This page takes apart real, documented influence operations: who ran them, how they were staffed and funded, what they posted, how it spread and how they were caught. It draws only on published investigations, court records and platform takedown reports, and it covers states and domestic operatives on every side, including the United States and its allies.
It is written so you can recognise and counter these methods. It describes how operations were built, as the public record documents them; it doesn't give instructions for building one. Everything here is in the Deception band of Fair, grey or deception: where each archive technique sits: none of it has an honest form, because each one works by hiding who is speaking.
The common anatomy
Across the cases below, investigators describe the same six parts. Knowing them tells you where to look.
- Sponsor and operator. A state agency, a contractor, a PR or marketing firm, or a party-aligned operative. Operators are often one step removed from sponsors, which makes attribution harder.
- Assets. Fake personas, pages and groups, sometimes cloned news sites or brand-new "institutes". Personas are built to look like members of the target audience (Plain folks).
- Content production. Writers and translators working to themes and quotas, increasingly with machine-generated text, faces, voices and video (Synthetic media).
- Amplification. Cross-posting between assets, paid ads, paid real influencers, comment brigades on real people's posts (Astroturfing, Manufactured consensus).
- Laundering. Getting the message picked up by real people, real outlets or search engines, so its origin disappears (Narrative laundering, Corpus poisoning, Sleeper effect).
- Detection and takedown. Researchers, journalists or platforms link the assets through shared infrastructure, behaviour or leaked documents, then publish and remove them.
Case files
Internet Research Agency (Russia, 2013–2018)
- Operator and funding. A St Petersburg company. A US federal indictment (2018) alleged it was funded through companies controlled by Yevgeniy Prigozhin, and that its US-focused "translator project" had more than 80 staff by July 2016 and a monthly budget for its wider "Project Lakhta" of over $1.25 million by September 2016.
- Assets and content. Personas and pages across the US political spectrum, including "Blacktivist", "United Muslims of America", "Heart of Texas", "Being Patriotic" and "Army of Jesus". Content leaned heavily on identity and grievance (Identity fusion, Outrage bait). Research for the US Senate found Instagram drew more engagement than Facebook.
- Scale. Facebook told Congress in 2017 that IRA content may have reached about 126 million users, and that the IRA bought about 3,500 ads for roughly $100,000. Twitter identified 3,814 IRA-linked accounts.
- Offline. In May 2016 IRA pages organised opposing protests at the same Houston location on the same day, one against and one in support of an Islamic centre.
- Detection. Platform investigations after the 2016 election, congressional hearings, the 2018 indictment and the Senate Intelligence Committee's 2019 report.
- Measured effect. A study of US Twitter users found exposure to IRA tweets in 2016 was concentrated among a small group of highly partisan users, and found no measurable relationship between exposure and changes in attitudes, polarisation or voting (Eady et al., 2023). On this measure, exposure to the operation's tweets was not associated with measurable effects.

'Russian Ads on Facebook' (House Intelligence Committee exhibit). Page 34 of the US House Permanent Select Committee on Intelligence report on Russian active measures (2018), reproducing Facebook pages run by the Internet Research Agency under names such as "Blacktivist", "Being Patriotic" and "LGBT United". Public domain (US government work).

'Miners for Trump' rally poster (Internet Research Agency). "Miners for Trump" rally poster, October 2016, reproduced in Volume I of the Special Counsel's report (US Department of Justice, 2019). The Internet Research Agency used it to promote rallies in Pittsburgh and Philadelphia. Public domain (US government work).
Doppelganger (Russia, 2022 onwards)
- Operator. Meta attributed the network in 2022 to two Russian companies, Structura National Technologies and the Social Design Agency. The EU sanctioned both in 2023. See the archive dossier Russia Social Design Agency — Projects 2026.
- Assets and content. Cloned websites imitating real European outlets, including Der Spiegel, Bild and The Guardian, carrying fake articles, mostly about the war in Ukraine and sanctions (EU DisinfoLab, 2022).
- Amplification. Fake accounts and paid ads pointed to the clones, often through redirect links.
- Detection. EU DisinfoLab's 2022 investigation, repeated platform takedowns, and in September 2024 a US Justice Department seizure of 32 internet domains, with court filings that released internal planning documents.
Spamouflage, also called Dragonbridge (China, 2019 onwards)
- Assets and content. A very large, very high-volume network across dozens of platforms, praising the Chinese government and attacking its critics, later posting on US politics (Firehosing). Graphika named it in 2019.
- Scale and attribution. In August 2023 Meta removed about 7,700 Facebook accounts and called it the largest known cross-platform covert operation, linking it to individuals associated with Chinese law enforcement.
- Synthetic media. Graphika (2023) documented it posting videos of AI-generated news anchors for a fictitious outlet, "Wolf News".
- Effect. Investigators consistently found little authentic engagement; much of its reach came from its own accounts. See also PRC-linked AI content farms targeting Taiwan.
US military anti-vaccine campaign (Philippines, 2020–2021)
- Operator. A Reuters investigation (2024) reported that the US military ran a clandestine campaign during the COVID-19 pandemic, using at least 300 accounts on X and others elsewhere, to undermine confidence in China's Sinovac vaccine in the Philippines.
- Content. Posts posing as Filipinos questioned the vaccine's ingredients and effectiveness (Fear appeal, Astroturfing), at a time when Sinovac was the main vaccine available there.
- Detection. Reuters' reporting, based on interviews with current and former officials and analysis of accounts. See also the archive dossier CENTCOM / Pentagon “gc_” newsroom network.
US and UK covert operations (Middle East and Central Asia, about 2017–2022)
- Findings. Graphika and the Stanford Internet Observatory (2022) analysed networks that Twitter and Meta removed for promoting the interests of the US and its allies and opposing countries including Russia, China and Iran, including fake personas, some with AI-generated faces, and accounts posing as independent media.
- Attribution. Twitter said the accounts originated in the United States and United Kingdom; Meta attributed the activity it removed to individuals associated with the US military.
- Effect. The report found most of the accounts drew little authentic engagement.
STOIC (Israel, 2024)
- Operator. Meta (May 2024) removed a network run by STOIC, a political marketing firm in Tel Aviv, that targeted audiences in the US and Canada. OpenAI reported disrupting the same operation's use of its models in the same month.
- Content. Fake personas posing as students, African Americans and concerned citizens commented on posts by news outlets and US lawmakers about the war in Gaza.
- Sponsor. The New York Times reported in June 2024 that Israel's Ministry of Diaspora Affairs organised and paid for the campaign.
Endless Mayfly (Iran-aligned, 2016–2019)
- Method. Citizen Lab (2019) documented a network that impersonated real news sites with look-alike domains, published false stories, amplified them through personas, then deleted the fake articles once they had been picked up, leaving the claims circulating without their source (Sleeper effect). See also Iran-origin Meta CIB — fake US activist personas (H2 2026).
"Project Birmingham" (US, Democratic-aligned, 2017)
- What happened. The New York Times reported in December 2018 that a group of Democratic-aligned technologists ran a covert social media effort during Alabama's 2017 special Senate election. An internal report described a "false flag" operation to create the impression that Republican Roy Moore's campaign was being boosted by Russian bot accounts, and a Facebook page aimed at splitting conservative votes.
- Funding. About $100,000, from money provided by the investor Reid Hoffman, who apologised and said he had not known of the tactics. A participant described it as a research experiment.
- Response. Facebook suspended several accounts involved.
Rally Forge and Turning Point Action (US, Republican-aligned, 2020)
- What happened. The Washington Post reported in September 2020 that a marketing firm, Rally Forge, working for the conservative group Turning Point Action, paid young people in Phoenix, some of them minors, to post near-identical pro-Trump messages from their own accounts without disclosing the arrangement (Astroturfing).
- Response. Facebook and Twitter removed accounts, and Facebook later banned Rally Forge. Turning Point Action said the posts were sincere political activism by real people.
Deepfakes in elections and war

'Gennady Rakitin,' an invented pro-war poet. The AI-generated profile photo of "Gennady Rakitin", an invented pro-war poet presented on the Russian network VKontakte from mid-2023. Reported in the archive's gallery entry; no human author.
- Ukraine, March 2022. A fabricated video of President Zelensky telling troops to lay down their arms appeared on a hacked Ukrainian news site. Ukraine's government had warned in advance that such a video might appear, and it was quickly debunked and removed.
- Slovakia, September 2023. Days before the parliamentary election, during the pre-vote media moratorium, fabricated audio circulated of Progressive Slovakia's leader Michal Šimečka and a journalist apparently discussing rigging the vote. Fact-checkers found signs of AI generation.
- United States, January 2024. Before the New Hampshire primary, robocalls used an AI-generated imitation of President Biden's voice telling Democrats not to vote. The political consultant who commissioned them had worked for a rival Democratic candidate's campaign, which said it didn't know. The FCC fined him $6 million and ruled that AI-generated voices in robocalls fall under existing robocall law.
The same anatomy from another operator: the Hanover Institute (Israel and United States, 2026)
A website styled as a U.S. think tank, with no named staff, published 124 unsigned reports in about a week that Politico's tests found chatbots citing. Filings under the U.S. Foreign Agents Registration Act name Israel's Government Advertising Agency as the foreign principal, working through contractors; the disclosure sits in the site's footer (Politico Influence, 14 August 2026). It has two features of the anatomy described above: a site presented as a think tank, and a foreign principal named in filings and a footer rather than in the reports themselves. See The Hanover Institute: reports written for chatbots to cite.
The Hanover Institute case as drawn for The Hanover Institute: reports written for chatbots to cite. Drawn by FRAME from the sources listed on that page.
How to spot them
The tells below come from the investigations above and from the archive's technique pages.
| Signal | What to check | Technique |
|---|---|---|
| Many "ordinary people" saying the same thing in the same words | Search the exact phrase; check account ages, posting times and profile photos | Astroturfing |
| A face that looks slightly off, a voice with no source | Reverse image search; look for provenance data; ask who first posted it | Synthetic media |
| A news site you half-recognise | Check the domain letter by letter; go to the outlet's real homepage and look for the story | Narrative laundering |
| A new "institute" or "study" everyone is citing | Who are its staff and funders? When was the domain registered? | Corpus poisoning, Narrative laundering |
| Many outlets, one talking point | Find the first appearance and trace who copied whom | Manufactured consensus |
| A torrent of contradictory claims | Track them over a week; if the story keeps changing, volume is the message | Firehosing, Flooding the zone |
| A funding label on the website but not on the clip | Is the disclosure on the thing people actually see? | Disclosure theater |
| A claim you "heard somewhere" | Can you still find where it came from? | Sleeper effect |
How to counter them
- Read laterally. Professional fact-checkers leave a site and search for what others say about it, instead of reading it closely (Wineburg & McGrew, 2019).
- Prebunk. Warning people in advance about a technique, with a weakened example, builds resistance to it, for audiences across the political spectrum (Roozenbeek & van der Linden, 2019; Roozenbeek et al., 2022). Ukraine's advance warning about a Zelensky deepfake is a real-world case.
- Use provenance. Content credentials (the C2PA standard) and platform ad libraries show who made or paid for content.
- Don't amplify to debunk. Repeating a false claim to rebut it can spread it. Lead with the truth, mention the falsehood once, explain why it's wrong, and repeat the truth (Continued influence effect, Illusory truth effect).
- Report, with evidence. A documented pattern gives platform reporting channels and researchers something to check; a hunch about "bots" does not.
- Don't cry "bot" at people you disagree with. Most accounts that disagree with you are real. Calling real opponents fake is its own distortion.
Sources
- United States v. Internet Research Agency LLC et al., Indictment, No. 1:18-cr-00032 (D.D.C., 16 February 2018).
- US Senate Select Committee on Intelligence (2019). Russian Active Measures Campaigns and Interference in the 2016 U.S. Election, Vol. 2: Russia's Use of Social Media.
- DiResta, R. et al. (2018). The Tactics & Tropes of the Internet Research Agency. New Knowledge, for the Senate Select Committee on Intelligence.
- Howard, P. N., Ganesh, B., Liotsiou, D., Kelly, J. & François, C. (2018). The IRA, Social Media and Political Polarization in the United States, 2012–2018. Oxford Internet Institute.
- Eady, G. et al. (2023). Exposure to the Russian Internet Research Agency foreign influence campaign on Twitter in the 2016 US election and its relationship to attitudes and voting behavior. Nature Communications, 14, 62.
- Alaphilippe, A., Machado, G., Miguel, R. & Poldi, F. (2022). Doppelganger: Media clones serving Russian propaganda. EU DisinfoLab.
- Meta (2022). Taking down coordinated inauthentic behavior from Russia and China, September 2022.
- US Department of Justice (2024). Announcement of the seizure of 32 internet domains used in Russian government-directed influence campaigns, 4 September 2024.
- Nimmo, B., François, C., Eib, C. S. & Ronzaud, L. (2019). Cross-platform spam network targeted Hong Kong protests: "Spamouflage Dragon". Graphika.
- Meta (2023). Quarterly Adversarial Threat Report, Q2 2023, August 2023.
- Graphika (2023). Deepfake It Till You Make It: Pro-Chinese actors promote AI-generated video footage of fictitious people.
- Bing, C. & Schechtman, J. (2024). Pentagon ran secret anti-vax campaign to undermine China during pandemic. Reuters, 14 June 2024.
- Graphika & Stanford Internet Observatory (2022). Unheard Voice: Evaluating five years of pro-Western covert influence operations.
- Meta (2024). Quarterly Adversarial Threat Report, Q1 2024, May 2024.
- OpenAI (2024). AI and covert influence operations: Latest trends, May 2024.
- Frenkel, S. (2024). Israel secretly targeted American lawmakers with campaign on Gaza war. The New York Times, 5 June 2024.
- Lim, G., Maynier, E., Scott-Railton, J., Fittarelli, A., Moran, N. & Deibert, R. (2019). Burned After Reading: Endless Mayfly's Ephemeral Disinformation Campaign. Citizen Lab.
- Shane, S. & Blinder, A. (2018). Secret experiment in Alabama Senate race imitated Russian tactics. The New York Times, 19 December 2018.
- Stanley-Becker, I. (2020). Pro-Trump youth group enlists teens in secretive campaign likened to a 'troll farm'. The Washington Post, 15 September 2020.
- US Federal Communications Commission (2024). Declaratory Ruling on AI-generated voices under the Telephone Consumer Protection Act (February 2024) and Forfeiture Order against Steve Kramer (September 2024).
- Wineburg, S. & McGrew, S. (2019). Lateral reading and the nature of expertise. Teachers College Record, 121(11).
- Roozenbeek, J. & van der Linden, S. (2019). Fake news game confers psychological resistance against online misinformation. Palgrave Communications, 5, 65.
- Roozenbeek, J., van der Linden, S., Goldberg, B., Rathje, S. & Lewandowsky, S. (2022). Psychological inoculation improves resilience against misinformation on social media. Science Advances, 8(34).
Images
| Image | Source | Licence |
|---|---|---|
| IRA Facebook pages, HPSCI report p. 34 | FRAME gallery, 'Russian Ads on Facebook' (House Intelligence Committee exhibit) | Public domain (US government work) |
| "Miners for Trump" poster | FRAME gallery, 'Miners for Trump' rally poster (Internet Research Agency) | Public domain (US government work) |
| "Gennady Rakitin" AI profile photo | FRAME gallery, 'Gennady Rakitin,' an invented pro-war poet | Public domain (AI-generated, no human author) |
| Hanover Institute case diagram | Drawn for FRAME (see The Hanover Institute: reports written for chatbots to cite) | CC BY 4.0, FRAME |
Techniques
Related
- Fair, grey or deception: where each archive technique sits
- Before you publish: the fair-play check
- Astroturfing
- Synthetic media
- Narrative laundering
- Manufactured consensus
- Russia Social Design Agency — Projects 2026
- CENTCOM / Pentagon “gc_” newsroom network
- Iran-origin Meta CIB — fake US activist personas (H2 2026)
- PRC-linked AI content farms targeting Taiwan