Spamouflage, also known as Dragonbridge and Taizi Flood, is a long-running China-linked covert influence and harassment operation aligned with the political interests of the People’s Republic of China. Public reporting has tied elements of the operation to Chinese government entities, including Chinese law enforcement and, in some cases, a unit within the Ministry of Public Security. The network has been active since at least 2019 and is widely tracked as one of the most prolific PRC-linked online influence operations. The operation uses large numbers of inauthentic accounts across social media, blogs, forums, video platforms, and imitation news ecosystems to manipulate discourse, suppress critics of the Chinese Communist Party, and amplify pro-PRC narratives. Its targets have included members of the Chinese diaspora, dissidents, human rights groups, journalists, pro-democracy figures in Hong Kong, foreign politicians, and audiences in the United States and other countries. Themes have included praise for Chinese government policies, attacks on critics of Beijing, narratives about Xinjiang, COVID-19, U.S. politics, the South China Sea, Hong Kong national security laws, and criticism of Japan over Fukushima wastewater discharge. Spamouflage is notable for combining broad low-engagement propaganda with more targeted harassment and transnational repression. Reported activity includes coordinated trolling, persona-driven influence operations, doxxing, psychological intimidation, and tailored abuse against journalists and activists, especially women of Asian descent who report on China-related issues. The operation has also impersonated local political personas, including purported U.S. voters, patriots, veterans, and conservative media voices, to inject divisive narratives into U.S. election discourse. Operationally, Spamouflage relies on mass account creation, cross-platform amplification, multilingual content generation, and coordinated posting patterns. It has operated in Chinese, English, Japanese, Korean, Cantonese, Russian, Italian, and Traditional Chinese. Researchers have observed use of stolen or AI-generated profile images, fabricated personas, synthetic media, and generative AI tools to produce comments, articles, memes, avatars, synthetic presenters, and other influence content at scale. Operators have also used AI tools for reconnaissance, social media research, code debugging, persona development, and preparation of operational reports. Known activity linked to the network includes campaigns targeting rare-earth companies in North America, attacks on Hong Kong pro-democracy figures, harassment of Chinese dissidents abroad, and influence efforts aimed at Japanese political figures. Reporting has also connected the operation to a doxxing and smear ecosystem used against critics of the Chinese government. Despite its scale and persistence, much of Spamouflage’s observable activity has historically shown limited authentic engagement, with amplification often coming primarily from accounts controlled by the operators themselves. Aliases and related naming seen in public reporting include Dragonbridge and Storm-1376. Related PRC-origin influence clusters have at times shown behavioral similarities to Spamouflage without confirmed technical linkage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PRC-origin influence network previously used inauthentic social media accounts to denigrate rare earth companies in North America and is cited here as a parallel for similar reputation-harm operations against strategically important firms.
China-aligned influence operation actor using generative AI content to scale political influence campaigns on social media.
China-linked covert influence/harassment operation attributed to Chinese law enforcement, using large-scale coordinated inauthentic behavior across many social platforms to target dissidents, human rights groups, and foreign officials; includes doxxing, fabricated evidence, and AI-generated content/memes.
Referenced as a similar long-running China-origin influence operation for comparison only; no technical link to Nine-emdash Line was identified in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.