State-Sponsored AI Evades Bot Detection, Mimics Humans
Key Takeaways State-sponsored influence operations from Russia and China are increasingly employing AI to mimic human behavior and evade traditional bot detection on social media platforms like X....
Key Takeaways
- State-sponsored influence operations from Russia and China are increasingly employing AI to mimic human behavior and evade traditional bot detection on social media platforms like X.
- These advanced tactics include reduced posting frequency, increased use of AI-generated images, multilingual content, and simulated human sleep patterns.
- Research from TwoSixTech, spanning 2024-2026, reveals a shift from high-volume, low-quality posts to more sophisticated, persuasive content, often repurposing older accounts.
- Pro-Russia narratives have notably pivoted to aggressively attacking the United States and its leadership, while pro-China narratives emphasize China’s AI dominance and portray Japanese leaders as U.S. puppets.
State-Sponsored Influence Operations Evolve with AI to Bypass Detection
Influence operations orchestrated by state-backed actors from Russia and China have entered a sophisticated new phase, moving beyond rudimentary spamming to leverage artificial intelligence for more convincing human impersonation. This strategic evolution allows these accounts to bypass established bot detection mechanisms on social media platforms, as detailed in a recent report.
Table Of Content
This subtle yet profound shift signifies a critical advancement in foreign interference techniques, adapting to the AI era. Previously, researchers tracking inauthentic accounts promoting pro-Russia and pro-China narratives on platforms such as X (formerly Twitter) observed a focus on sheer volume, with automated bots rapidly churning out numerous posts.
However, the landscape has changed. These modern influence accounts now exhibit more nuanced behavior: posting less frequently, incorporating a higher proportion of images, and even mimicking human sleep cycles to evade platform moderation tools. This strategic change is documented in a comprehensive analysis.
Advanced AI Techniques Employed by Malign Actors
Analysts at TwoSixTech developed a novel machine learning methodology specifically designed to identify these sophisticated inauthentic accounts on X with high confidence. Applying this methodology to data spanning 2024, 2025, and 2026, the team uncovered significant trends.
According to a report shared with Cyber Security News (CSN), TwoSixTech analysts found that both Russian and Chinese actors dramatically reduced their post volumes by half while simultaneously enhancing content quality. This indicates a clear learning curve, with adversaries adapting from past, less effective tactics. Rather than generating entirely new accounts via AI agents, these actors are now repurposing older, established accounts for new campaigns, making them significantly harder to detect through conventional means.
Despite these advancements, the overall number of active inauthentic accounts on X remained consistent, fluctuating between 5,000 and 11,000 for both China and Russia across the three years analyzed.

These operations are no longer merely about covert presence; they actively aim to shape public opinion through richer, more compelling content. The integration of AI-generated imagery, multilingual posts, and realistic activity patterns suggests a calculated, long-term strategy rather than opportunistic disruption.
Russian and Chinese Influence Actors Use AI
A key finding highlights how these accounts leverage AI to emulate human behavior and circumvent bot detection systems. Pro-Russia and pro-China accounts now post at a deliberately slower pace, with many pro-Russia accounts exhibiting extended periods of inactivity daily, effectively simulating a human sleep schedule. This detailed behavioral mimicry is crucial for evading automated monitoring.
Between 2024 and 2026, the proportion of original posts featuring images more than quadrupled for pro-Russia accounts and doubled for pro-China accounts. Many of these images are AI-generated, designed to add emotional resonance to their narratives. Furthermore, pro-Russia accounts expanded their linguistic reach, posting in a median of six languages, a significant increase from just two in 2024, a capability likely powered by AI translation tools.
Despite these sophisticated upgrades, most inauthentic accounts struggle to gain substantial traction. A typical inauthentic account received only one engagement for every 3 to 50 posts. However, TwoSixTech identified an average of 15 pro-Russia “outlier” accounts each year that managed to attract tens of thousands of genuine followers. These high-impact accounts averaged 17 to 22 engagements per post, effectively serving as content hubs that amplify the broader inauthentic network.
Shifting Narratives Against the United States
A particularly striking discovery relates to pro-Russia actors’ significant escalation of attacks against the United States and its leadership. This marks a notable reversal from earlier pro-Trump messaging that previously characterized Russian influence campaigns. This strategic pivot is attributed to Moscow’s perceived frustration that the U.S. administration has not pressured Ukraine into terms favorable to Russia.
Between 2024 and 2026, anti-U.S. narratives from pro-Russia accounts surged. Personal attacks on the president and other U.S. figures increased by 264 percent, while messaging concerning U.S. military weakness climbed by 263 percent. Anti-U.S. conspiracy theories saw a 124 percent rise, and narratives linked to U.S. imperialism grew by 65 percent.
Concurrently, pro-China actors consistently advanced anti-U.S. narratives throughout the three-year period, with an increasing emphasis on portraying China as the global leader in AI development. By 2026, these accounts broadened their geographic scope, beginning to depict Japanese Prime Minister Sanae Takaichi as a puppet of the United States.
What You Should Do
- Social media platforms must invest in advanced AI-powered detection tools that can identify subtle behavioral cues beyond simple post volume.
- Researchers and platform security teams should prioritize monitoring the repurposing of aged accounts, as this tactic significantly complicates detection by conventional methods.
- Users should exercise critical thinking when encountering highly emotional or politically charged content, especially from accounts with inconsistent posting patterns or a sudden shift in focus.
- Enhance media literacy training to help users recognize sophisticated influence tactics, including AI-generated images and multilingual content designed to manipulate public opinion.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.