM https://timbuktu-institute.org/index.php/toutes-l-actualites/item/1735-artificial-intelligence-a-new-propaganda-lever-for-jnim-in-mali?print=1&tmpl=component #Disinformation #Mali #Sahel #Africa #ArtificialIntelligence #AI #GenerativeAI #AIPropaganda #InformationWarfare #InfluenceOperations #Propaganda #Deepfakes #SyntheticMedia #Azawad #FLA #JNIM #AfricaCorps #Russia #RussianInfluence #TikTok #DigitalWarfare #MediaManipulation #WRLD

Rapport - DES ALGORITHMES EN GUERRE : Comment l'IA générative rebat les cartes du conflit malien

BREAKING: dit verandert alles. Ik ben laaiend enthousiast. Kunnen we überhaupt nog zíén dat een machine deze beelden heeft gemaakt?👇 Mijn droom om m'n thriller "Delirium" tegen de achtergrond van de moord op filmmaker Theo van Gogh te verfilmen, begint nu eindelijk werkelijkheid te worden. Een conventionele verfilming werd in 2012 nog op circa €10 miljoen begroot. Dankzij AI cinema verwacht ik de film voor minder dan €50.000 te kunnen realiseren. In deze test bespreken Michael Scott, Jim Halpert en Dwight Schrute uit The Office (oorspronkelijk gespeeld door Steve Carell, John Krasinski en Rainn Wilson) m'n filmpitch voor Delirium. Wat vinden jullie? #AI #Cinema #AICinema #AIFilm #AIFilmmaking #AIVideo #GenerativeAI #AITech #MiniMaxH3 #HailuoAI #AIStorytelling #FutureOfFilm #FutureOfCinema #VirtualProduction #SyntheticMedia #IndieFilm #FilmTwitter #TheOffice #DeliriumFilm #LucidDreamPro #erickoverveen #film #cinema #AI #Cinema #IndieFilm