Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Influence Operations🇨🇳 CN

Spamouflage

Also known asDragonbridgeSpamouflageTaizi Flood

Spamouflage is a Beijing-backed, People’s Republic of China-aligned influence operation, also known as Dragonbridge, Storm 1376, and Taizi Flood. The content describes it as a pro-CCP network previously attributed by Twitter to the Chinese government in 2019, publicly attributed by Meta in 2023 to Chinese law enforcement, and described by OpenAI in 2026 as tied directly to Chinese law enforcement-linked covert influence and harassment activity. The actor conducts coordinated information operations across major social media platforms using large numbers of inauthentic accounts and fabricated personas. Reported activity includes impersonating U.S. voters and U.S.-based users on X and TikTok to influence discourse around U.S. elections; spreading divisive narratives about candidates, election integrity, gun control, homelessness, the Israel-Hamas conflict, and racial inequality; and operating fake media personas and outlets such as Deep Red / “Common fireman” and Harlan Report. Graphika reported that Spamouflage expanded since mid-2023 from low-quality generic personas to more developed personas posing as patriots, veterans, soldiers, and disappointed American voters. The content also describes coordinated harassment and digital transnational repression activity attributed to another iteration of the Spamouflage network. ASPI assessed that inauthentic Twitter accounts likely linked to Spamouflage targeted prominent women of Asian descent, especially journalists and human rights activists who report on China, with mass trolling, sexist and racist abuse, threats, and highly personalized harassment. Targets mentioned include Jiayang Fan, Muyi Xiao, Xinyan Yu, Alice Su, Mei Fong, Lingling Wei, and Jane Li. Indicators cited include coordinated account creation, use of stolen or AI-generated profile images, bilingual English/Mandarin activity, posting patterns aligned with Beijing business hours, and reuse of narratives linked to prior pro-CCP messaging on Xinjiang, Covid-19, Ukraine, and other geopolitical issues. OpenAI’s 2026 reporting further describes a ChatGPT account allegedly linked to an individual associated with Chinese law enforcement that was used to edit and polish status reports for large-scale covert operations tied directly to Spamouflage. According to the content, these operations spanned hundreds of foreign social media platforms and thousands of fake accounts, targeting dissidents, human rights groups, and foreign officials. Reported tactics included coordinated influence, harassment, suppression of critics of the CCP, fake email accounts, forged documents, fabricated obituary and gravestone imagery, and use of other AI models for monitoring, profiling, and content creation. Named targets in that reporting include Japanese politician Sanae Takaichi, activist Li Ying, Safeguard Defenders, and dissident Jie Lijian. Google also observed Dragonbridge content disseminated through GLASSBRIDGE-operated inauthentic news and newswire networks that published PRC-aligned content for audiences outside China, indicating Spamouflage/Dragonbridge content distribution through broader deceptive media ecosystems.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Media & Entertainment

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

1 of 15 tactics2 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1585×2
Establish Accounts
T1585.001
Social Media Accounts
ACTIVITY FEED

Recent activity

10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping2

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.