Storm-1376 is a China-linked influence operations actor known widely as Spamouflage and Dragonbridge. It is associated with pro-PRC online information operations that use networks of inauthentic social media accounts and multilingual content to shape narratives, amplify divisive themes, and undermine trust in political institutions and public information. Microsoft classifies it as an influence-operations actor and has attributed to it some of the most prolific recent China-linked social media manipulation activity. The actor has targeted audiences in the United States, Taiwan, and Japan, among others, with narratives tailored to local political and social tensions. Reported themes have included contentious U.S. domestic issues, conspiracy-laden messaging around major incidents, and attempts to discredit official assessments on politically sensitive topics. In Taiwan, the group was observed using AI-generated or AI-enhanced content during the 2024 presidential election cycle, including fabricated audio and synthetic media intended to influence political perceptions. It has also used AI-generated memes and virtual news-anchor style content, indicating an evolution in tradecraft toward scalable synthetic propaganda. Storm-1376’s operations center on spoofed personas and coordinated amplification rather than network intrusion or destructive cyber activity. Its capabilities include online impersonation, narrative seeding, and broad dissemination of manipulated or deceptive media across platforms. The actor’s dominant motivation is influence operations aligned with Chinese state interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked influence operations cluster listed in Microsoft's naming taxonomy mapping.
Storm-1376 is a Chinese threat actor using AI-generated content for information operations and election interference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.