Spamouflage, also known as Dragonbridge, Taizi Flood, and Storm-1376, is a long-running PRC-origin covert influence operation assessed to be aligned with Chinese government interests. Meta has attributed the activity to individuals associated with Chinese law enforcement, and the FBI has attributed portions of its social-media activity to a unit within China’s Ministry of Public Security. The operation promotes PRC-aligned narratives, attacks critics of the Chinese government, and seeks to influence political discourse abroad. The network operates large numbers of inauthentic accounts across social-media, blogging, forum, and video-sharing platforms. It uses fabricated personas, impersonation, coordinated posting, abusive replies, false reporting, and harassment to amplify narratives and suppress or discredit dissidents, journalists, human-rights advocates, and other CCP critics. Documented activity includes doxxing and smear campaigns, targeted harassment of members of the Chinese diaspora, and attempted manipulation of discourse surrounding US elections, Japanese politics, Hong Kong democracy activists, Fukushima wastewater, and rare-earth production. Spamouflage content is principally Chinese-language but also appears in English, Japanese, Korean, and other languages. Its operators have used generative AI for research, translation, content drafting, social-media analysis, persona development, and operational documentation, although AI-generated material represents only a minority of observed output. The operation has generally achieved limited authentic engagement, though some individual persona-based campaigns have attained materially greater reach. Its activity is also associated with transnational repression: coordinated online intimidation, impersonation, fabricated allegations, and efforts to silence overseas critics of the CCP.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PRC-origin influence network previously used inauthentic social media accounts to denigrate rare earth companies in North America and is cited here as a parallel for similar reputation-harm operations against strategically important firms.
China-aligned influence operation actor using generative AI content to scale political influence campaigns on social media.
China-linked covert influence/harassment operation attributed to Chinese law enforcement, using large-scale coordinated inauthentic behavior across many social platforms to target dissidents, human rights groups, and foreign officials; includes doxxing, fabricated evidence, and AI-generated content/memes.
A China-linked covert influence and transnational repression operation. It uses coordinated fake social-media accounts, narrative manipulation, fabricated claims and evidence, impersonation, abusive platform reporting, account impersonation, doxxing, harassment, and attempted suppression of dissidents, CCP critics, and foreign political figures. The reported activity included an unsuccessful, low-engagement campaign to discredit Japanese Prime Minister Sanae Takaichi and sustained harassment campaigns against Chinese dissidents.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.