Alberto Fittarelli @fittarelli.com · 17/09/2026Then just two weeks ago, Meta released their H2 Adversarial Threat Report, which included disrupting an IO firm from Israel running the *same exact campaigns* that BlackCore was exposed for, including in Angola. Meta doesn't name the firm - but how likely is it to be a pure coincidence? 121
Alberto Fittarelli @fittarelli.com · 17/09/2026But you may be surprised by the engagement levels they were proud to show their clients. Almost 20k reactions, 230 comments, and 90 shares for a single BlackCore's linked Facebook post. And: 630K views, 90% of which by non-followers of the page! The red markings are theirs. 100
Alberto Fittarelli @fittarelli.com · 17/09/2026You probably won't be shocked to hear that one of BlackCore's main avatars in Angola, "Gancho Atalaia", was an AI-generated middle-aged man depicted while pensively reading a tome on "ciência política". Nor that "Dorivaldo Kiala" was not a real Angolan political activist. 100
Alberto Fittarelli @fittarelli.com · 17/09/2026But what was even more revealing was their final report to the client. In it, BlackCore claimed to have run a continuative 14-week program including the deployment of live assets on the target platforms. It showed examples. And it boasted of its successes. 100
Alberto Fittarelli @fittarelli.com · 17/09/2026Their proposal was pretty specific and, at times, even technical. It even included modules on how to run advertisement campaigns linked to the covert IO on both Meta's platforms and TikTok. 100
Alberto Fittarelli @fittarelli.com · 17/09/2026But one more thing particularly stood out. BlackCore offered training programs for clients to run their own local campaigns independently. A source gave us access to documentation from one of them: a training program and its related operations supporting the government of Angola domestically. 100
Alberto Fittarelli @fittarelli.com · 17/09/2026On a subdomain of their website, BlackCore explicitly advertised *deception* as a service. Dominating the discourse w/avatars? ✅ Getting real people to engage with fakes? ✅ Disrupting dissenting, legitimate narratives? ✅ Are 100K to 1M monthly messages enough? ✅ Oh, and influencer partnerships. 110
Alberto Fittarelli @fittarelli.com · 17/09/2026BlackCore positioned itself as an expert actor in the covert influence operations industry. "Influencing perceptions" on behalf of clients is one of their stated goals. But before you're tempted to ask - isn't that what strategic political communications does? Let's move on to their next website. 100
Alberto Fittarelli @fittarelli.com · 17/09/2026We set out to analyze BlackCore's online presence and digital infrastructure, so to understand more about their modus operandi. The amount of publicly available information on their tactics was staggering, and it gave us an unprecedented view on how private covert IO firms truly operate. 100
Alberto Fittarelli @fittarelli.com · 17/09/2026🚨 NEW REPORT: We @citizenlab.ca analyze the covert influence ops run by the Israeli firm BlackCore on behalf of the Angolan government. We obtained access to their training documentation. Their claims are shocking - or are they? citizenlab.ca/research/bla... 🧵 21610
Alberto Fittarelli @fittarelli.com · 11/08/20268/ It's then obvious that a much broader ecosystem of PRC operations exists out there that awaits to be discovered. Most will have zero impact. But it depends on how we calculate impact: is it polluting the web and its AI crawlers? Is it pushing dissidents to silence? Or burning through gov budget? 100
Alberto Fittarelli @fittarelli.com · 11/08/20267/ On Gem Herald, "Archie Watson" is the sole author of articles that, when not stolen elsewhere, are labeled as 100% AI-made by verification tools like @pangram.com . The articles often push familiar narratives. 100
Alberto Fittarelli @fittarelli.com · 11/08/20264/ "Reveal Scum", the contents of which I won't show, followed the HKLEAKS playbook almost to the letter. Completely anonymous, with good operational security. A couple of generic Wordpress usernames ("Autumn" and the Chinese equivalent for "admin"). Anonymous hosting on US and Canada-based infra. 220
Alberto Fittarelli @fittarelli.com · 11/08/20263/ OpenAI identified it as part of a much larger effort to target dissidents (and the Japanese PM), revealing the enormity of its scale in terms of human and technological resources deployed by the actors. 110
Alberto Fittarelli @fittarelli.com · 11/05/202610/ So - is this another PAPERWALL, plus some extras? Not in scale. Here: 10 websites with no traffic, one probably purchased FB page with no engagement. But what's in it for Jack Sanders? No one really knows. But his profile as a "serious conman" with a pro-China angle should keep folks alert. 000
Alberto Fittarelli @fittarelli.com · 11/05/20269/ But this whole campaign really unraveled when someone using Sanders' son's name, Richard, reached out to ICIJ reporter @scillaa.bsky.social - co-author of the "China Targets" investigation on China's transnational repression methods. Richard wanted to learn more about what Scilla was working on. 100
Alberto Fittarelli @fittarelli.com · 11/05/20268/ Now? Sanders seems to be taking over Facebook pages out of Botswana to run "livestreams" on the politics of the Philippines, or publish dubious articles on his "news" websites, under a variety of aliases. In fact, even @whljustin.bsky.social is now being impersonated after writing about him! 100
Alberto Fittarelli @fittarelli.com · 11/05/20267/ Then, he re-emerged in 2004 as the (discredited) source of a scandal: the NZ intel service would have spied on the country's Māori leaders. A government investigation then dismissed the claims as made-up: www.beehive.govt.nz/release/pms-... 100
Alberto Fittarelli @fittarelli.com · 11/05/20266/ But his story goes much farther back. In fact, we first see him emerging to public news in 2003, when he's blamed for a supposed passport reselling scheme involving China, Nauru, and other countries - codenamed "Operation Weasel": en.wikipedia.org/wiki/Operati... 100
Alberto Fittarelli @fittarelli.com · 11/05/20265/ That's far from the only random venture that Sanders has been linked to over the years. From hosting diplomats, to posing as one, he seems to be actively making political connections - and it's unclear what his goals, or even just legitimacy, are. 100
Alberto Fittarelli @fittarelli.com · 11/05/20264/ On top of "news" sites, Sanders seems to run other websites - including one for a never-before-heard-of religious order, where he shows up dressed as a priest, and signs his posts as "Granf Toff Quid". 100
Alberto Fittarelli @fittarelli.com · 11/05/20263/ Which may not be surprising. After all, Sanders can be seen attending the "17th China International Public Security Products Expo and Smart and Security Industry Development Conference" in Beijing in 2024. chinarta[.]com/m/view.php?aid=170306 100
Alberto Fittarelli @fittarelli.com · 11/05/20262/ The focus? Chinese interests - in Asia and Oceania. 100
Alberto Fittarelli @fittarelli.com · 11/05/20261/ The New Zealander now known as "Jake Sanders" seems to run, or at least be closely associated with, a small network of "news" websites that were either coopted, or don't actually exist. 100
Alberto Fittarelli @fittarelli.com · 07/05/20269/ Their *intended* audiences though? Australia, New Zealand, India especially. But also Bangladesh, Nepal, Sri Lanka, and others - covering what was left unaddressed in Asia by the original PAPERWALL network. 100
Alberto Fittarelli @fittarelli.com · 07/05/20268/ Let me repeat once more: there is NO indication that these sites get any legit traffic. It's important to keep it in mind. That doesn't mean this isn't toxic however, or potentially harmful if activated to target individuals or organizations, like the older sites would do. 100
Alberto Fittarelli @fittarelli.com · 07/05/20267/ The content is often - but not always - repeated across the sites, just like the old PAPERWALL websites would do. Typically, this is clustered around target audiences: AU & NZ readers? Here's a story on how "the Trump admin first approved the supply of weapons to Kiev". Others? Different ones. 100
Alberto Fittarelli @fittarelli.com · 07/05/20266/ That's an important detail to this day. Pivoting off the IP addresses historically utilized by PAPERWALL websites, we can still observe new but almost identical websites being sprung up. And they now host their images... on ru.updatenews[.]info, a subdomain of the Haimai website. 100
Alberto Fittarelli @fittarelli.com · 07/05/20265/ That eventually led us to attributing PAPERWALL. A Chinese marketing firm called (in short) Haimai shared advertising infrastructure with one of the earliest websites ever set up for the network: updatednews[.]info. 100
Alberto Fittarelli @fittarelli.com · 07/05/20264/ But the real telling signs that the websites were all run by the same people were: their domains were all hosted on a small group of IP addresses; and their images were often hosted directly on a website functioning as a central hub, and also run by the same actors. 100
Alberto Fittarelli @fittarelli.com · 07/05/20263/ The websites lifted entire articles from real outlets in the target country. Not only that: they linked directly to the content hosted on the cloned websites, saving effort and hosting space to themselves. 100
Alberto Fittarelli @fittarelli.com · 07/05/20262/ Let's recap quickly. PAPERWALL was (well, is) a network of poorly set up websites mimicking local news outlets in dozens of countries globally. In our report, we mapped out their geographical focus at the time - which notably left out Africa, most of SE Asia, and Oceania. 101
Alberto Fittarelli @fittarelli.com · 12/03/20264/ China, Russia, Iran. Sure, we know, they run IOs all the time. But aren’t countries that are not US adversaries doing it too, with equally harmful consequences? Our JUICYJAM and PRISONBREAK reports at @citizenlab.ca at least stand to prove otherwise. 110
Alberto Fittarelli @fittarelli.com · 12/03/20263/ Why is “CIB” now almost an afterthought at the bottom of the report? Did the influence operations threat and harm landscape fundamentally change? I beg to differ. 100
Alberto Fittarelli @fittarelli.com · 12/03/20262/ Why “First Half 2026” now when it used to be quarterly and even more frequent before that? What next? 100
Alberto Fittarelli @fittarelli.com · 02/03/20264/ The creation date for several of the accounts is also telling. Very often, they were registered over the past ~2 months. 1231
Alberto Fittarelli @fittarelli.com · 02/03/20263/ I could probably spend the whole day listing accounts like these - posting the hashtags in question in large volumes. 1221
Alberto Fittarelli @fittarelli.com · 02/03/20262/ A significant number of accounts pushing the usual pro-Pahlavi hashtags, plus some new ones, look like this. “Account based in [name country]”. See that “shield” icon to the right? That’s X telling us not to trust the location as the user is on a VPN. 27118
Alberto Fittarelli @fittarelli.com · 26/01/2026We also happen to know this about Homan: abcnews.go.com/Politics/doj... 021
Alberto Fittarelli @fittarelli.com · 10/01/2026Let me be *really* clear. Confirmation bias is NOT believing your eyes when you have multiple clear data sources *all* confirming what they see. Check the bodycam footage. Check the NYT multi-angle reconstruction, and the witnesses statements. This was plain murder. 061
Alberto Fittarelli @fittarelli.com · 07/01/20266/ Is “she” alone? Oh no. Here’s another example of legit, patriotic, antisemite Finn posting the same content and logging into X from… a Swiss VPN IP. 110
Alberto Fittarelli @fittarelli.com · 07/01/20265/ Do we know “she” is Russian-based? No. Do we know she’s real? Also no. Because of course “she” operates the account from a VPN, and has zero personal information on it. Except an anonymous blog on Blogspot, where “she” posts writings by… Aleksandr Dugin. 110
Alberto Fittarelli @fittarelli.com · 07/01/20264/ But “she” doesn’t stop at that! Let’s not forget to throw in the mix a copy of the Protocol of the Elders of Zion, it’s still fashionable in 2026 after all. 110
Alberto Fittarelli @fittarelli.com · 07/01/20263/ “She” is gloating about the US threats to Greenland and Denmark, naturally. And doesn’t forget to link them to Denmark’s integrity in supporting Ukraine. 110
Alberto Fittarelli @fittarelli.com · 07/01/20262/ Of course, she mainly posts articles from the “Pravda Network” (aka Portal Kombat, that we all know by now to be a Russian network. Check the great Viginum reports on it.) “Her” niche is Finland, so here’s the Finnish website. 110
Alberto Fittarelli @fittarelli.com · 07/01/20261/ Russian disinfo sponsors can’t believe their luck at the chaos spurred by their American counterparts. Not only politicians, but their tech enablers too, of course. Meet “Budjetti”. “She” is on X, of course. Openly antisemitic, racist, anti-Ukraine. And completely unchallenged. 156
Alberto Fittarelli @fittarelli.com · 12/12/20256/ To the point that… it’s still being used today. And very likely, also by the governments targeted here in the first place. In October 2025, we reported on PRISONBREAK, a most likely Israeli-run IO targeting Iran. They had a variation on the ephemerality theme: fake links to real news outlets. 140
Alberto Fittarelli @fittarelli.com · 12/12/20255/ Their “ephemeral disinformation” technique was later seen with other actors, and in different contexts. We won’t award a prize for who came up first with it… but we will say: it was effective. And intentionally confusing. 131
Alberto Fittarelli @fittarelli.com · 12/12/20254/ Why was Endless Mayfly special? We reported about it in 2019, but tracked the origin of that specific part of the campaign to at least 2017. Despite coming early into the online IO landscape - or what we now know of it - this actor was *skilled*. And it used some frustrating evasion techniques. 131
Alberto Fittarelli @fittarelli.com · 12/12/20253/ Meta’s attribution tied Endless Mayfly to a broader set of campaigns that the company has disrupted on its platforms repeatedly over the years. 131