DigitalMANIPULATIVE
Online False-Flag Operation
What it is
Running an intrusion or influence campaign so that the evidence points to a third party — planting another actor's language, tools, personas, or infrastructure in order to be misattributed.
How it works
Real-world examples
- •Olympic Destroyer (February 2018) carried a forged Rich header matching North Korean Lazarus malware plus code fragments associated with Chinese groups. Kaspersky demonstrated the forgery, and a 2020 U.S. indictment charged officers of Russia's GRU.
- •In April 2015 the French broadcaster TV5Monde was taken off air by a group calling itself the CyberCaliphate and posting jihadist messages. French investigators later linked the intrusion to the Russian group APT28.
- •During the December 2017 Alabama Senate race, Democratic-aligned operatives in what was called Project Birmingham arranged for Russian-looking bot accounts to follow Republican Roy Moore, generating news stories that Russia was backing him; the New York Times revealed the scheme in December 2018.
- •State operators have also impersonated a domestic group: a 2020 Iranian email and video campaign was sent in the name of the American far-right Proud Boys, and U.S. officials attributed it to Iran within days.
Ethical guidelines
- ●Impersonating a third party to draw blame onto them is deception aimed at two victims: the audience and the framed group.
- ●Analysts should treat an unusually tidy set of indicators as a reason for more checking, not less.
- ●Do not invoke the possibility of a false flag to wave away solid evidence; it is a hypothesis that needs its own support.
- ●Those who experiment with such tactics for research or to make a point still deceive voters and should expect to be judged accordingly.
How to defend against it
- ►Ask which indicators an operator could choose (language, slogans, persona names, malware strings) and which they could not easily control (platform registration data, payment records, long-term infrastructure). Weight the second kind.
- ►Be suspicious of attribution evidence that is conveniently legible to journalists within hours.
- ►Ask who is harmed by the apparent attribution and whether the supposed actor had any reason to be so careless.
- ►Hold both errors in view: false flags exist, and they are rare. Wait for assessments that draw on more than the visible surface.
- ►When a claim that something was a false flag circulates, demand the same evidence you would for the original attribution.
References
- Kaspersky Global Research and Analysis Team (2018). OlympicDestroyer is here to trick the industry. Securelist, March 8, 2018 · linkTechnical demonstration that the Lazarus-matching Rich header in Olympic Destroyer was forged.
- Shane, S., & Blinder, A. (2018). Secret Experiment in Alabama Senate Race Imitated Russian Tactics. The New York Times, December 19, 2018Project Birmingham, including the use of Russian-looking accounts to follow Roy Moore.
- Rid, T., & Buchanan, B. (2015). Attributing Cyber Attacks. Journal of Strategic Studies, 38(1-2), 4-37 · linkDiscussion of deception and planted indicators as a standing problem in attribution and why multiple independent indicators limit it.
Last reviewed
Suggest a correctionRelated Articles
Dark Patterns in UX: How Apps Manipulate Your Behavior
Subscription traps, misleading interfaces, and engineered addiction. Understanding the persuasion techniques built into the apps you use every day.
7 min read
OSINT for Beginners: Open Source Intelligence Explained
Open Source Intelligence (OSINT) uses publicly available data to gather actionable insights. Here is a beginner-friendly guide to what OSINT is and how it is used.
10 min read