Spamouflage (also tracked as Spamouflage Dragon and DRAGONBRIDGE)
Spamouflage is the name Graphika gave in September 2019 to a network of fake and hijacked accounts on YouTube, Twitter and Facebook that mixed Chinese-language political posts with unrelated filler such as scenery, basketball and short videos, apparently to camouflage the politics, which is where the name comes from. The first targets were the Hong Kong protest movement and an exiled Chinese businessman and critic of the government. Over the next four years the network added English and other languages, spread to dozens of platforms, and turned to praising China and criticising the United States, Western foreign policy and individual critics of Beijing. Google and Mandiant track the same activity as DRAGONBRIDGE. In August 2023 Meta called it the largest known cross-platform covert influence operation in the world. It is also, by every published measure, among the least successful at reaching real people. That combination of vast scale, long life and minimal uptake is the reason to study it.
Individuals associated with Chinese law enforcement, according to Meta. A US Department of Justice complaint separately alleges that officers of the Ministry of Public Security, working in a unit called the 912 Special Project Working Group, ran a fake-account operation of closely similar description.
Attributed by: Meta (Adversarial Threat Report, Second Quarter 2023, published 29 August 2023); Google Threat Analysis Group and Mandiant (2022–2024); Global Affairs Canada, Rapid Response Mechanism (23 October 2023); US Department of Justice (criminal complaint unsealed 17 April 2023). Graphika, which named the network in September 2019, did not attribute it to the Chinese state in its first report.
Confidence, in their words: Varies by body, and none of it has been tested in court. Meta: although the people behind the activity tried to conceal their identities and coordination, its investigation found links to individuals associated with Chinese law enforcement. Google: a spammy influence network linked to China. Mandiant: a network of inauthentic accounts promoting narratives in support of the political interests of the People's Republic of China. Global Affairs Canada: a campaign connected to the People's Republic of China. The Justice Department complaint is an allegation against 34 Ministry of Public Security officers, all believed to be in China and at large; it does not use the name Spamouflage, and the connection between the two was drawn by Meta and by press reporting.
Objective
In Graphika's early assessment, to support the Chinese government and discredit its critics at home and abroad. Later reporting adds a second strand aimed at foreign publics: portraying the United States as hegemonic, divided and badly governed, defending Chinese policy on Xinjiang, Hong Kong, Taiwan and COVID-19, and, in a few documented cases, trying to affect specific commercial or political outcomes. The Justice Department complaint describes the alleged police unit's purpose as targeting Chinese dissidents located throughout the world. Whether the underlying goal was persuasion, intimidation of critics, or simply the production of visible activity for superiors is disputed.
Target audiences
- Chinese-speaking audiences worldwide, including diaspora communities and followers of exiled dissidents
- Hong Kong residents during and after the 2019 protests
- English-speaking audiences in the United States, United Kingdom, Australia and Canada
- Audiences in Taiwan and Japan
- Individual critics of the Chinese government, including journalists, researchers and activists, as targets rather than audiences
Timeline
- Mid-2019Mandiant dates its first reporting on the activity it later named DRAGONBRIDGE to June 2019. On 25 September 2019 Graphika publishes its first Spamouflage report, describing an active and prolific but ultimately low-impact spam network attacking the Hong Kong protesters.
- 2020The network begins producing English-language video, much of it critical of the United States, and comments on the COVID-19 pandemic and US domestic unrest. Graphika documents the shift in further reports.
- 4 February 2021Graphika's Spamouflage Breakout report finds that, after posting more than 1,400 unique videos in a year, a few of the network's accounts were for the first time amplified by real, prominent users, including Chinese diplomats, a Venezuelan foreign minister and a former British MP. Graphika still describes this reach as limited relative to the assets deployed.
- September 2021 – June 2022Mandiant reports that the network has spread across dozens of platforms and has tried, without success, to mobilise street protests in the United States. In June 2022 it reports fake accounts posing as Texas residents to stir environmental opposition to rare earths companies that compete with Chinese producers.
- 26 January 2023Google reports disrupting more than 50,000 instances of DRAGONBRIDGE activity in 2022 and terminating more than 100,000 accounts over the network's lifetime, with engagement close to zero.
- February 2023Graphika reports the network using AI-generated video presenters for a fictitious outlet called Wolf News, which it describes as the first use of such footage by a state-aligned operation. None of the videos exceeded 300 views.
- 17 April 2023The US Justice Department unseals a complaint charging 34 officers of China's Ministry of Public Security, alleged members of the 912 Special Project Working Group, with running thousands of fake personas to harass dissidents and spread propaganda.
- 29 August 2023Meta removes 7,704 Facebook accounts, 954 Pages, 15 Groups and 15 Instagram accounts, ties earlier clusters together as one operation active on more than 50 platforms and forums, and links it to individuals associated with Chinese law enforcement.
- 23 October 2023Global Affairs Canada reports that a Spamouflage bot network left thousands of English and French comments on the Facebook and X accounts of dozens of Members of Parliament, across parties, beginning in August 2023.
- 2024Google reports disrupting more than 10,000 further instances in the first quarter of 2024 alone, indicating that the operation continued at volume after the public attributions.
Channels
- YouTube, Blogger and other Google services
- Facebook and Instagram
- Twitter, later X
- TikTok, Reddit, Pinterest, Medium, Vimeo, LiveJournal and VKontakte, as listed by Meta
- Dozens of smaller platforms and regional web forums
- Comment sections beneath the posts of politicians, journalists and dissidents
Techniques
The whole network consisted of accounts pretending to be unconnected individuals. Meta found posting concentrated in mid-morning and early afternoon Beijing time, with pauses matching lunch and supper and a final burst in the evening, a pattern it read as people working shifts from shared premises in several parts of China.
Volume was the method. Graphika counted more than 1,400 unique videos in under a year. Google removed more than 50,000 channels, blogs and accounts in 2022 alone. The same material was pasted across more than 50 platforms and forums, so that removal in one place left copies in many others.
Operators did not build their own accounts. Google says the network buys accounts in bulk from commercial sellers, and Meta says many Facebook Pages were probably acquired from spam operators complete with pre-existing fake followers. Graphika also documented hijacked accounts whose earlier, unrelated posts remained visible.
Named individuals were a constant focus: first an exiled businessman and the Hong Kong protest movement, later journalists, researchers and activists critical of Beijing. Meta lists critics of the Chinese government among the network's main subjects, and the US complaint alleges that the police unit's fake personas harassed and threatened dissidents abroad.
Global Affairs Canada recorded thousands of comments posted in a matter of weeks beneath the social media posts of dozens of Canadian MPs, including the Prime Minister and the leader of the Opposition. The US complaint alleges that members of the police unit also disrupted online meetings held by pro-democracy advocates.
Mandiant found accounts presenting themselves as local Texas residents worried about pollution, posting in an existing community group opposed to a rare earths processing plant. The companies targeted were commercial rivals to Chinese producers. Mandiant judged that the posts received only limited engagement from seemingly real people.
In late 2022 the network posted clips fronted by AI-generated presenters for an invented outlet, Wolf News, made with a commercial video-avatar product. Graphika treats it as a first for a state-aligned operation and also notes that none of the clips passed 300 views.
Much of the English-language output answered criticism of China by pointing at the United States: gun violence, racial injustice, the pandemic response and the health of American democracy. Google lists criticism of US democracy, the US COVID-19 response and US Taiwan policy among the recurring themes.
The US complaint alleges that the police unit spread propaganda intended to sow divisions within the United States. Mandiant likewise reports that the rare earths campaign drew on criticism already voiced by real American politicians from both parties, attaching itself to existing domestic disputes rather than inventing new ones.
Actors, behaviors, content
Actors. According to Meta, individuals associated with Chinese law enforcement, working from several locations in China. According to the US complaint, serving officers of the Ministry of Public Security. Account supply came from commercial bulk sellers and spam operators with no evident political role. Chinese diplomats occasionally amplified network accounts; Graphika considered it likely that they did not know the accounts were fake.
Behaviors. Bulk acquisition of accounts, rapid replacement after takedowns, identical content pasted across many platforms, political posts buried among unrelated filler, mass commenting on the posts of named targets, and later the use of AI-generated presenters. Platform investigators repeatedly describe careless execution; Google cites poor translations, malapropisms and mispronunciations.
Content. Praise for China and its policies in Xinjiang and Hong Kong; attacks on the United States, Western foreign policy and named critics of Beijing; commentary on COVID-19, Taiwan and US politics; and a very large volume of apolitical spam. Google notes blurry visuals, garbled audio and poor translations as typical, and says that only a small fraction of the network's accounts posted political content at all.
Did it work? What is actually known
The evidence is unusually consistent, and it shows very little reach. Google reported that 58 per cent of the 53,177 YouTube channels it disabled in 2022 had no subscribers, that 83 per cent of the network's videos had fewer than 100 views, that nearly 95 per cent of its Blogger posts had ten or fewer views, and that the rare engagement it did receive was almost entirely inauthentic, coming from other accounts in the network. Meta described the operation as the largest known of its kind and in the same breath as unsuccessful. Its Pages showed about 560,000 followers, but Meta assessed that these came bundled with Pages bought from spam operators and were mainly fake accounts from Vietnam, Bangladesh and Brazil, not the audiences the operation was addressing. Graphika called the 2019 network low-impact, and Mandiant found that attempts to prompt real-world protests failed. The main exception is Graphika's 2021 finding that a handful of accounts were shared by prominent real users, which shows that occasional breakout is possible. Important limits remain. Platforms can count views on their own services but cannot see closed messaging apps or every small forum. View counts do not capture the effect on a dissident or a journalist of being the subject of thousands of hostile comments, which may matter more than persuasion. And no published study measures any change in public opinion attributable to the network, so that effect is unknown, though nothing in the record suggests it was significant.
How it was caught
Through the same carelessness that limited its reach. Graphika first spotted the network by the odd pairing of political posts with unrelated filler on accounts that had abruptly changed language and subject. Platform teams then linked clusters through reused content, shared technical signals and synchronised timing, and Meta used the working-hours pattern to infer a staffed, shift-based operation. Because the operators bought accounts in bulk and posted identical material everywhere, finding one cluster tended to expose others. Researchers at different companies were tracking the same activity under different names, and Meta's 2023 report was the first to state publicly that these were one operation. The US complaint added an account, based on investigative material, of how one alleged unit was organised.
Lessons
- »Scale is not success. Counts of accounts removed describe the operator's effort, not its effect. A headline about the largest operation ever found is compatible with almost nobody having seen its content, and in this case the platforms said exactly that.
- »Check who is actually engaging. A post with many likes or comments from accounts that have no history, no connections and generic names has not been endorsed by anyone. Inflated numbers were the network's main product.
- »Harassment can be the point. For exiles, researchers and reporters, the practical impact of this network was being swamped with hostile replies, not being out-argued. Volume aimed at a person should be read as an attempt to raise the cost of speaking, and reported to the platform as coordinated abuse.
- »Sudden changes of subject and language are a tell. Many accounts had earlier lives posting about something else entirely, in another language. Scrolling back through an unfamiliar account's history is a quick and effective check.
- »Synthetic presenters are now cheap, and still not persuasive on their own. The AI-generated news anchors drew attention from researchers and the press and almost none from viewers. An unfamiliar news brand with a flawless, oddly stiff presenter and no traceable staff or address deserves doubt.
- »Persistence without improvement is itself informative. An operation that runs for years with poor results may be answering to internal measures such as posts published rather than to real-world impact. Defenders should avoid assuming that every long-lived operation must be working.
Still contested
- What it is for. Some analysts read the low quality as evidence that the operators are rewarded for output rather than influence. The US complaint's description of performance tracking within the alleged police unit is consistent with that view. Others argue the aim is to drown out critics and intimidate them, for which engagement figures are the wrong measure.
- Whether it is one operation. Meta states that the clusters form a single operation. Graphika observed early on that clusters had different focuses and appeared to have a degree of autonomy rather than rigid central control. Both can be true, but the boundary of what counts as Spamouflage differs between research groups, which is one reason their numbers differ.
- How firm the state link is. Graphika did not attribute its 2019 findings to the Chinese state. Meta's 2023 wording refers to individuals associated with law enforcement, not to a ministry. The US charges are untested allegations against defendants who are believed to be in China and have not appeared in court.
- How much attention it merits. Because its measurable reach is so small, some researchers caution that prominent coverage overstates the threat. Others point to the 2021 breakout, the targeting of elected officials in Canada and the adoption of AI-generated video as signs that the operators are experimenting and could become more effective.
- Whether takedowns work. More than 100,000 Google accounts were terminated over the network's life and it continued to operate at scale. Removal clearly imposes cost and keeps reach low, but it has not ended the activity, and there is no agreement on what would.
Sources
- Graphika, Spamouflage: Cross-Platform Spam Network Targeted Hong Kong Protests (25 September 2019)The name and its origin, the platforms first involved, the early targets, the use of fake and hijacked accounts, and the assessment of the network as prolific but low-impact.
- Graphika, Spamouflage Breakout (4 February 2021)More than 1,400 videos in a year, the shift to attacking the United States, and the first documented amplification by real prominent users including diplomats.
- Graphika, Deepfake It Till You Make It (February 2023)The AI-generated Wolf News presenters, the claim of a first for a state-aligned operation, and the view counts below 300.
- Meta, Raising Online Defenses Through Transparency and Collaboration (Q2 2023 Adversarial Threat Report, 29 August 2023)The description as the largest known cross-platform covert influence operation, more than 50 platforms and forums, the list of platforms, and the link to individuals associated with Chinese law enforcement.
- The Record (Recorded Future News), Chinese law enforcement linked to largest covert influence operation ever discovered (29 August 2023)Detailed figures from the Meta report: assets removed, the 560,000 mostly fake followers and their origin, the shift-work posting pattern, target countries, and the connection drawn to the US complaint.
- Google Threat Analysis Group, Over 50,000 instances of DRAGONBRIDGE activity disrupted in 2022 (26 January 2023)Removal totals, subscriber, view and comment statistics, the finding that engagement was almost entirely inauthentic, bulk purchase of accounts, content quality and recurring narratives.
- Google Threat Analysis Group, Google disrupted over 10,000 instances of DRAGONBRIDGE activity in Q1 2024Continued activity at volume after public attribution.
- Mandiant, Pro-PRC DRAGONBRIDGE Influence Campaign Targets Rare Earths Mining Companies (28 June 2022)Tracking since June 2019, the expansion across dozens of platforms, failed attempts to mobilise protests, the fake Texas residents, use of real politicians' criticism, the attribution wording, and the finding of limited engagement.
- US Department of Justice, 40 Officers of China's National Police Charged in Transnational Repression Schemes Targeting U.S. Residents (17 April 2023)The complaint against 34 Ministry of Public Security officers of the 912 Special Project Working Group: thousands of fake personas, harassment of dissidents, disruption of online meetings, propaganda intended to sow division, performance tracking, and the defendants' status.
- Global Affairs Canada, Rapid Response Mechanism Canada detects Spamouflage campaign targeting Members of Parliament (23 October 2023)The comment-flooding campaign against dozens of Canadian MPs, its timing, and the government's attribution wording.