Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical LiteLLM Supply Chain Flaw Exposes 2,500 Companies, 434,000 CI/CD Pipelines
August 11, 2026
CISA Warns of Critical SonicWall SMA 1000 Zero-Days Exploited in Ransomware Attacks
August 11, 2026
Critical VMware vCenter CVE-2023-34048 Under Active Exploitation
August 11, 2026
Home/Threats/State-Sponsored AI Evades Bot Detection, Mimics Humans
Threats

State-Sponsored AI Evades Bot Detection, Mimics Humans

Key Takeaways State-sponsored influence operations from Russia and China are increasingly employing AI to mimic human behavior and evade traditional bot detection on social media platforms like X....

Jennifer sherman
Jennifer sherman
June 16, 2026 4 Min Read
59 0

Key Takeaways

  • State-sponsored influence operations from Russia and China are increasingly employing AI to mimic human behavior and evade traditional bot detection on social media platforms like X.
  • These advanced tactics include reduced posting frequency, increased use of AI-generated images, multilingual content, and simulated human sleep patterns.
  • Research from TwoSixTech, spanning 2024-2026, reveals a shift from high-volume, low-quality posts to more sophisticated, persuasive content, often repurposing older accounts.
  • Pro-Russia narratives have notably pivoted to aggressively attacking the United States and its leadership, while pro-China narratives emphasize China’s AI dominance and portray Japanese leaders as U.S. puppets.

State-Sponsored Influence Operations Evolve with AI to Bypass Detection

Influence operations orchestrated by state-backed actors from Russia and China have entered a sophisticated new phase, moving beyond rudimentary spamming to leverage artificial intelligence for more convincing human impersonation. This strategic evolution allows these accounts to bypass established bot detection mechanisms on social media platforms, as detailed in a recent report.

Table Of Content

  • Key Takeaways
  • State-Sponsored Influence Operations Evolve with AI to Bypass Detection
  • Advanced AI Techniques Employed by Malign Actors
  • Russian and Chinese Influence Actors Use AI
  • Shifting Narratives Against the United States
  • What You Should Do

This subtle yet profound shift signifies a critical advancement in foreign interference techniques, adapting to the AI era. Previously, researchers tracking inauthentic accounts promoting pro-Russia and pro-China narratives on platforms such as X (formerly Twitter) observed a focus on sheer volume, with automated bots rapidly churning out numerous posts.

However, the landscape has changed. These modern influence accounts now exhibit more nuanced behavior: posting less frequently, incorporating a higher proportion of images, and even mimicking human sleep cycles to evade platform moderation tools. This strategic change is documented in a comprehensive analysis.

Advanced AI Techniques Employed by Malign Actors

Analysts at TwoSixTech developed a novel machine learning methodology specifically designed to identify these sophisticated inauthentic accounts on X with high confidence. Applying this methodology to data spanning 2024, 2025, and 2026, the team uncovered significant trends.

According to a report shared with Cyber Security News (CSN), TwoSixTech analysts found that both Russian and Chinese actors dramatically reduced their post volumes by half while simultaneously enhancing content quality. This indicates a clear learning curve, with adversaries adapting from past, less effective tactics. Rather than generating entirely new accounts via AI agents, these actors are now repurposing older, established accounts for new campaigns, making them significantly harder to detect through conventional means.

Despite these advancements, the overall number of active inauthentic accounts on X remained consistent, fluctuating between 5,000 and 11,000 for both China and Russia across the three years analyzed.

A video shared as part of a pro-Kremlin inauthentic campaign to smear Armenian prime minister Nikol Pashinyan during Armenian elections (Source - TwoSixTech)
A video shared as part of a pro-Kremlin inauthentic campaign to smear Armenian prime minister Nikol Pashinyan during Armenian elections (Source – TwoSixTech)

These operations are no longer merely about covert presence; they actively aim to shape public opinion through richer, more compelling content. The integration of AI-generated imagery, multilingual posts, and realistic activity patterns suggests a calculated, long-term strategy rather than opportunistic disruption.

Russian and Chinese Influence Actors Use AI

A key finding highlights how these accounts leverage AI to emulate human behavior and circumvent bot detection systems. Pro-Russia and pro-China accounts now post at a deliberately slower pace, with many pro-Russia accounts exhibiting extended periods of inactivity daily, effectively simulating a human sleep schedule. This detailed behavioral mimicry is crucial for evading automated monitoring.

Between 2024 and 2026, the proportion of original posts featuring images more than quadrupled for pro-Russia accounts and doubled for pro-China accounts. Many of these images are AI-generated, designed to add emotional resonance to their narratives. Furthermore, pro-Russia accounts expanded their linguistic reach, posting in a median of six languages, a significant increase from just two in 2024, a capability likely powered by AI translation tools.

Despite these sophisticated upgrades, most inauthentic accounts struggle to gain substantial traction. A typical inauthentic account received only one engagement for every 3 to 50 posts. However, TwoSixTech identified an average of 15 pro-Russia “outlier” accounts each year that managed to attract tens of thousands of genuine followers. These high-impact accounts averaged 17 to 22 engagements per post, effectively serving as content hubs that amplify the broader inauthentic network.

Shifting Narratives Against the United States

A particularly striking discovery relates to pro-Russia actors’ significant escalation of attacks against the United States and its leadership. This marks a notable reversal from earlier pro-Trump messaging that previously characterized Russian influence campaigns. This strategic pivot is attributed to Moscow’s perceived frustration that the U.S. administration has not pressured Ukraine into terms favorable to Russia.

Between 2024 and 2026, anti-U.S. narratives from pro-Russia accounts surged. Personal attacks on the president and other U.S. figures increased by 264 percent, while messaging concerning U.S. military weakness climbed by 263 percent. Anti-U.S. conspiracy theories saw a 124 percent rise, and narratives linked to U.S. imperialism grew by 65 percent.

Concurrently, pro-China actors consistently advanced anti-U.S. narratives throughout the three-year period, with an increasing emphasis on portraying China as the global leader in AI development. By 2026, these accounts broadened their geographic scope, beginning to depict Japanese Prime Minister Sanae Takaichi as a puppet of the United States.

What You Should Do

  • Social media platforms must invest in advanced AI-powered detection tools that can identify subtle behavioral cues beyond simple post volume.
  • Researchers and platform security teams should prioritize monitoring the repurposing of aged accounts, as this tactic significantly complicates detection by conventional methods.
  • Users should exercise critical thinking when encountering highly emotional or politically charged content, especially from accounts with inconsistent posting patterns or a sudden shift in focus.
  • Enhance media literacy training to help users recognize sophisticated influence tactics, including AI-generated images and multilingual content designed to manipulate public opinion.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackSecurity

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Microsoft Teams Exposes Wi-Fi Hotspot Data on Employee Devices

Next Post

Novo Nordisk Confirms Data Breach After Cyberattack

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OpenAI Daybreak Cyber Adds GPT-5.6 for Exploit Validation and Pentesting
August 11, 2026
Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA
August 10, 2026
Anthropic Claude: New Security Feature Automates Agent Access Approvals
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us