Sign in

Alberto Fittarelli

@fittarelli.com
3K followers 550 following 332 posts

Sr. Researcher @citizenlab.ca, Disinformation & Harassment. Fmr. Meta. Trainer: find & expose covert influence. I like doers. Opinions my own.

PostsRepliesMedia
Reposted by Alberto Fittarelli
Organized Crime and Corruption Reporting Project @occrp.org · 17/09/2026
Israeli Firm May Have Run Angola Influence Campaign www.occrp.org/en/news/isra...
occrp.org
Israeli Firm May Have Run Angola Influence Campaign
Citizen Lab uncovers a 14-week campaign in Angola using AI-generated personas, deceptive posts, and a phantom news site to revamp state messaging.
065
Reposted by Alberto Fittarelli
Raphael Satter @raphae.li · 17/09/2026
New: @citizenlab.ca's @fittarelli.com, @jsrailton.bsky.social & Maia Scott take a deep dive into the Israeli disinformation firm BlackCore. Among their findings: They accidentally left a spreadsheet detailing their Angola information operations exposed to the web. citizenlab.ca/research/bla...
citizenlab.ca
Research Note: BlackCore’s Influence Operations for Hire - The Citizen Lab
In this research note, we examine the digital infrastructure of BlackCore, an Israeli influence-for-hire company. We describe how we identified a BlackCore campaign consisting of a training program pr...
198
Alberto Fittarelli @fittarelli.com · 17/09/2026
Key takeaways: ☢️ IO firms are the threat we continue to underestimate. We @citizenlab.ca will keep researching them. 🌍 They are a global thing. Do not think they only are in certain countries. Remember #PAPERWALL? 🤖 AI is already making them harder to detect. Let's make AI harder for them to use.
010
Alberto Fittarelli @fittarelli.com · 17/09/2026
Then just two weeks ago, Meta released their H2 Adversarial Threat Report, which included disrupting an IO firm from Israel running the *same exact campaigns* that BlackCore was exposed for, including in Angola. Meta doesn't name the firm - but how likely is it to be a pure coincidence?
Screenshot from Meta's H2 2026 Adversarial Threat Report
121
Alberto Fittarelli @fittarelli.com · 17/09/2026
But you may be surprised by the engagement levels they were proud to show their clients. Almost 20k reactions, 230 comments, and 90 shares for a single BlackCore's linked Facebook post. And: 630K views, 90% of which by non-followers of the page! The red markings are theirs.
Screenshot from BlackCore's Final Report showing the levels of engagement obtained by one Facebook post made as part of the company's training program in Angola.
100
Alberto Fittarelli @fittarelli.com · 17/09/2026
You probably won't be shocked to hear that one of BlackCore's main avatars in Angola, "Gancho Atalaia", was an AI-generated middle-aged man depicted while pensively reading a tome on "ciência política". Nor that "Dorivaldo Kiala" was not a real Angolan political activist.
Cached AI-generated image on Google of "Gancho Atalaia", one of BlackCore's avatars in Angola.Screenshot from BlackCore's Final Report showing a Facebook post made by their Angolan avatar "Dorivaldo Kiala".
100
Alberto Fittarelli @fittarelli.com · 17/09/2026
But what was even more revealing was their final report to the client. In it, BlackCore claimed to have run a continuative 14-week program including the deployment of live assets on the target platforms. It showed examples. And it boasted of its successes.
Header from the "Executive Report of the Communication Program" to the government of the Republic of Angola, 2026.Screenshot from a summary of the contents of the training program delivered in Angola by BlackCore, as shown in the company's Final Report.
100
Alberto Fittarelli @fittarelli.com · 17/09/2026
Their proposal was pretty specific and, at times, even technical. It even included modules on how to run advertisement campaigns linked to the covert IO on both Meta's platforms and TikTok.
Header from BlackCore's "Angolan Government Campaign" proposal, February 2026.
100
Alberto Fittarelli @fittarelli.com · 17/09/2026
But one more thing particularly stood out. BlackCore offered training programs for clients to run their own local campaigns independently. A source gave us access to documentation from one of them: a training program and its related operations supporting the government of Angola domestically.
Screenshot from a section of BlackCore's website describing their training programs for clients "to build internal capabilities in influence operations".
100
Alberto Fittarelli @fittarelli.com · 17/09/2026
On a subdomain of their website, BlackCore explicitly advertised *deception* as a service. Dominating the discourse w/avatars? ✅ Getting real people to engage with fakes? ✅ Disrupting dissenting, legitimate narratives? ✅ Are 100K to 1M monthly messages enough? ✅ Oh, and influencer partnerships.
Screenshot from BlackCore's website describing their deceptive IO tactics designed to promote the clients' narratives and disrupt opposition.Screenshot from BlackCore's website describing a "dual track strategy" to include both positive messaging and "counter-narrative" operations to stifle dissent.
110
Alberto Fittarelli @fittarelli.com · 17/09/2026
BlackCore positioned itself as an expert actor in the covert influence operations industry. "Influencing perceptions" on behalf of clients is one of their stated goals. But before you're tempted to ask - isn't that what strategic political communications does? Let's move on to their next website.
Screenshot from BlackCore's website describing the general services offered by the firm.
100
Alberto Fittarelli @fittarelli.com · 17/09/2026
We set out to analyze BlackCore's online presence and digital infrastructure, so to understand more about their modus operandi. The amount of publicly available information on their tactics was staggering, and it gave us an unprecedented view on how private covert IO firms truly operate.
Header from BlackCore's website with a description of their "comprehensive solutions for influence operations".
100
Alberto Fittarelli @fittarelli.com · 17/09/2026
BlackCore has been exposed before. Notably, in June this year the French government - via their counter-influence operations agency Viginum - accused the Israeli firm of being behind interference in elections in Scotland, New York City, a few African countries, and of course France.
theguardian.com
France accuses Israeli firm of interfering in Scottish elections and targeting SNP
Cyber agency says BlackCore targeted John Swinney, as well as interfering in New York and French elections
121
Alberto Fittarelli @fittarelli.com · 17/09/2026
🚨 NEW REPORT: We @citizenlab.ca analyze the covert influence ops run by the Israeli firm BlackCore on behalf of the Angolan government. We obtained access to their training documentation. Their claims are shocking - or are they? citizenlab.ca/research/bla... 🧵
Feature image of the Citizen Lab's Research Note on BlackCore's Influence Operations for Hire.
2169
Reposted by Alberto Fittarelli
The Citizen Lab @citizenlab.ca · 09/09/2026
1/ Citizen Lab researchers @noura.bsky.social, Shaila Baran, @mmichae1sen.bsky.social and @sanstis.bsky.social analyze how intersecting identities of gender and sexual orientation shape experiences of digital transnational repression in a special issue of the Journal of Online Trust and Safety.
195
Alberto Fittarelli @fittarelli.com · 03/09/2026
The bigger news may be that X still has a Safety team. Glad to hear that. Noting that we @citizenlab.ca notified the platform of multiple proven IO networks at this point (#PRISONBREAK, #JUICYJAM, etc) without receiving any response or seeing any action on them.
030
Alberto Fittarelli @fittarelli.com · 17/08/2026
As it's been said many times by now, the covert influence rush is now no more on individual voters, but on Large Language Models. What better way to scale covert influence up in 2026?
politico.com
Israeli PR wants to answer your ChatGPT questions
French PR firm Havas Media, which runs the lion’s share of Israel’s FARA-registered foreign influence work in the U.S., appears to have stood up an “institute” aimed at feeding LLMs positive informati...
000
Alberto Fittarelli @fittarelli.com · 11/08/2026
9/ Thanks to the @citizenlab.ca Senior Research Fellow @lokman.org, also a co-author on our HKLEAKS report, for his contribution in flagging and researching this more recent doxxing campaign.
040
Alberto Fittarelli @fittarelli.com · 11/08/2026
8/ It's then obvious that a much broader ecosystem of PRC operations exists out there that awaits to be discovered. Most will have zero impact. But it depends on how we calculate impact: is it polluting the web and its AI crawlers? Is it pushing dissidents to silence? Or burning through gov budget?
100
Alberto Fittarelli @fittarelli.com · 11/08/2026
7/ On Gem Herald, "Archie Watson" is the sole author of articles that, when not stolen elsewhere, are labeled as 100% AI-made by verification tools like @pangram.com . The articles often push familiar narratives.
100
Alberto Fittarelli @fittarelli.com · 11/08/2026
6/ A closer look reveals another familiar playbook: that of PAPERWALL. A "local news" site in fact channeling anti-dissident harassment and pro-PRC, unsourced "op-eds", mixed with the unattributed lifting of real articles from actual international media to lend credibility to the whole thing.
citizenlab.ca
PAPERWALL: Chinese Websites Posing as Local News Outlets Target Global Audiences with Pro-Beijing Content - The Citizen Lab
A network of at least 123 websites operated from within the People’s Republic of China while posing as local news outlets in 30 countries across Europe, Asia, and Latin America, disseminates pro-Beiji...
120
Alberto Fittarelli @fittarelli.com · 11/08/2026
5/ But like for HKLEAKS, they made mistakes. For about a month and a half in 2023, the website resolved to the same IP address as just 1 domain. Gem Herald [WARNING: open with caution] claims to offer Australian audiences "Real Aussie news. No fluff." It's also flagged for malware by Maltrail:
github.com
100
Alberto Fittarelli @fittarelli.com · 11/08/2026
4/ "Reveal Scum", the contents of which I won't show, followed the HKLEAKS playbook almost to the letter. Completely anonymous, with good operational security. A couple of generic Wordpress usernames ("Autumn" and the Chinese equivalent for "admin"). Anonymous hosting on US and Canada-based infra.
220
Alberto Fittarelli @fittarelli.com · 11/08/2026
3/ OpenAI identified it as part of a much larger effort to target dissidents (and the Japanese PM), revealing the enormity of its scale in terms of human and technological resources deployed by the actors.
110
Alberto Fittarelli @fittarelli.com · 11/08/2026
2/ The domain revealscum[.]com was registered in 2023 and became active almost immediately. It followed a playbook we have already described that same year in our report on HKLEAKS. Exposing as much private information as possible, framing it in the most damaging way for the target.
citizenlab.ca
Beautiful Bauhinia: "HKLeaks" – The Use of Covert and Overt Online Harassment Tactics to Repress 2019 Hong Kong Protests - The Citizen Lab
In August 2019 a wave of websites and social media channels, called “HKLEAKS,” began “doxxing” the identities and personal information of pro-democracy activists in Hong Kong. While the creators of th...
110
Alberto Fittarelli @fittarelli.com · 11/08/2026
1/ In Feb 2026, OpenAI reported on a doxxing website, which since 2023 had been exposing Chinese activists and dissidents. Unsurprisingly, the company attributed that activity to Chinese law enforcement. We @citizenlab.ca had been looking at it for a while and have some extra details. 🧵
openai.com
Disrupting malicious uses of AI
Our latest threat report examines how malicious actors combine AI models with websites and social platforms—and what it means for detection and defense.
167
Alberto Fittarelli @fittarelli.com · 06/08/2026
All because there’s a general election coming up next year and voters are moving even further to the right…
020
Alberto Fittarelli @fittarelli.com · 06/08/2026
As I mention in my comment to this investigation by @jdowsea.bsky.social and @occrp.org, coordinated false reporting is an almost invisible, and therefore incredibly underestimated censorship threat to civil society - and to anyone bothering those who will pay for the service.
01811
Reposted by Alberto Fittarelli
The Citizen Lab @citizenlab.ca · 03/07/2026
1/ NEW REPORT: Former Member of the European Parliament Stelios Kouloglou was repeatedly hacked with NSO Group’s Pegasus spyware while serving on the EU committee investigating Pegasus and other spyware abuses in Europe. Full report: citizenlab.ca/research/mem...
citizenlab.ca
Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus - The Citizen Lab
We found that former Member of the European Parliament Stelios Kouloglou was hacked with Pegasus spyware while serving on the PEGA committee, which investigated Pegasus and other spyware abuses in Eur...
13121
Reposted by Alberto Fittarelli
Ron Deibert @rondeibert.bsky.social · 03/07/2026
NEW @citizenlab.ca report: Member of 🇪🇺 Euro Parliamentary committee (#PEGA) tasked with investigating spyware abuses himself hacked with Pegasus spyware 👇 citizenlab.ca/research/mem...
citizenlab.ca
Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus - The Citizen Lab
We found that former Member of the European Parliament Stelios Kouloglou was hacked with Pegasus spyware while serving on the PEGA committee, which investigated Pegasus and other spyware abuses in Eur...
01813
Reposted by Alberto Fittarelli
Alan Jagolinzer @jagolinzer.bsky.social · 27/06/2026
• a cowardice problem where people like you and me, who have sworn oaths to uphold existing laws, have become unwilling to intervene and prevent blatant criminal actions because we fear losing status, losing money, being harassed, or emotional and physical abuse to ourselves or our families.” (8/8)
1153
Alberto Fittarelli @fittarelli.com · 19/06/2026
“If a hostile state ran AI-generated sockpuppet networks to swing our politics, we would call it foreign interference and respond with the full machinery of state.” So let’s call it precisely that.
redbridgeintel.substack.com
Call It What It Is: Foreign Interference
If a hostile state ran this sort of operation to swing our vote, we'd call it foreign interference. It's time we did.
051
Alberto Fittarelli @fittarelli.com · 05/06/2026
Some great digital sleuthing here.
020
Reposted by Alberto Fittarelli
Kerim Friedman 傅可恩 @kerim.one · 03/06/2025
On this June 4th, wishing for a world with more people willing to stand in front of the tanks, and less who are willing to drive them.
This wide-angle aerial photograph shows a broad avenue with a column of military tanks positioned down the center of the street. The tanks appear to be Type 59 or similar models, arranged in a single-file line stretching into the distance. In the foreground, a solitary figure can be seen standing directly in front of the lead tank, though from this elevated perspective the person appears quite small. The avenue is flanked by rows of trees on both sides, with large open plaza areas visible. In the background, there are multi-story buildings and what appears to be a large public square or gathering area. The photograph has the characteristic color tone and grain of film photography from the late 1980s.

This is the famous wide-shot perspective of the "Tank Man" incident at Tiananmen Square in Beijing, China, taken on June 4, 1989, capturing the moment when an unknown protester stood in front of a column of tanks following the government crackdown on pro-democracy demonstrations.

(ALT Text by Claude AI)
6424146
Reposted by Alberto Fittarelli
The Citizen Lab @citizenlab.ca · 29/05/2026
Doctoral fellow Swantje Lange @swantjelan.bsky.social spoke with the Hasso Plattner Institut @hpi.bsky.social about sophisticated surveillance campaigns being used to exploit mobile networks, sharing that “the mobile network is highly opaque and extremely complex.” hpi.de/en/article/r...
hpi.de
Researchers uncover espionage in mobile networks
Like a spy movie: Researchers from HPI and the University of Toronto reveal how surveillance actors exploit mobile networks to track people worldwide.
02011
Alberto Fittarelli @fittarelli.com · 28/05/2026
And sorry, but I don’t buy any of the excuses I’ve seen and heard.
020
Alberto Fittarelli @fittarelli.com · 11/05/2026
10/ So - is this another PAPERWALL, plus some extras? Not in scale. Here: 10 websites with no traffic, one probably purchased FB page with no engagement. But what's in it for Jack Sanders? No one really knows. But his profile as a "serious conman" with a pro-China angle should keep folks alert.
000
Alberto Fittarelli @fittarelli.com · 11/05/2026
9/ But this whole campaign really unraveled when someone using Sanders' son's name, Richard, reached out to ICIJ reporter @scillaa.bsky.social - co-author of the "China Targets" investigation on China's transnational repression methods. Richard wanted to learn more about what Scilla was working on.
100
Alberto Fittarelli @fittarelli.com · 11/05/2026
8/ Now? Sanders seems to be taking over Facebook pages out of Botswana to run "livestreams" on the politics of the Philippines, or publish dubious articles on his "news" websites, under a variety of aliases. In fact, even @whljustin.bsky.social is now being impersonated after writing about him!
100
Alberto Fittarelli @fittarelli.com · 11/05/2026
7/ Then, he re-emerged in 2004 as the (discredited) source of a scandal: the NZ intel service would have spied on the country's Māori leaders. A government investigation then dismissed the claims as made-up: www.beehive.govt.nz/release/pms-...
100
Alberto Fittarelli @fittarelli.com · 11/05/2026
6/ But his story goes much farther back. In fact, we first see him emerging to public news in 2003, when he's blamed for a supposed passport reselling scheme involving China, Nauru, and other countries - codenamed "Operation Weasel": en.wikipedia.org/wiki/Operati...
100
Alberto Fittarelli @fittarelli.com · 11/05/2026
5/ That's far from the only random venture that Sanders has been linked to over the years. From hosting diplomats, to posing as one, he seems to be actively making political connections - and it's unclear what his goals, or even just legitimacy, are.
100
Alberto Fittarelli @fittarelli.com · 11/05/2026
4/ On top of "news" sites, Sanders seems to run other websites - including one for a never-before-heard-of religious order, where he shows up dressed as a priest, and signs his posts as "Granf Toff Quid".
100
Alberto Fittarelli @fittarelli.com · 11/05/2026
3/ Which may not be surprising. After all, Sanders can be seen attending the "17th China International Public Security Products Expo and Smart and Security Industry Development Conference" in Beijing in 2024. chinarta[.]com/m/view.php?aid=170306
100
Alberto Fittarelli @fittarelli.com · 11/05/2026
2/ The focus? Chinese interests - in Asia and Oceania.
100
Alberto Fittarelli @fittarelli.com · 11/05/2026
1/ The New Zealander now known as "Jake Sanders" seems to run, or at least be closely associated with, a small network of "news" websites that were either coopted, or don't actually exist.
100
Alberto Fittarelli @fittarelli.com · 11/05/2026
🧵Here's a little thread on the campaign exposed by @whljustin.bsky.social, and the interesting, if surreal, figure that apparently runs it.
thepost.co.nz
The strange re-emergence of a serial conman
Two decades after conning New Zealand media outlets, Jake Sanders has re-emerged in Asia as a geopolitical commentator, media executive, ordained priest and the ‘Knight Commander’ of a religious order...
112
Alberto Fittarelli @fittarelli.com · 09/05/2026
This must be the weirdest disinformation network and actor I have seen in a long time. Glad I could comment on @whljustin.bsky.social ‘s story about it. Ever see pro-China disinfo sites run by a supposed priest/diplomat/journalist who once posed as a NZ spy and triggered a fake scandal? Read on.
074
Alberto Fittarelli @fittarelli.com · 07/05/2026
10/ Should we expect more websites to pop up soon? Most likely - yes. Are they harmful? Potentially, and especially if amplified by large networks - like Spamouflage for example. For now, it's important to keep track of their development, and be alert on the changes in their behavior.
000
Alberto Fittarelli @fittarelli.com · 07/05/2026
9/ Their *intended* audiences though? Australia, New Zealand, India especially. But also Bangladesh, Nepal, Sri Lanka, and others - covering what was left unaddressed in Asia by the original PAPERWALL network.
100