2017–2022 (some Twitter accounts dated to 2012)

The pro-Western covert network removed by Meta and Twitter (Unheard Voice)

In July and August 2022 Twitter and Meta removed two overlapping sets of fake accounts that had promoted the interests of the United States and its allies to audiences in the Middle East and Central Asia. Both companies passed data to Graphika and the Stanford Internet Observatory, whose joint report, Unheard Voice, appeared on 24 August 2022. The researchers described it as the most extensive case of covert pro-Western influence activity on social media analysed by open-source researchers to that point. They found not one campaign but a series of them over almost five years, using invented personas, some with computer-generated faces, and outlets posing as independent local media. They also found that almost nobody was listening. The case is included here because it shows a democratic state's military-linked operators using the same deceptive toolkit that Western governments criticise in others, being caught by the same platform enforcement, and getting the same poor return. A separate US military operation, reported by Reuters in June 2024 and concerning Chinese COVID-19 vaccines in the Philippines, is often confused with this network. It is described below only to keep the two apart.

Attribution

Individuals associated with the US military, according to Meta. No official US body has publicly claimed or confirmed the network. The Washington Post, citing unnamed officials, reported that US Central Command was among the commands whose online activities came under review.

Attributed by: Meta (Adversarial Threat Report, Third Quarter 2022, published November 2022). Twitter gave only presumptive countries of origin. The researchers who analysed the data, Graphika and the Stanford Internet Observatory, made no attribution of their own.

Confidence, in their words: Meta: its investigation found links to individuals associated with the US military, adding that the people behind the network attempted to conceal their identities and coordination. Twitter: presumptive countries of origin were the United States and Great Britain. Graphika and Stanford reported what the platforms told them and did not name an operator. The Pentagon neither confirmed nor denied responsibility; its press secretary said that military information operations support national security priorities and must comply with law and policy.

Objective

Judging by content, since no operator has explained its aims: to promote the United States and its allies and to criticise Russia, China and Iran. Unheard Voice reports that the accounts consistently advanced narratives favourable to US interests, criticised Russia in particular for its wars and, after February 2022, for the invasion of Ukraine, and attacked Iranian influence in the Middle East and the conduct of the Taliban in Afghanistan. A good deal of the output simply redistributed material from US government-funded media and from news sites sponsored by the US military.

Target audiences

  • Russian-speaking audiences in Central Asia
  • Persian-speaking audiences in and around Iran
  • Audiences in Afghanistan
  • Arabic-speaking audiences in the Middle East, particularly Iraq, Syria, Lebanon and Yemen

Timeline

  1. 2008 onward (background)
    The US military operates openly sponsored regional news sites under the Trans-Regional Web Initiative. These are overt, not covert, but matter later because the fake accounts repeatedly shared their content.
  2. March 2012 – 2017
    The oldest accounts in the Twitter dataset are created. Graphika and Stanford date the bulk of the covert activity, and all of the Meta assets, to 2017 and after.
  3. Late 2019
    The US Congress passes Section 1631 of the annual defence authorisation act, which the Washington Post describes as affirming that the military may conduct clandestine operations in the information environment.
  4. 2020
    According to the Washington Post, Facebook disables fake personas created by Central Command to counter Chinese claims about the origins of COVID-19, and a senior Facebook official warns the Pentagon that if Facebook could find such accounts, so could US adversaries.
  5. February – July 2022
    After the Russian invasion of Ukraine, the Central Asia accounts turn to the war, its civilian toll and its economic consequences for the region. The Meta assets remain active until July 2022.
  6. July – August 2022
    Twitter removes the accounts under its platform manipulation and spam policy. Meta removes 39 Facebook accounts, 16 Pages, two Groups and 26 Instagram accounts for coordinated inauthentic behaviour.
  7. 24 August 2022
    Graphika and the Stanford Internet Observatory publish Unheard Voice, based on 146 Twitter accounts and 299,566 tweets plus the Meta set.
  8. 19 September 2022
    The Washington Post reports that the undersecretary of defense for policy has ordered every command that conducts online psychological operations to provide a full accounting of its activities, following concerns raised by the White House and State Department.
  9. November 2022
    Meta publishes its own account of the takedown and states that it found links to individuals associated with the US military.
  10. 14 June 2024 (separate operation)
    Reuters reports that the US military ran a clandestine campaign from spring 2020 to mid-2021 to discredit Chinese COVID-19 vaccines and aid, mainly in the Philippines. This is a different operation from the Unheard Voice network, with a different audience, period and subject.

Channels

  • Twitter, Facebook and Instagram
  • Five further platforms identified by Graphika and Stanford, including YouTube, Telegram and the Russian networks VKontakte and Odnoklassniki
  • Sham news outlets with their own social media pages and, in some cases, websites
  • Online petitions on the Avaaz platform
  • Links to openly US-funded media and to news sites sponsored by US Central Command

Techniques

Sockpuppeting

The network was built from invented people. Unheard Voice documents personas presented as local residents, journalists and commentators in Central Asia, Iran, Afghanistan and the Arab world, none of whom disclosed any connection to a government.

Deepfakes/Synthetic Media

Some personas used profile photographs produced by generative adversarial networks, identifiable by the fixed eye position and background artefacts typical of such images. Others used collages that altered photographs taken from elsewhere, including one built from a picture of an actress.

Front Groups

The Central Asia cluster alone included ten sham media outlets presenting themselves as independent regional news organisations. Similar outlets appeared in the Persian-language cluster, one of them reposting Voice of America Farsi content under its own brand.

Information Laundering

Covert accounts repeatedly shared articles from websites sponsored by US Central Command and from US-funded broadcasters, so that official messaging reached readers looking like the independent choice of a local voice rather than like a government publication.

Coordinated Inauthentic Behavior

Accounts posted at regular 15-minute or 30-minute intervals, reused the same text and images across platforms, and formed clusters that amplified one another. Meta said the operators tried to conceal their identities and coordination.

Hashtag Hijacking

Posts were loaded with batches of trending and unrelated hashtags in the target language to place them in front of people following those topics. Unheard Voice found this did little to raise engagement.

Astroturfing

The Central Asia cluster launched four petitions on Avaaz and promoted hashtag campaigns that presented operator-written demands as grassroots regional sentiment.

Atrocity Propaganda

Some content went beyond spin. The Washington Post highlights a post, linked to a US military-affiliated site, claiming that relatives of Afghan refugees had reported bodies returned from Iran with organs missing. Other posts, on Russian conduct in Ukraine, drew on real reporting, which illustrates how accurate and unverifiable claims were mixed in one stream.

Gray and Black Propaganda

The network sat between grey and black propaganda: sources were concealed or falsely presented as local and independent, while much of the underlying material came from overt, acknowledged US outlets. The deception lay mostly in who was speaking rather than in what was said.

Actors, behaviors, content

Actors. Per Meta, individuals associated with the US military, operating from the United States. Twitter also listed Great Britain as a presumptive country of origin, a point that has not been publicly explained. No individual operators have been identified, and none are named here.

Behaviors. Fake personas, synthetic or doctored profile photographs, sham media brands, scheduled and duplicated posting, cross-platform recycling and petition drives. These are the behaviours that platform rules prohibit regardless of who is behind them or what is said, and they are the stated reason for removal.

Content. Mixed. Unheard Voice records a large volume of reposted material from overt US-funded sources, original posts praising US aid and criticising Russia, China and Iran, sarcastic and cultural content aimed at Iranian audiences, and a smaller amount of lurid or unverified claims. It was organised as four regional campaigns: Central Asia, Iran, Afghanistan and the Arabic-speaking Middle East.

Did it work? What is actually known

This is one of the better-measured cases, and the measurement is unflattering. Graphika and Stanford found that the average tweet in the dataset received 0.49 likes and 0.02 retweets, that only 19 per cent of the covert assets had more than 1,000 followers, and that Facebook posts in the Central Asia cluster often had fewer than ten likes. They concluded that the vast majority of posts received no more than a handful of likes or retweets. Meta reached the same judgement, stating that most of the operation's posts had little to no engagement from authentic communities. The researchers also observed that the most-followed accounts in the Twitter data were overt ones that openly declared a link to the US military, which suggests that concealment bought nothing. Two caveats apply. Likes and retweets measure reaction, not exposure or persuasion, and the datasets contain only what the platforms chose to share. No study has tested whether any audience changed its views, so effect on opinion is strictly unknown, though nothing in the record suggests it was large. The clearest measurable consequence was reputational: the Washington Post reported concern inside the US government that the tactics risked eroding US credibility.

How it was caught

By the platforms' own enforcement teams. Twitter acted under its rules on platform manipulation and spam and Meta under its policy on coordinated inauthentic behaviour, which targets deceptive conduct rather than viewpoint. Both then gave portions of the data to outside researchers, who identified the clusters through shared posting schedules, duplicated text and images, recycled assets across platforms, and the visual signatures of computer-generated faces. The Washington Post reports that the pattern was not new to the companies: Facebook had found and disabled military-run fake personas in 2020 and had told the Pentagon how easy they were to detect.

Lessons

  • »Deceptive technique is not the property of any one country or cause. The methods documented here are the same ones documented in Russian, Chinese and Iranian operations. A reader who only expects manipulation from adversaries will miss it when it arrives carrying agreeable messages.
  • »Judge the behaviour, then the message. The platforms removed these accounts for pretending to be people they were not, not for their opinions. That standard is what allows enforcement to be even-handed, and it is a useful test for readers too: ask who is actually speaking before asking whether you agree.
  • »Fake voices tend to perform worse than honest ones. In this dataset, accounts that openly declared their government connection drew larger followings than the covert personas. Audiences are often more willing to hear a declared source than operators assume.
  • »An unfamiliar outlet that mostly republishes another organisation's reporting deserves a second look. Several of the sham outlets here were thin wrappers around overt government-funded content. Checking the about page, the named staff and the outlet's history is a reasonable habit.
  • »Exposure carries a cost that outlasts the operation. Once a government is shown to have used fake personas, its genuine statements and the independent local voices who happen to agree with it become easier to dismiss as more of the same.
  • »Keep distinct operations distinct. The 2022 network and the campaign Reuters reported in 2024 differ in audience, period, subject and potential for harm. Merging them, in either direction, produces a less accurate picture than the record supports.

Still contested

  • Attribution remains partial. Meta's wording is links to individuals associated with the US military, which is narrower than saying the Department of Defense ran the network. The department has not publicly acknowledged it, and the identification of Central Command rests on unnamed officials quoted by the Washington Post. Twitter's reference to Great Britain has never been publicly accounted for.
  • Whether it is one operation. Graphika and Stanford stress that the data appear to cover a series of campaigns over almost five years rather than a single homogeneous effort, and that the two platforms' sets only partly overlap. Treating it as one network is a convenience.
  • Whether truthful content changes the ethics. Defenders of military information operations argue that distributing largely accurate material to audiences under authoritarian information controls differs from spreading fabrications. Critics, including officials cited by the Washington Post, answer that fake personas are deceptive whatever they post and that the practice undercuts the values the United States says it is defending. Both positions were reportedly argued inside the US government.
  • What the Pentagon review changed. The September 2022 review was reported, but its findings have not been published in full. Renee DiResta, writing in Lawfare in 2026, argues that US military-sponsored online influence has since moved away from fake personas toward paid advertising for sponsored news sites with less prominent disclosure. How far that shift reflects the review is not publicly documented.
  • The separate vaccine campaign. Reuters reported, citing former officials, that the military used at least 300 fake accounts on X to disparage the Sinovac vaccine and other Chinese aid in the Philippines and beyond from spring 2020 to mid-2021, over objections from US diplomats in the region. A Pentagon spokesperson responded that the military uses a variety of platforms, including social media, to counter malign influence attacks aimed at the US and its partners. Public health experts briefed by Reuters condemned the campaign as endangering lives. Whether it measurably reduced vaccine uptake in the Philippines, where hesitancy already had other causes, has not been established.

Sources

  1. Graphika and Stanford Internet Observatory, Unheard Voice: Evaluating five years of pro-Western covert influence operations (24 August 2022), Stanford Digital Repository
    Permanent record of the report: the takedown circumstances, dataset sizes, the four regional campaigns, tactics, narratives, engagement figures, and the platforms' statements on country of origin.
  2. Graphika, Unheard Voice (report page and PDF)
    Same report from the co-author's own site: synthetic profile images, sham media outlets, posting intervals, petitions, links to Central Command-sponsored sites, and the finding that overt accounts outperformed covert ones.
  3. Meta, Adversarial Threat Report, Third Quarter 2022 (November 2022)
    Counts of removed assets, the list of targeted countries, the attribution to individuals associated with the US military, and the statement that most posts had little to no authentic engagement.
  4. Ellen Nakashima, Pentagon opens sweeping review of clandestine psychological operations, Washington Post (19 September 2022)
    The Pentagon review and who ordered it, the focus on Central Command, the 2020 Facebook warning, the organ-harvesting example, White House and State Department concerns about credibility, Section 1631, and the Pentagon press secretary's statement.
  5. Chris Bing and Joel Schectman, Pentagon ran secret anti-vax campaign to undermine China during pandemic, Reuters (14 June 2024)
    The separate 2020–2021 campaign against Chinese vaccines and aid: at least 300 accounts, the Philippines focus, timing, diplomats' objections and expert reaction.
  6. Military.com, Pentagon Stands by Secret Anti-Vaccination Disinformation Campaign in Philippines After Reuters Report (14 June 2024)
    The Department of Defense spokesperson's on-record response to the Reuters investigation.
  7. Renee DiResta, Fewer Bots, More Ads: The Pentagon's Evolving Online Influence Campaigns, Lawfare (2026)
    Background on the overt Trans-Regional Web Initiative sites and the argument that military-sponsored influence has shifted from fake personas to paid promotion since 2022.
Last reviewed Suggest a correction