Spamouflage, which Microsoft tracks as Tides of Flood and as Storm 1376, is a China-linked influence operation known for large-scale multilingual propaganda and social-media manipulation. The activity has also been referred to as Dragon Bridge. It operates across a very broad online footprint spanning social platforms and websites, and has been observed distributing content in dozens of languages to amplify narratives aligned with Chinese state interests and to sow political and social discord. The actor is associated with coordinated inauthentic behavior using large networks of accounts to spread narratives around major geopolitical and social events. Reported themes include disinformation following the Hawaii wildfires, false or misleading messaging during Taiwan’s 2023–2024 election period, and amplification of criticism surrounding Japan’s release of treated nuclear wastewater into the Pacific. Its operations have included rapid multilingual amplification, use of fabricated or misleading personas, and attempts to shape public opinion internationally. A notable characteristic of this actor is its adoption of generative AI in influence operations. It has used AI-generated imagery and AI-generated news-anchor style videos to make propaganda content appear more credible and engaging. These techniques have been used to disseminate false or negative narratives at scale, including election-related messaging targeting Taiwan. The actor’s tradecraft centers on influence and spoofed media personas rather than traditional network intrusion or malware operations. Spamouflage/Tides of Flood is best understood as a state-linked information operation rather than a ransomware or financially motivated cybercrime group. Its dominant objective is influence operations in support of Chinese geopolitical messaging.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.