• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
ai powered fake news campaign targets western support for ukraine and

AI-Powered Fake News Campaign Targets Western Support for Ukraine and U.S. Elections

You are here: Home / General Cyber Security News / AI-Powered Fake News Campaign Targets Western Support for Ukraine and U.S. Elections
November 29, 2024

A Moscow-based company sanctioned by the U.S. earlier this year has been linked to yet another influence operation designed to turn public opinion against Ukraine and erode Western support since at least December 2023.

The covert campaign undertaken by Social Design Agency (SDA), leverages videos enhanced using artificial intelligence (AI) and bogus websites impersonating reputable news sources to target audiences across Ukraine, Europe, and the U.S. It has been dubbed Operation Undercut by Recorded Future’s Insikt Group.

“This operation, running in tandem with other campaigns like Doppelganger, is designed to discredit Ukraine’s leadership, question the effectiveness of Western aid, and stir socio-political tensions,” the cybersecurity company said.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


“The campaign also seeks to shape narratives around the 2024 U.S. elections and geopolitical conflicts, such as the Israel-Gaza situation, to deepen divisions.”

Cybersecurity

Social Design Agency has been previously attributed to Doppelganger, which also employs social media accounts and a network of inauthentic news sites to sway public opinion. The company and its founders were sanctioned by the U.S. earlier this March, alongside another Russian company known as Structura.

Operation Undercut shares infrastructure with both Doppelganger and Operation Overload (aka Matryoshka and Storm-1679), a Russia-aligned influence campaign that has attempted to undermine the 2024 French elections, the Paris Olympics, and the U.S. presidential election using a combination of fake news sites, false fact-checking resources, and AI-generated audio.

Ukraine and U.S. Elections

The latest campaign is no different in that it abuses the trust users place on trusted media brands and leverages AI-powered videos and images mimicking media sources to lend it more credibility. No less than 500 accounts spanning various social media platforms, such as 9gag and America’s best pics and videos, have been used to amplify the content.

Furthermore, the operation has been found to use trending hashtags in targeted countries and languages to reach a bigger audience, as well as promote content from CopyCop (aka Storm-1516).

“Operation Undercut is part of Russia’s broader strategy to destabilize Western alliances and portray Ukraine’s leadership as ineffective and corrupt,” Recorded Future said. “By targeting audiences in Europe and the U.S., the SDA seeks to amplify anti-Ukraine sentiment, hoping to reduce the flow of Western military aid to Ukraine.”

APT28 Conducts Nearest Neighbor Attack

The disclosure comes as the Russia-linked APT28 (aka GruesomeLarch) threat actor has been observed breaching a U.S. company in early February 2022 through an unusual technique called the nearest neighbor attack that involved first compromising a different entity located in an adjacent building located within the Wi-Fi range of the target.

The end goal of the attack aimed at the unnamed organization, which took place just ahead of Russia’s invasion of Ukraine, was to collect data from individuals with expertise on and projects actively involving the nation.

Cybersecurity

“GruesomeLarch was able to ultimately breach [the organization’s] network by connecting to their enterprise Wi-Fi network,” Volexity said. “The threat actor accomplished this by daisy-chaining their approach to compromise multiple organizations in close proximity to their intended target.”

The attack is said to have been accomplished by conducting password-spray attacks against a public-facing service on the company’s network to obtain valid wireless credentials, and taking advantage of the fact that connecting to the enterprise Wi-Fi network did not require multi-factor authentication.

Ukraine and U.S. Elections

The strategy, Volexity said, was to breach the second organization located across the street from the target and use it as a conduit to laterally move across its network and ultimately connect to the intended company’s Wi-Fi network by supplying the previously obtained credentials, while being thousands of miles away.

“The compromise of these credentials alone did not yield access to the customer’s environment, as all internet-facing resources required use of multi-factor authentication,” Sean Koessel, Steven Adair, and Tom Lancaster said. “However, the Wi-Fi network was not protected by MFA, meaning proximity to the target network and valid credentials were the only requirements to connect.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «protecting tomorrow's world: shaping the cyber physical future Protecting Tomorrow’s World: Shaping the Cyber-Physical Future
Next Post: Wanted Russian Cybercriminal Linked to Hive and LockBit Ransomware Has Been Arrested wanted russian cybercriminal linked to hive and lockbit ransomware has»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.