Bit of a spike in X followers for Iran's foreign minister.
Decided to take a look after seeing accounts like Kim Dotcom's advocate for people to follow him.
Bit of a spike in X followers for Iran's foreign minister.
Decided to take a look after seeing accounts like Kim Dotcom's advocate for people to follow him.
Since the conflict in Iran began on 28 Feb, ISD has been tracking narratives from Russian, Iranian or Chinese-state backed and state-linked actors on social media. Our second update below β¬οΈ
A month after 1516 targeted Macron with Epstein lies, they go after Zelensky. They really don't like Macron.
There's a war happening, but Russian IOs are going local today. Here's 1516 targeting a mayoral race in France, and Overload has been targeting local elections in Germany.
Itβd be a good time to have CrowdTangle.
Yeah, I get it's complicated. I just think it's funny after all the talk of China becoming the global AI leader that they're continually using Western models.
That could change in the future, and I could get better at snark.
If DeepSeek is such a Chinese threat, why aren't Chinese threat actors sticking to it?
edition.cnn.com/2026/02/25/p...
My X account is such a cesspool of pro-Iran AI content that I don't even know where to begin research. It's the worst I've ever seen my algorithm.
In the recent weeks our team identified several disinformation campaigns around the upcoming parliamentary election in Hungary, which appear to be conducted by the Storm-1516 operators. The election seem to be critical for the rule of Viktor Orban, the biggest Russian ally in EU
Wow. In ten minutes of scrolling X, my For You page served me three Overload posts and a Storm-1516 post.
That's insane. What a megaphone for Russian info ops.
Overload has been grabbing Cameo videos from random celebrities and using AI audio to make it sound like they're calling for Zelensky to be killed. Those videos have been on X for five days now. Absolutely wild.
H/t @ushadrons.bsky.social, who spotted this last week.
Really interesting alleged leak from a former Prigozhin project now tied to the SVR. One thing jumped out to my nerd brain:
The mention an op targeting the French firm Orano, which was active in Niger. Back in 2024, Storm-1516 circulated disinfo about Oranoβs role in Niger. Quite a coincidence.
This isn't getting near enough attention.
Within the span of a week, Russia's most sophisticated information operation laundered two narratives through Chinese state media.
Seems like a signal that Russia and China are willing to cooperate more closely on IOs?
Operation Overload runs the same play over and over. It's lazy clockwork.
Here's a claim from a few days ago next to a claim from last year. They look a lot alike.
Finally, we have a definitive answer to the question of whether AI, bots, and laundering tactics will improve Chinaβs information operations.
The answer is no.
Among the many reasons you donβt kidnap a foreign head of state at gunpoint even if you have the capability, is that it sparks consequences you can neither control nor anticipate.
The US TikTok sale has been signed. The company will be controlled by a joint venture including Oracle, Silver Lake, Andreessen Horowitz, Abu Dhabi-based MGX. Adding a UAE company really makes it clear that this was never about national security concerns.
www.axios.com/2025/12/18/t...
Graphika recently reported on a pro-CCP network attacking Missouri AG Catherine Hanaway. Finding the network wasn't hard. It's using the hashtag FuckHanaway.
Here's what else it's talking about. I should stress, though, that no one is listening. The engagement is tragically low.
Big spike in articles published by the Pravda Network site focused on Australia.
More than 400% increase from Dec 13 to Dec 14.
I believe this is Iran's Storm-2035 making a push against the Trump administration's actions against Venezuela by using the hashtag ElMundoRepudiaATrump on X.
Several of these accounts are confirmed 2035.
Meta's Threat Report essentially declared the end of Iran's Endless Mayfly operation, at least on Meta platforms.
That's not entirely the case. There's a few Insta stragglers tied to IUVM and at least a dozen Insta accounts posting identical hashtags and content to X accounts flagged by OpenAI.
The Ministry of State Security is just like us! Reminds me of one hacktivist Telegram channel that periodically shares screenshots of their TryHackMe progress.
Per Z-Pentest, she only drew pictures π
In my work, the biggest story of 2025 has been Russian IOs pivoting away from the US.
I don't have comprehensive data on all covert ops. But if we use 1516 as an example, the US was its top target in 2024 and not even a top 5 target in 2025. Anecdotally, that roughly holds for all other ops, too.
Great news but also, how were these entities not already sanctioned?
apnews.com/article/uk-s...
Wow -- Russia reportedly plotted last year to plant bombs on US-bound flights (gift link) giftarticle.ft.com/giftarticle/...
Article dβun journaliste du Figaro dont lβidentitΓ© a Γ©tΓ© usurpΓ©e dans le cadre de la derniΓ¨re opΓ©ration informationnelle de Storm-1516.
www.lefigaro.fr/internationa...
It strikes me that people make fun of American politicians or influencers who post AI nonsense. But when Russia, China or Iran does the same thing, people act like they're sophisticated threat actors capable of shaping global opinion at will.
Iβm off this week, but I hear the MAGA influencer accounts on X that have been amplifying Russian IOs arenβt based in the US.
And Iβm shocked.
It's still so cool when outlets I read every day cover research I contributed to.
You can read more about ISD's findings here: www.isdglobal.org/digital_disp...