Meta, the parent company of Facebook, recently announced the disruption of two large covert influence operations originating from China and Russia. These operations violated Meta's policy against Coordinated Inauthentic Behavior and operated across multiple social media platforms.


The Chinese operation involved thousands of accounts and pages across various platforms. Its focus was on spreading content related to China, Xinjiang, criticism of the U.S. and Western foreign policies, and criticism of the Chinese government. The operation was run by geographically dispersed operators in China, with links to individuals associated with Chinese law enforcement.

On the other hand, the Russian operation, known as Doppelganger, aimed to weaken support for Ukraine. It did this by mimicking websites of mainstream news outlets and government entities to post fake articles. Meta described Doppelganger as the most significant and persistent Russian-origin operation it has dismantled since 2017.

The Chinese operation targeted audiences in the US and the Czech Republic, focusing on the government's support of Ukraine and calls to avoid antagonizing China. It involved more than 50 apps, including Facebook, Instagram, Twitter, YouTube, TikTok, Reddit, and others.

The Russian operation, on the other hand, targeted users in Germany, France, Italy, Ukraine, and the UK. It included a network of over 60 websites impersonating legitimate news organizations. The operation had around 4,000 followers and spent an estimated $105,000 on advertising on Facebook and Instagram. It used careful replication of news websites and crude social media amplification. The Russian operation was investigated by EU DisinfoLab and remains a continuing threat.

Additionally, Meta also removed networks of accounts targeting audiences in Turkey.


These covert influence operations originating from China and Russia have significant implications. They highlight the need for continued vigilance in addressing similar malicious activity. Meta's actions in disrupting these operations and publishing a report on its findings aim to assist the security community in mitigating future threats.