Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
India Temporarily Bans Telegram Over Medical Exam Fraud
June 16, 2026
Microsoft 365 Device Code Phishing Byp Campaign Bypasses
June 16, 2026
Hackers Weaponize Microsoft Teams Relay to Conceal Malware Traffic
June 16, 2026
Home/Threats/Russian & Chinese AI Evade Bot Detection, Mimic Humans
Threats

Russian & Chinese AI Evade Bot Detection, Mimic Humans

State-linked influence operations from Russia and China have entered a new, more dangerous phase. These actors are no longer relying on flooding social media with low-quality posts. Instead, they now...

Jennifer sherman
Jennifer sherman
June 16, 2026 3 Min Read
4 0

State-linked influence operations from Russia and China have entered a new, more dangerous phase. These actors are no longer relying on flooding social media with low-quality posts. Instead, they now leverage artificial intelligence to make their accounts look and act more like real people, thereby evading traditional bot detection methods. This represents a significant evolution in their tactics, as detailed in a

The shift is subtle but significant, marking a clear evolution in how foreign interference works in the age of AI.

For years, researchers tracked inauthentic accounts pushing pro-Russia and pro-China narratives on platforms like X, formerly Twitter. What stood out in the past was sheer volume, with automated bots churning out posts at a rapid pace.

Today the picture looks different, as these accounts post less often, use more images, and even mimic sleep patterns to avoid platform moderation tools.

Analysts at TwoSixTech developed a new machine learning methodology to identify these inauthentic accounts on X with high confidence, applying it to data from 2024, 2025, and 2026.

The team found that both Russian and Chinese actors cut their post volumes in half while improving content quality, as the analysts at TwoSixTech said in a report shared with Cyber Security News (CSN).

The findings show adversaries clearly learning from past mistakes. Instead of creating new accounts through AI agents, these actors repurpose older accounts for fresh campaigns.

A video shared as part of a pro-Kremlin inauthentic campaign to smear Armenian prime minister Nikol Pashinyan during Armenian elections (Source - TwoSixTech)
A video shared as part of a pro-Kremlin inauthentic campaign to smear Armenian prime minister Nikol Pashinyan during Armenian elections (Source – TwoSixTech)

The number of active inauthentic accounts on X remained in the thousands, ranging from 5,000 to 11,000 each for China and Russia across all three years studied.

These operations are no longer just about hiding in plain sight. They actively work to shape public opinion with richer and more persuasive content.

The use of AI-generated images, multilingual posts, and human-like activity patterns points to a long-term, calculated strategy rather than a quick disruption effort.

Russian and Chinese Influence Actors Use AI

One of the most striking findings is how these accounts use AI to mimic human behavior and slip past bot detection systems.

Pro-Russia and pro-China accounts now post at slower speeds, and many pro-Russia accounts stay inactive for long stretches each day, effectively simulating a person who sleeps at night.

The share of original posts with images more than quadrupled for pro-Russia accounts and doubled for pro-China accounts between 2024 and 2026.

Some of these images are AI-generated and used to add emotional weight to narratives. Pro-Russia accounts also expanded their language use to a median of six languages, up from just two in 2024, with AI likely driving that translation capability.

Despite these upgrades, most accounts still fail to gain real traction. The typical inauthentic account received just one engagement for every 3 to 50 posts.

TwoSixTech identified an average of 15 pro-Russia outlier accounts each year with tens of thousands of real followers, averaging 17 to 22 engagements per post and acting as content hubs fueling the broader inauthentic network.

Shifting Narratives Against the United States

One of the most notable findings involves pro-Russia actors sharply increasing attacks on the United States and President Trump.

This marks a reversal from earlier pro-Trump messaging that once defined Russian influence operations. The shift is linked to Moscow’s frustration that the administration has not pushed Ukraine toward terms favorable to Russia.

Between 2024 and 2026, anti-US narratives from pro-Russia accounts surged. Personal attacks on the president and other US figures rose 264 percent, while narratives about US military weakness climbed 263 percent.

Anti-US conspiracy theories rose 124 percent, and messaging tied to US imperialism went up 65 percent.

Pro-China actors consistently pushed anti-US narratives across all three years, with growing focus on framing China as the leader in the global AI race.

In 2026, accounts began portraying Japanese Prime Minister Sanae Takaichi as a US puppet, marking a geographic expansion of the campaign.

TwoSixTech recommends that platforms invest in AI-powered detection tools capable of catching behavioral signals beyond simple post volume.

The firm also urges researchers and platforms to monitor the repurposing of aged accounts, since that tactic makes inauthentic networks far harder to detect through conventional methods.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackSecurity

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Microsoft Teams Analyzes Employee Wi-Fi Hotspot Data Connected

Next Post

Novo Nordisk Cyber Attack: Patient Data & AI Confirms Hackers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Russian & Chinese AI Evade Bot Detection, Mimic Humans
June 16, 2026
Microsoft Teams Analyzes Employee Wi-Fi Hotspot Data Connected
June 16, 2026
PRC-Nexus Hackers Exploit REDCap to Spy Servers Medical
June 16, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us