News: 1666830704

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Pro-China crew ramps up disinfo ahead of US midterms. Not that anyone's falling for it

(2022/10/27)


The prolific pro-Beijing Dragonbridge crew has apparently stepped up its activity ahead of the US 2022 midterms by trying to discourage Americans from voting as well as pinning the Nord Stream pipeline explosion on Uncle Sam.

[1]Google subsidiary Mandiant reports [2]this week that the China-aligned cyber-influence team is using thousands of fake online accounts across social media platforms to reach Americans. The sophisticated and well-financed operation is trying to spread disinformation designed to discouraging US voters from turning up at the polls.

"The solution to America's ills is not to vote for someone," but rather to "root out this ineffective and incapacitated system," one propaganda video spread around claimed.

[3]

Dragonbridge has become better at impersonating Americans in social media posts, mainly through improved writing and use of pronouns, Mandiant claimed. The crew has also been caught impersonating Intrusion Truth, a group that targets Chinese cyber-criminals and leaks their private documents, in a bid to lend itself an air of legitimacy.

[4]

[5]

The latest wave of propaganda spam also tries to pin the activities of well-known cyber-spies [6]APT41 – widely believed to operate at the behest of Beijing – on US government agents. That is to say, Uncle Sam is being framed for the APT's nefarious operations. These stories have been heavily promoted across social media in a "more sophisticated" way than before, Mandiant said.

The group is also pushing the Russian narrative that America was responsible for the twin explosions last month that disabled the Nord Stream gas pipelines in the Baltic Sea. The United States blew up the supply lines to become the dominant energy provider for Europe, and cut Russia out, it's claimed.

[7]

Mandiant has been tracking Dragonbridge since 2019, when it was first spotted on social networks trying to discredit pro-democracy protests in Hong Kong. The crew also appeared over the summer this year to [8]troll an Australian rare-earths mining company.

"The Dragonbridge campaign has continued to exhibit aggressiveness through both the content of its narratives and its willingness to experiment with new tactics to accomplish its aims," Mandiant claimed.

[9]Mandiant 'highly confident' foreign cyberspies will target US midterm elections

[10]China-linked fake news site shows disinformation on the rise

[11]China is trolling rare-earth miners online and the Pentagon isn't happy

[12]Iran, China-linked gangs join Putin's disinformation war online

There's a big "but" here, though: while churning out tons of misinformation, "the campaign has continued to fail to garner any significant engagement," Mandiant said. Despite this, it looks unlikely Dragonbridge isn't going to keep trying.

While Dragonbridge's activities appear confined to social media disinfo campaigns, election security is very much on people's minds at the moment.

The Biden administration may soon [13]warn of attempts by foreign powers to derail America's election security infrastructure. We're told an upcoming bulletin will provide details of cyber threats from China, Russia, and non-state miscreants.

[14]

Mandiant has [15]previously fretted that overseas agents would target the US midterm elections. American officials have [16]said they're confident attempts to affect election infrastructure will be unsuccessful at disrupting or preventing voting, fail at compromising the integrity of ballots, and fail at manipulating votes at any meaningful scale. ®

Get our [17]Tech Resources



[1] https://www.theregister.com/2022/10/11/google_mandiant_brain/

[2] https://www.mandiant.com/resources/blog/prc-dragonbridge-influence-elections

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y1oCXXD09XyKltQMEN8xkAAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y1oCXXD09XyKltQMEN8xkAAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y1oCXXD09XyKltQMEN8xkAAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2020/03/26/fireeye_apt41_chinese_hackers_zoho_citrix_cisco/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y1oCXXD09XyKltQMEN8xkAAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/06/28/dod_china_dragonbridge/

[9] https://www.theregister.com/2022/09/08/mandiant_cyberspies_us_elections/

[10] https://www.theregister.com/2022/08/05/china_fake_news/

[11] https://www.theregister.com/2022/06/28/dod_china_dragonbridge/

[12] https://www.theregister.com/2022/05/19/iran_china_disinformation_online/

[13] https://www.politico.com/news/2022/10/24/biden-election-infrastructure-national-security-warnings-00063134

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y1oCXXD09XyKltQMEN8xkAAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://www.theregister.com/2022/09/08/mandiant_cyberspies_us_elections/

[16] https://www.theregister.com/2022/10/06/us_midterm_election_cyberattack_unlikely/

[17] https://whitepapers.theregister.com/



Those "engagement numbers" may be misleading

Anonymous Coward

Though reading the crystal ball for these groups is a fools game, much like the low quality Russian campaigns from a few years ago, there are a couple of forks in the road:

One is they are busywork for unskilled operators whose leadership is still billing for their services. Which has happened.

Another is that the objectives of the campaigns aren't conventional engagement, and the producers know their transparent and shoddy work is not in itself convincing anybody.

Why persist at it then? Depending on the specifics of the campaign, it may be boosting the transmission of payload related to their posts but not linked to the accounts sending the low quality messages. This is one way to boost another campaign while avoiding simple network analysis. So if you want conspiracies about the Nord Stream pipeline or a dirty bomb, mentioning them in active but ignored campaigns may reach the often surprisingly low threshold to get boosted further by many of the "mystery box" algorithms that drive the modern online world.

Interestingly, the low quality posts can be a strategy, as they get filtered from the results but then can help lift a post from somebody in Gulfport or Billings that uses the same terms. So they may work as well as higher quality posts in biasing the results, but are made stealthier as they are either ignored when seen or filtered out. This is one of the ways people have amplified seemingly organic hate speech to help it get viral. It can assist posts reflecting it's talking points on other accounts not in it's engagement network, often without the intent or much visibility of the operator. One of the curses of using ML models as a magic wand for so many things is the opacity of their decision making process. And there is always a shit talking idiot out there, so why try to find and amplify them on your own when you can get Facebook or Twitter to do it for you, automatically?

Not sure how resistant either of those companies are today, but it was a brisk business gaming their naive weighting system just a few years ago. And now those systems aren't just there and Google and the Hyperscalers. Before the game was to springboard on one big platform to bounce the results on the other majors. Reddit to Twitter to Facebook or YouTube or vice versa depending on the crews. Now that so many other companies are using the same techniques, even as the majors start playing whack a mole and locking down direct actions on their platforms, the attackers just shifted to pulling the same stunt on systems that use the same mechanics but are not policed as effectively. Since the majors surface and scrape content from everywhere else, it still can go viral on their platforms even when the actors aren't running a campaign directly on their system.

Like matter creates gravity, these hyper-scale algorithmic systems create emergent instabilities and are prone to being hijacked. Systems like that are unstable and inherently dangerous. People didn't listen at first, because "how could Twitter be dangerous", then Facebook accelerated ethnic cleansing and genocide in south east Asia, because their black box was left to run unsupervised in a country where the developers weren't paying attention to anything other than the revenue and didn't speak the language. Villages burned and piles of corpses. Millions internally displaced, and many forced into permanent refugee camps in neighboring countries.

This stuff is not academic, it is neither funny nor fun.

What campaign?

martinusher

I sent my vote in last week. Hadn't heard of any Chinese disinformation campaign, not around here anyway. As for 'discouraging people from voting', you don't need remote Chinese operatives to do that, you just need to be of a certain color and political persuasion and want to vote in Florida (get arrested on felony charges) or Arizona (armed thugs by ballot drop boxes) or whatever. Here in California all is peaceful so far.

As for dear old Uncle Sam being involved in the NS pipeline explosions you don't need a Chinese disinformation campaign to make that connection. Its the combination of "who benefits?" plus US warships in the vicinity in the week before plus is being in Danish territorial waters. Of course it might not be us who did it -- we did invent the concept of 'denyability' after all -- but its definitely the sort of thing we'd be involved in.

Incidentally, I know its fashionable to look for 50s this and 40s that in movies and stuff but a) the 50s were pretty awful and b) we had quite enough "Reds under your beds" scares then, we really don't need to recycle that old BS.

"He dropped his voice still lower. In the stillness, a fly
would not have dared cleat its throat. "