cross-posted from: https://scribe.disroot.org/post/10725085

The European Centre for Strategies and Transformations has mapped the architecture of Russian influence in Europe in its analytical brief Russia’s Disinformation Network in Europe: FIMI, AI Operations and the New Hybrid Threat Landscape (pdf).

The research on FIMI [Foreign Information Manipulation and Interference] shows how proxy media, cloned outlets, platform manipulation, AI-generated content and cross-platform amplification already function as parts of a wider hybrid-pressure system. The next question is whether selected elements of that infrastructure could become interoperable with Chinese influence capabilities.

For much of the past decade, Russian and Chinese influence operations have been treated as two different security problems. Russia became associated with disruption: hacked material, proxy outlets, fabricated personas and campaigns designed to deepen political divisions. Chinese operations were generally more selective, combining state-media and diplomatic amplification with covert account networks, multilingual content and targeted attempts to shape debate around issues of strategic importance to Beijing. The distinction was never absolute, but it provided a workable basis for analysis.

Where the threat becomes concrete

An election campaign offers a clear example. A Russian-linked network may obtain or fabricate compromising material, release it through a proxy outlet and push allegations of fraud or foreign control. The story does not have to be convincing on its own. It only needs to create enough noise to be picked up elsewhere. Chinese state media, diplomatic accounts or covert networks could then carry parts of the controversy into other languages and markets, not necessarily endorsing the original allegation but presenting it as further evidence of political dysfunction in the West …

The same logic applies beyond elections. A cyber intrusion may produce stolen documents; selected files can then be leaked, stripped of context or mixed with fabricated material. Russian-linked outlets have extensive experience turning such releases into political scandals. Wider circulation through Chinese media and multilingual account networks could make the material appear to have several independent points of origin …

Where the Russian and Chinese systems already converge

The clearest convergence is strategic. NATO StratCom COE research identifies alignment around criticism of US dominance, NATO, sanctions, Western military interventions and alleged Western hypocrisy.

The alignment is selective, not automatic. Beijing has not consistently repeated Moscow’s most extreme claims about Ukraine and still invests heavily in presenting China as a constructive and responsible power. Russian operations in NATO information environments are generally more disruptive and more willing to cultivate confusion for its own sake … Formal media links provide another layer. They do not establish covert campaign management, but create durable channels through which narratives, techniques and professional practices can circulate.

The foundations for deeper convergence therefore already exist. What remains uncertain is whether they will connect to covert operational infrastructure …

Elections are the most likely test

Elections provide the clearest environment in which such a model could take shape. Russian operations can discredit institutions, intensify hostility between political groups, question electoral legitimacy and create confusion. Contradictory narratives can be useful when the objective is disruption rather than persuasion.

China’s approach has historically been more selective, focused on regime reputation and specific policy interests. Recent reporting on Russian election interference and Microsoft’s analysis of PRC-linked activity show a wider willingness by state-linked actors to test domestic fault lines and election-related tensions …

Building resilience before convergence becomes operational

European governments need to get better at joining the dots. A cyberattack, a suspicious leak, a sudden wave of election-related claims and an opaque payment to a communications contractor may all be parts of the same operation, yet they are still too often handled by different institutions. Governments should build permanent channels for sharing information across intelligence, cyber-security, electoral and financial authorities, and focus less on individual posts than on the infrastructure behind them: domains, contractors, advertising accounts, payment routes and patterns of activity across languages and platforms.

The private sector also has a central role. Platforms, hosting providers, advertising firms, media companies and AI developers should know who is using their services and be prepared to act when the same networks move between them …

Civil society, journalists and researchers should look beyond the latest false claim and pay closer attention to how a story travels. The key question is often not whether one post is true or false, but who introduced the narrative, who gave it credibility and how it moved from an anonymous source into mainstream debate. That requires sustained multilingual monitoring, stronger open-source investigation and greater caution around dramatic leaks and apparently independent foreign commentary.

Archived