Spamouflage
Spamouflage is a Beijing-backed, People’s Republic of China-aligned influence operation, also known as Dragonbridge, Storm 1376, and Taizi Flood. The content describes it as a pro-CCP network previously attributed by Twitter to the Chinese government in 2019, publicly attributed by Meta in 2023 to Chinese law enforcement, and described by OpenAI in 2026 as tied directly to Chinese law enforcement-linked covert influence and harassment activity. The actor conducts coordinated information operations across major social media platforms using large numbers of inauthentic accounts and fabricated personas. Reported activity includes impersonating U.S. voters and U.S.-based users on X and TikTok to influence discourse around U.S. elections; spreading divisive narratives about candidates, election integrity, gun control, homelessness, the Israel-Hamas conflict, and racial inequality; and operating fake media personas and outlets such as Deep Red / “Common fireman” and Harlan Report. Graphika reported that Spamouflage expanded since mid-2023 from low-quality generic personas to more developed personas posing as patriots, veterans, soldiers, and disappointed American voters. The content also describes coordinated harassment and digital transnational repression activity attributed to another iteration of the Spamouflage network. ASPI assessed that inauthentic Twitter accounts likely linked to Spamouflage targeted prominent women of Asian descent, especially journalists and human rights activists who report on China, with mass trolling, sexist and racist abuse, threats, and highly personalized harassment. Targets mentioned include Jiayang Fan, Muyi Xiao, Xinyan Yu, Alice Su, Mei Fong, Lingling Wei, and Jane Li. Indicators cited include coordinated account creation, use of stolen or AI-generated profile images, bilingual English/Mandarin activity, posting patterns aligned with Beijing business hours, and reuse of narratives linked to prior pro-CCP messaging on Xinjiang, Covid-19, Ukraine, and other geopolitical issues. OpenAI’s 2026 reporting further describes a ChatGPT account allegedly linked to an individual associated with Chinese law enforcement that was used to edit and polish status reports for large-scale covert operations tied directly to Spamouflage. According to the content, these operations spanned hundreds of foreign social media platforms and thousands of fake accounts, targeting dissidents, human rights groups, and foreign officials. Reported tactics included coordinated influence, harassment, suppression of critics of the CCP, fake email accounts, forged documents, fabricated obituary and gravestone imagery, and use of other AI models for monitoring, profiling, and content creation. Named targets in that reporting include Japanese politician Sanae Takaichi, activist Li Ying, Safeguard Defenders, and dissident Jie Lijian. Google also observed Dragonbridge content disseminated through GLASSBRIDGE-operated inauthentic news and newswire networks that published PRC-aligned content for audiences outside China, indicating Spamouflage/Dragonbridge content distribution through broader deceptive media ecosystems.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Media & Entertainment
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-aligned influence operation actor using generative AI content to scale political influence campaigns on social media.
China-linked covert influence/harassment operation attributed to Chinese law enforcement, using large-scale coordinated inauthentic behavior across many social platforms to target dissidents, human rights groups, and foreign officials; includes doxxing, fabricated evidence, and AI-generated content/memes.
Chinese influence operation using fake personas across social media platforms to spread divisive narratives about U.S. elections, impersonate U.S. voters, and amplify politically polarizing content.
A pro-CCP information operation network conducting coordinated online harassment, disinformation, and intimidation campaigns against journalists and human rights activists, especially women of Asian descent, across Twitter and other platforms.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.