top of page

Cyber based influence campaigns 27th July – 2nd August 2026 Report

  • Writer: CRC
    CRC
  • 3 hours ago
  • 19 min read
Cover Image- Text: Weekly Media Update: Information Operations


[Introduction]


Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW).

Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. 

Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. 

We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc.

During the 27th July to 2nd August 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities.



[Contents]





Russia 

china


[Cyfluence Attacks]



[Appendix - Frameworks to Counter Disinformation]





[ Report Highlights]


  • DFRLab mapped Storm-1516's full interference infrastructure against Armenia's May 2026 parliamentary elections, 45 campaigns, 149.5 million views, 450 accounts, two false-front website clusters, GRU Unit 29155, while France's Viginum attributed to the same network the first documented Storm-1516 campaign against a declared presidential candidate: fabricated health claims against Edouard Philippe, declared 2027 contender, one of 205 operations Viginum has attributed to Storm-1516 since August 2023.

  • Storm-1516 deployed a fake BBC video digitally inserting a stolen Lalique pendant on Ukraine's First Lady, Olena Zelenska, to generate 3.27 million views across 13,700 posts. At the same time, Ukraine's Foreign Minister revealed Russia had published more than 1,500 articles exploiting Spain's Ceuta migration crisis to spread anti-Ukraine narratives across European audiences.

  • Graphika's Ore Else report documented Spamouflage deploying 62 inauthentic accounts across four platforms to target six named Chilean journalists covering copper smuggling, marking a documented operational shift from geopolitical influence objectives to economic-sector information control.

  • On August 2nd, 2026, the EU AI Act's transparency requirements entered formal enforcement: chatbots must disclose AI status at first contact, deepfakes must be labelled, and AI-generated content must carry machine-readable marks, with more than 180 organisations signed to the Code of Practice and penalties of up to EUR 15 million or 3% of global turnover.

  • AI-generated fake flood videos during Typhoon Noel circulated widely on Chinese social media, triggering panic-buying across affected regions and prompting an emergency crackdown order from the Cyberspace Administration of China specifically targeting AI-generated disaster disinformation.

  • Google's Q2 2026 Influence Operations Bulletin documented the termination of more than 3,500 YouTube channels and several domains across operations linked to China (1,763 channels), India (1,419 channels across five campaigns), Russia (558+ channels and two domains across five operations), Azerbaijan, Chile, Hungary, Spain, Venezuela, Iran, and more than a dozen campaigns without confirmed state attribution.

  • Cheap TV streaming sticks sold through major retailers secretly enroll in residential proxy networks and spoof mobile device identities to generate fraudulent clicks on AI-generated websites, illustrating the convergence of consumer electronics, ad fraud infrastructure, and AI-generated content farming into a self-sustaining criminal revenue cycle.

  • Cyfluence Research Center documented weaponized nostalgia as a below-radar hostile influence technique, identifying a Russian-linked Facebook network of 75 or more pages embedding communist-era nostalgic affect across 12,790 posts targeting Romania, and PRC-aligned operations deploying five interlocking Ryukyuan nostalgic subthemes against Okinawa across X, YouTube, and Facebook, with content surges correlated with official PRC diplomatic actions, identifying nostalgia as a structural cognitive threat vector invisible to most automated detection systems.

[ Report Summary]

  • DFRLab documented Storm-1516's full interference infrastructure against Armenia's May 2026 parliamentary elections, 45 campaigns, 149.5 million views, 450 accounts, GRU Unit 29155, while Meduza reported France's Viginum attribution of fabricated health claims against Edouard Philippe as the first documented Storm-1516 operation targeting a declared presidential candidate.

  • Lead Stories documented Storm-1516's deployment of a fake BBC news video falsely claiming Ukrainian First Lady Olena Zelenska was photographed wearing a stolen Lalique pendant at the Coalition of the Willing summit, with the pendant digitally inserted into genuine summit footage, generating 3.27 million views and 13,700 posts before BBC publicly confirmed on July 27th, 2026 that the video was fabricated.

  • Ukraine's Foreign Minister Andrii Sybiha revealed that Russian state and state-aligned media published more than 1,500 articles exploiting Spain's Ceuta migration crisis to spread anti-Ukraine propaganda, deploying Pravda, RT, and affiliated outlets to link Ukrainian military assistance to EU-level migration pressures and weaken European public support for Ukraine.

  • Graphika's Ore Else report documented Spamouflage deploying 62 inauthentic accounts across Facebook, Parler, Tumblr, and YouTube to suppress Chilean media coverage of copper smuggling investigations, targeting six named Chilean journalists with coordinated harassment and AI-generated counter-narratives, marking a documented operational shift for the network from geopolitical targeting to economic-sector information control.

  • BBC reported that AI-generated videos falsely depicting catastrophic flooding during Typhoon Noel circulated widely on Chinese social media, triggering panic-buying across affected regions before the Cyberspace Administration of China issued an emergency crackdown order on July 23rd, 2026, specifically targeting AI-generated disaster disinformation.

  • The EU AI Act's transparency requirements entered formal enforcement on August 2nd, 2026, requiring chatbots to disclose AI status at first contact, deepfakes to be labelled, and AI-generated content to carry machine-readable marks, with the European Commission AI Office and national authorities in all 27 member states activating enforcement powers and more than 180 organisations including Meta signed to the voluntary Code of Practice, while analysts identified enforcement gaps including strippable watermarks and the difficulty of automated machine-text detection.

  • A joint advisory from cybersecurity agencies warned that Russian-linked threat actor Laundry Bear is exploiting Zimbra vulnerability CVE-2025-66376 to silently exfiltrate government email credentials with no user interaction required, using a lure posing as a Belgian media-integrity verification organisation to ensure delivery to government targets involved in media or information policy.

  • Krebs on Security reported that inexpensive TV streaming sticks sold through major retailers secretly enroll in residential proxy networks and spoof mobile device identities to generate fraudulent clicks on AI-generated websites, creating a self-sustaining criminal revenue cycle in which consumers unknowingly subsidise ad fraud while advertisers fund traffic to synthetic content sites with no genuine readership.

  • FactCheck.org documented that President Trump misrepresented a CIA devil's advocacy analytical exercise as confirmed intelligence, falsely claiming the CIA found evidence that Venezuela had exactly manipulated US voting machines in 2020, when the exercise produced no such evidence, devil's advocacy being a technique designed to stress-test prevailing assessments, not produce validated findings.

  • Rest of World documented China's AI microdrama industry's systematic exploitation of human faces for AI-generated synthetic actors, with more than 95% of 128,000 microdramas produced in Q1 2026 using AI actors, ByteDance removing more than 85,000 unauthorised face reproductions, and Chinese courts logging 700 facial theft cases, illustrating the industrialisation of biometric data exploitation within a commercially legalised licensing framework.

  • Google's Q2 2026 Influence Operations Bulletin documented the termination of more than 3,500 YouTube channels and several domains across operations linked to China (1,763 channels), India (1,419 channels across five campaigns), Russia (558+ channels and two domains across five operations), Azerbaijan, Chile, Hungary, Spain, Venezuela, Iran, and more than a dozen campaigns without confirmed state attribution.


  • Cyfluence Research Center documented two hostile influence campaigns weaponizing nostalgia as a below-radar cognitive driver: a Russian-linked Facebook network embedding communist-era nostalgic affect across 12,790 posts targeting Romania, and PRC-aligned operations deploying five interlocking Ryukyuan nostalgic subthemes against Okinawa across X, YouTube, and Facebook with content surges correlated with official PRC diplomatic actions, identifying nostalgia as a structural cognitive threat vector that is largely invisible to automated detection systems.

[State Actors]


Russia

Storm-1516 Ran 45 Campaigns Against Armenia's Elections and Targeted France's Declared 2027 Candidate 

An investigation published by DFRLab states that the Atlantic Council's Digital Forensic Research Lab mapped the full digital infrastructure behind Storm-1516's interference campaign targeting Armenia's May 2026 parliamentary elections, identifying 45 distinct narrative campaigns that generated 149.5 million views on X, distributed by a network of more than 450 accounts including six core amplifier accounts responsible for the bulk of reach. The operation produced AI-generated articles and videos through two false-front website clusters formatted as apparent local news outlets, publishing content in Armenian, English, French, and Turkish, attributed to GRU Unit 29155 and following the network's documented template of fabricated infrastructure establishment before an electoral period, followed by coordinated amplification to manufacture the appearance of organic public concern.


Another article published by Meduza states that France's Viginum service attributed to Storm-1516 a campaign fabricating false health claims about Edouard Philippe, the former French Prime Minister and declared candidate for France's 2027 presidential election, described by a French security source as the first documented Storm-1516 campaign targeting a declared presidential candidate, one of 205 operations Viginum has attributed to the network since August 2023. Storm-1516 is assessed as active since 2023, linked to Russia's GRU, and its operator base includes former employees of Yevgeny Prigozhin's information operations infrastructure; the Philippe targeting fits a documented pattern of selecting political figures whose election would strengthen Western security architecture and deploying fabricated personal health or integrity claims that force candidates into public denials amplifying the original false claim regardless of the denial's success.


Sources: 

  1. DFRLab. Uncovering the Digital Infrastructure Behind Russian Interference in Armenian Elections. [online] Published 29 July 2026. Available at: https://dfrlab.org/2026/07/29/uncovering-the-digital-infrastructure-behind-russian-interference-in-armenian-elections/

  2. Meduza. Russian disinformation network Storm-1516 accused of targeting French presidential candidate Édouard Philippe with fake health claims. [online] Published 24 July 2026. Available at: https://meduza.io/en/news/2026/07/24/russian-disinformation-network-storm-1516-accused-of-targeting-french-presidential-candidate-edouard-philippe-with-fake-health-claims


Storm-1516 Used Fake BBC Video

A fact-check published by Lead Stories states that a fake video formatted as an authentic BBC news report falsely claimed Ukrainian First Lady Olena Zelenska was photographed wearing a stolen Lalique pendant at the Coalition of the Willing summit, with the pendant digitally inserted into genuine summit footage. The fabricated content generated 3.27 million views and 13,700 social media posts before the BBC publicly confirmed on July 27th, 2026, that the video was fake and did not originate from any BBC broadcast or publication. Lead Stories attributed the operation to Storm-1516, consistent with the network's documented use of established broadcaster brands to lend false credibility to fabricated content targeting Ukrainian national figures.


The publication states that the fake BBC video illustrates a core Storm-1516 operational technique: attaching fabricated narratives to visually authentic-appearing footage from genuine events, with broadcaster logos and graphic design elements reproduced to bypass credibility filters among audiences unfamiliar with the specific broadcast format being impersonated. The Zelenska pendant claim targets the First Lady of a wartime head of state and is consistent with Storm-1516's documented strategy of generating reputational damage narratives around Ukrainian national figures, a tactic effective even when quickly debunked, because the debunking process produces additional broadcast coverage of the original false claim and forces official Ukrainian institutions to expend credibility capital issuing denials.


Source: Lead Stories. Fact Check: FAKE BBC Report Claims Olena Zelenska Was Spotted Wearing Stolen Lalique Pendant. [online] Published 27 July 2026. Available at: https://leadstories.com/hoax-alert/2026/07/fact-check-fake-bbc-report-shows-zelenska-wearing-stolen-lalique-pendant.html


Russia Published 1,500 Articles Exploiting Spain's Ceuta Crisis Against Ukraine

An article published by European Pravda states that Ukrainian Foreign Minister Andrii Sybiha revealed that Russian state and state-aligned media published more than 1,500 articles exploiting Spain's Ceuta migration crisis to advance anti-Ukraine propaganda narratives across European audiences, deploying Pravda, RT, and affiliated outlets to link Ukrainian military assistance to EU-level migration pressures. Sybiha stated that Ukraine had uncovered and exposed the Russian propaganda campaign, which sought to leverage an active European migration crisis to shift European public opinion against continued support for Ukraine by connecting EU policy failures to the costs of the Ukraine conflict.


The article states that the Ceuta exploitation campaign illustrates a recurring Russian FIMI strategy of attaching anti-Ukraine messaging to genuine European domestic crises, a technique that requires no fabricated events, only the selective framing of real developments to support predetermined narratives. By deploying more than 1,500 publications across Pravda, RT, and affiliated platforms rather than relying on inauthentic amplification networks, the operation exploited the established reach of Russian state media infrastructure to distribute its messaging, making platform-level content removal less effective than would be the case for synthetically amplified material. The exposure by Sybiha follows a documented pattern of Ukrainian intelligence and diplomatic disclosure of active Russian information operations, designed to pre-emptively denature narratives before they achieve wider penetration in Western European media.


Source: European Pravda. Sybiha: Ukraine uncovers Russian propaganda campaign linked to crisis in Spanish city. [online] Published 31 July 2026. Available at: https://www.eurointegration.com.ua/eng/news/2026/07/31/7242718/


China

Spamouflage Deployed 62 Accounts Targeting Chilean Journalists

A report published by Graphika states that Spamouflage, the China state-aligned network also documented as Dragonbridge and Taizi Flood, deployed 62 inauthentic accounts across Facebook, Parler, Tumblr, and YouTube to suppress Chilean media coverage of copper smuggling investigations, targeting six named Chilean journalists with coordinated harassment and AI-generated content designed to discredit their reporting. The campaign, documented in a Graphika investigation titled Ore Else, combined AI-generated visual and text content with coordinated account volume to reduce the visibility of the targeted journalists' copper smuggling coverage and associate it with pro-industry counter-narratives.


The report states that the Ore Else investigation identifies the operation as a documented evolution for Spamouflage: rather than the geopolitical and election-focused targeting previously documented for the network, the infrastructure was here deployed to protect copper supply chain narratives of direct relevance to Chinese commercial interests, suggesting that the Spamouflage model is available not only for political influence objectives but for direct commercial information control in any sector where China holds strategic interests and where investigative journalism poses a reputational or supply chain risk. The use of four distinct platforms, including Parler and Tumblr alongside the more commonly monitored Facebook and YouTube, reflects an adaptive distribution strategy designed to maintain operational reach after platform enforcement actions on any single channel, a structural adaptation that limits the effectiveness of single-platform moderation responses.


Source: Graphika. Ore Else: Spamouflage Targets Chile’s Copper Smuggling Coverage. [online] Published 30 July 2026. Available at: https://www.graphika.com/reports/ore-else 


Fake AI Videos During Typhoon Noel Triggered Government Crackdown

An article published by BBC states that AI-generated videos falsely depicting catastrophic flood conditions during Typhoon Noel circulated widely on Chinese social media platforms, triggering panic-buying across regions where viewers could not verify on-the-ground conditions against the fabricated footage. The fabricated disaster content demonstrated the particular vulnerability of AI-generated disinformation during natural disaster events, where time pressure, communication disruption, and public anxiety create conditions in which synthetic emergency content can propagate rapidly before fact-checking or platform moderation systems respond.


The article states that the Cyberspace Administration of China issued an emergency enforcement action on July 23rd, 2026, specifically targeting AI-generated content misrepresenting disaster conditions, as the volume and apparent realism of synthetic flood videos became significant enough to require direct state intervention. The Noel flooding episode illustrates a tension within China's AI content regulation framework: AI-generated synthetic media is an official development priority sector, while uncoordinated AI content that disrupts public order represents a direct challenge to state information control. The emergency crackdown focused on content capable of generating public panic, leaving unresolved the broader question of how platform-level accountability for synthetic disaster content should be institutionalised within China's existing AI regulatory architecture.


Source: BBC News. Trump says Iran war talks taking place during lull in strikes. [online] Published 24 June 2026. Available at: https://www.bbc.co.uk/news/articles/cx27mjvxgg1o 

[Cyfluence Attacks]


Laundry Bear Steals Government Emails Without User Interaction

An article published by Nextgov/FCW states that a joint advisory from cybersecurity agencies warned that Russian-linked threat actor Laundry Bear is exploiting Zimbra email server vulnerability CVE-2025-66376 to silently exfiltrate government email credentials without any user interaction, no link click, no attachment open, no action of any kind required from the target. The zero-click exploit delivers the credential theft payload when the target's Zimbra server receives and processes a specially crafted email, with the initial lure formatted as communications from a Belgian media-integrity verification organisation, designed to ensure delivery to government and public sector recipients involved in media or information policy.


The article states that the Laundry Bear operation merges cyber exploitation with influence infrastructure deception: the lure delivering the zero-click exploit is itself a false-flag persona organization, a fake Belgian media-verification body, whose institutional framing is specifically calibrated to be credible to the government email recipients targeted. This combination of a zero-interaction technical exploit with a persona-organisation social engineering lure represents an escalation in operational sophistication, as it eliminates the human-action dependency that has historically been the primary point of failure and detection in spear-phishing campaigns. Government email systems compromised via CVE-2025-66376 expose the full contents of targeted accounts without any audit trail of the initial infection trigger, creating a covert intelligence collection capability with no forensic footprint at the user level.


Source: Nextgov/FCW. Russian hackers can steal government emails without victims clicking a link, cyber agencies warn. [online] Published 24 July 2026. Available at: https://www.nextgov.com/cybersecurity/2026/07/russian-hackers-can-steal-government-emails-without-victims-clicking-link-cyber-agencies-warn/414967/


[AI Related Articles]


EU AI Act Transparency Enforcement Begins

An announcement published by the European Commission states that from August 2nd, 2026, the AI Act's transparency framework requires AI systems to disclose they are not human at first contact with users, deepfakes to be explicitly labelled, and AI-generated or altered content to carry machine-readable marks enabling automated platform and regulatory detection. High-risk AI systems in regulated products are deferred to August 2028 and high-risk applications in recruitment, credit scoring, and law enforcement to December 2027; IBTimes UK confirmed that more than 180 organisations, including Meta across Facebook, Instagram, and Threads, signed the voluntary Code of Practice on transparency of AI-generated content ahead of the mandatory enforcement date, with the Commission's AI Office and national authorities across all 27 EU member states activating documentation compulsion, technical evaluation authority, and penalties calibrated to global annual turnover from  August 2nd, 2026.


Another article published by The Next Web states that enforcement faces a central operational vulnerability: watermarks can be stripped, metadata can be lost in format conversions, and machine-written text is notoriously difficult to detect automatically, making the transparency framework only as effective as the detection tools that back it, tools that remain commercially inconsistent in 2026. A possible simplification package could defer machine-marking obligations to December 2026 while maintaining chatbot disclosure from August 2026; carve-outs exempt clearly unrealistic or fantastical content, machine-written text reviewed by humans with genuine editorial responsibility, and artistic or satirical content with appropriate disclosure. The EU regime is anticipated to shape worldwide labelling practices as platforms standardize compliance globally; Meta's voluntary pre-enforcement signature on the Code of Practice is a commitment whose gap with actual implementation will constitute the first test of the AI Office's enforcement authority from  August 2nd, 2026.


Sources: 

  1. European Commission. Commission starts enforcing AI Act rules and new transparency requirements from 2 August. [online] Published 3 August 2026. Available at: https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august

  2. The Next Web. EU AI Act labels become compulsory for synthetic content. [online] Published 31 July 2026. Available at: https://thenextweb.com/news/eu-ai-act-labels-compulsory-synthetic-content


[General Reports]


Cheap Streaming Sticks Secretly Click Ads on AI-Generated Sites via Residential Proxy Networks

An article published by Krebs on Security states that inexpensive TV streaming sticks sold through major online retailers secretly enroll in commercial residential proxy networks without user knowledge or consent, renting out the devices' internet connections and spoofing them as mobile phone identities to generate fraudulent advertisement clicks on AI-generated websites. The scheme creates a criminal revenue model in which consumers unknowingly contribute their home bandwidth and IP reputation to ad fraud operations, while advertisers are billed for traffic to AI-generated content sites that have no genuine human readership.


The article states that the scheme is structurally self-sustaining: device manufacturers sell sticks at prices partially subsidised by proxy enrolment revenue, making the fraud model profitable at the device supply level before any advertising click is generated. Advertisers pay programmatic systems for traffic that spoofed mobile device identities are specifically designed to pass through standard detection filters, and AI-generated content sites collecting per-click payments require no ongoing human content creation costs. No single intervention point is sufficient to collapse the scheme; eliminating proxy enrolment requires manufacturer-level accountability that current retail supply chains do not enforce, eliminating fraudulent traffic requires ad network reforms that programmatic buying architectures are not designed to deliver, and the replacement cost for deplatformed AI-generated content sites approaches zero.


Source: Krebs on Security. Read This Before You Buy That TV Streaming Stick. [online] Published 30 July 2026. Available at: https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/ 


Trump Distorted CIA Intelligence to Claim Venezuela Manipulated US Voting

A fact-check publication by FactCheck.org states that President Trump publicly cited CIA intelligence to claim Venezuela had exactly manipulated US voting machines during the 2020 election, misrepresenting a CIA analytical technique known as devil's advocacy, in which analysts deliberately argue against prevailing assessments to test their robustness, as a confirmed intelligence finding. FactCheck.org's review found that the CIA devil's advocacy exercise produced no evidence of Venezuelan interference with US voting systems, and that the technique's design and purpose are explicitly to generate stress-test arguments rather than validated intelligence conclusions.


The misrepresentation of intelligence methodology, presenting a process that explicitly did not produce a finding as the source of that finding, represents a structurally effective disinformation technique because institutional credibility attaches to the citing organization rather than to the specific analytical output being claimed: a CIA process carries inherent authority in public perception regardless of what that specific process concluded. Debunking this category of claim requires communicating both that the specific assertion is false and that the cited analytical method is structurally incapable of producing the type of validated intelligence finding described, a two-step correction that is considerably harder to convey than the original single-step assertion. FactCheck.org assessed Trump's claim as false.


Source: FactCheck.org. Trump’s Distorted Venezuela Elections Claim. [online] Published 23 July 2026. Available at: https://www.factcheck.org/2026/07/trumps-distorted-venezuela-elections-claim/


China's AI Microdrama Industry Harvests Faces at Scale

An article published by Rest of World states that China's AI-powered microdrama industry has industrialised the use of synthetic actors based on real human faces, with more than 95% of 128,000 microdramas produced in Q1 2026 using AI-generated actors, generating a commercial market in which individuals rent their facial likeness for AI reproduction in exchange for payments. ByteDance removed more than 85,000 unauthorised face reproductions from its platforms during the period reviewed, and Chinese courts have logged 700 facial theft cases from creators whose likenesses were used without consent, establishing the scale of unconsented biometric exploitation within a framework that simultaneously permits licensed use.


An article published by Rest of World states that China's face-licensing ecosystem creates a two-tier commercial structure: a legal tier in which individuals consciously sell facial licensing rights for AI reproduction in entertainment, and an illicit tier in which faces are copied, modified, and deployed without consent or payment, with the legal tier normalising the infrastructure the illicit tier exploits. In the context of information integrity, the systematic commercial development of large, licensed datasets of real human faces for AI-generated synthetic actors represents an industrial-scale capability for producing indistinguishable synthetic human likenesses, a foundational capability layer applicable to AI-generated synthetic media in disinformation contexts. The ByteDance enforcement actions and 700 court cases document only cases reaching formal resolution; total unconsented face use in AI microdramas is substantially larger.


Source: Rest of World. In China, people are renting out their faces to AI. [online] Published 27 July 2026. Available at: https://restofworld.org/2026/china-ai-microdramas-face-licensing/


Influence Operations Bulletin Q2 2026

Google's Q2 2026 Influence Operations Bulletin covers coordinated influence operations terminated on its platforms between April and June 2026.


In China, 1,763 YouTube channels were terminated as part of an ongoing investigation into a coordinated inauthentic network linked to the People's Republic of China. The network was uploading content in Chinese and English focused on China-US foreign affairs. An additional 2 Blogger blogs linked to China were terminated for sharing pro-China content in English and Chinese.


In Russia, five separate operations were identified and actioned. The largest involved 505 YouTube channels linked to a named Russian consulting firm sharing content in Russian that was supportive of Russia and critical of Ukraine, NATO, and the West. A second operation involved 28 YouTube channels sharing content in Hungarian supportive of a Hungarian political party. A third operation involved 23 YouTube channels sharing content in Russian supportive of Russia and critical of Moldova. A fourth involved 2 YouTube channels sharing content in Armenian critical of the Armenian government. Additionally, one domain was blocked from eligibility to appear on Google News and Discover for sharing content in Portuguese supportive of Russia and critical of the United States. One further domain linked to the Czech Republic was blocked for sharing content in Czech associated with Russian state media.


In India, five separate operations were terminated during the quarter. The largest involved 992 YouTube channels sharing content in Hindi and Marathi supportive of an Indian political party. The remaining four operations involved 236, 108, 49, and 34 channels respectively, operating in English, Hindi, Punjabi, and Tamil, all supportive of Indian political parties. Combined, Indian-linked operations accounted for more than 1,419 channel terminations in a single quarter. 


In Azerbaijan, 132 YouTube channels were terminated for sharing content in Azerbaijani supportive of Azerbaijan and critical of Armenia and critics of the Azerbaijani government. In Chile, 110 YouTube channels were terminated for sharing content in Spanish critical of one candidate in Colombia's 2026 presidential election and supportive of another. In Hungary, 105 YouTube channels were terminated for sharing content in Hungarian critical of a Hungarian political party. In Spain, 54 YouTube channels were terminated for sharing content in Spanish critical of the Spanish government. In Venezuela, 43 YouTube channels were terminated for sharing content in English and Spanish supportive of Venezuela. In Argentina, 13 YouTube channels were terminated for sharing content in Spanish supportive of a candidate in Colombia's 2026 presidential election. In Iran, 2 YouTube channels were terminated for sharing content in English and French supportive of Iran and critical of Israel and the United States.


Among campaigns without confirmed state attribution, Google terminated 49 YouTube channels sharing content in English and Zulu supportive of a South African political party and critical of the South African government; 44 channels in Arabic critical of the Iraqi government; 31 channels in Ukrainian critical of the Ukrainian government; 93 channels in Indonesian and Malay supportive of the Malaysian government; 50 channels in English and Urdu supportive of the Pakistani military and government; 30 channels in Belarusian critical of the Belarusian government; 22 channels in Korean supportive of South Korean political figures; and multiple operations targeting Indonesian, Japanese, Turkish, Italian, Armenian, and Paraguayan audiences across a range of supportive and critical narratives. Additional smaller operations were recorded across further languages and regions.



[Appendix - Frameworks to Counter Disinformation]


Weaponized Nostalgia Identified as Below-Radar Cognitive Threat

A report published by the Cyfluence Research Center states that CRC documented two empirical case studies of hostile influence campaigns weaponizing nostalgia as their primary psychological driver: a Russian-linked network of 75 or more Facebook pages in Romania embedding nostalgic affect across 12,790 posts through implicit references to the communist era, and PRC-aligned campaigns across X, YouTube, and Facebook targeting Okinawa with five interlocking Ryukyuan nostalgic subthemes, with content surges correlated with official PRC diplomatic actions and state media activity, indicating deliberate coordination between state narrative-setting outlets and inauthentic amplification clusters. CRC identified 78 X accounts associated with the Okinawa-targeting network, the majority suspended at the time of publication, alongside a Facebook infrastructure including an Okinawan Independence page and a group promoting cessation of US base construction, both assessed as advancing PRC-aligned geopolitical narratives.


The report states that nostalgia functions as a below-radar ambient emotion that does not announce itself as political, unlike high-arousal negative emotions such as anger or outrage, nostalgic content circulates as cultural celebration, religious reflection, or communal memory and remains largely invisible to automated narrative detection systems, making it a structurally effective cognitive threat vector that is slow to produce measurable indicators and difficult to attribute to hostile actors. CRC analysis identifies a dual-strand PRC influence strategy: nostalgia narratives delegitimize the present by measuring it against a romanticized past rendered wrongly lost, while parallel techno-utopian narratives measure it against a Chinese-led future only PRC alignment can deliver, addressing target audiences simultaneously from both temporal directions so that the present is rendered inadequate from both sides without any individual content stream announcing a coordinated agenda. Counter-messaging and prebunking face a structural challenge because directly challenging nostalgic content risks appearing hostile to legitimate cultural expression or identity, requiring influence defense practitioners to engage the emotional register of the content rather than relying solely on factual rebuttal.


Source: Cyfluence Research Center. Research Section. [online] Available at: https://www.cyfluence-research.org/research-section


[CRC Glossary]


The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult.


To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence.


As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website.










 
 
bottom of page