Alberto Fittarelli
@fittarelli
Sr. Researcher @citizenlab.ca, Disinformation & Harassment. Fmr. Meta. Trainer: find & expose covert influence. I like doers. Opinions my own.
8/ It's then obvious that a much broader ecosystem of PRC operations exists out there that awaits to be discovered. Most will have zero impact. But it depends on how we calculate impact: is it polluting the web and its AI crawlers? Is it pushing dissidents to silence? Or burning through gov budget?
7/ On Gem Herald, "Archie Watson" is the sole author of articles that, when not stolen elsewhere, are labeled as 100% AI-made by verification tools like @pangram.com . The articles often push familiar narratives.
4/ "Reveal Scum", the contents of which I won't show, followed the HKLEAKS playbook almost to the letter. Completely anonymous, with good operational security. A couple of generic Wordpress usernames ("Autumn" and the Chinese equivalent for "admin"). Anonymous hosting on US and Canada-based infra.
3/ OpenAI identified it as part of a much larger effort to target dissidents (and the Japanese PM), revealing the enormity of its scale in terms of human and technological resources deployed by the actors.
10/ So - is this another PAPERWALL, plus some extras? Not in scale. Here: 10 websites with no traffic, one probably purchased FB page with no engagement. But what's in it for Jack Sanders? No one really knows. But his profile as a "serious conman" with a pro-China angle should keep folks alert.
9/ But this whole campaign really unraveled when someone using Sanders' son's name, Richard, reached out to ICIJ reporter @scillaa.bsky.social - co-author of the "China Targets" investigation on China's transnational repression methods. Richard wanted to learn more about what Scilla was working on.
8/ Now? Sanders seems to be taking over Facebook pages out of Botswana to run "livestreams" on the politics of the Philippines, or publish dubious articles on his "news" websites, under a variety of aliases. In fact, even @whljustin.bsky.social is now being impersonated after writing about him!
7/ Then, he re-emerged in 2004 as the (discredited) source of a scandal: the NZ intel service would have spied on the country's Māori leaders. A government investigation then dismissed the claims as made-up: www.beehive.govt.nz/release/pms-...
6/ But his story goes much farther back. In fact, we first see him emerging to public news in 2003, when he's blamed for a supposed passport reselling scheme involving China, Nauru, and other countries - codenamed "Operation Weasel": en.wikipedia.org/wiki/Operati...
5/ That's far from the only random venture that Sanders has been linked to over the years. From hosting diplomats, to posing as one, he seems to be actively making political connections - and it's unclear what his goals, or even just legitimacy, are.
4/ On top of "news" sites, Sanders seems to run other websites - including one for a never-before-heard-of religious order, where he shows up dressed as a priest, and signs his posts as "Granf Toff Quid".
3/ Which may not be surprising. After all, Sanders can be seen attending the "17th China International Public Security Products Expo and Smart and Security Industry Development Conference" in Beijing in 2024. http://chinarta[.]com/m/view.php?aid=170306
1/ The New Zealander now known as "Jake Sanders" seems to run, or at least be closely associated with, a small network of "news" websites that were either coopted, or don't actually exist.
9/ Their *intended* audiences though? Australia, New Zealand, India especially. But also Bangladesh, Nepal, Sri Lanka, and others - covering what was left unaddressed in Asia by the original PAPERWALL network.
8/ Let me repeat once more: there is NO indication that these sites get any legit traffic. It's important to keep it in mind. That doesn't mean this isn't toxic however, or potentially harmful if activated to target individuals or organizations, like the older sites would do.
7/ The content is often - but not always - repeated across the sites, just like the old PAPERWALL websites would do. Typically, this is clustered around target audiences: AU & NZ readers? Here's a story on how "the Trump admin first approved the supply of weapons to Kiev". Others? Different ones.
6/ That's an important detail to this day. Pivoting off the IP addresses historically utilized by PAPERWALL websites, we can still observe new but almost identical websites being sprung up. And they now host their images... on ru.updatenews[.]info, a subdomain of the Haimai website.
5/ That eventually led us to attributing PAPERWALL. A Chinese marketing firm called (in short) Haimai shared advertising infrastructure with one of the earliest websites ever set up for the network: updatednews[.]info.
4/ But the real telling signs that the websites were all run by the same people were: their domains were all hosted on a small group of IP addresses; and their images were often hosted directly on a website functioning as a central hub, and also run by the same actors.
3/ The websites lifted entire articles from real outlets in the target country. Not only that: they linked directly to the content hosted on the cloned websites, saving effort and hosting space to themselves.
2/ Let's recap quickly. PAPERWALL was (well, is) a network of poorly set up websites mimicking local news outlets in dozens of countries globally. In our report, we mapped out their geographical focus at the time - which notably left out Africa, most of SE Asia, and Oceania.
4/ China, Russia, Iran. Sure, we know, they run IOs all the time. But aren’t countries that are not US adversaries doing it too, with equally harmful consequences? Our JUICYJAM and PRISONBREAK reports at @citizenlab.ca at least stand to prove otherwise.
3/ Why is “CIB” now almost an afterthought at the bottom of the report? Did the influence operations threat and harm landscape fundamentally change? I beg to differ.
2/ Why “First Half 2026” now when it used to be quarterly and even more frequent before that? What next?
4/ The creation date for several of the accounts is also telling. Very often, they were registered over the past ~2 months.
3/ I could probably spend the whole day listing accounts like these - posting the hashtags in question in large volumes.
2/ A significant number of accounts pushing the usual pro-Pahlavi hashtags, plus some new ones, look like this. “Account based in [name country]”. See that “shield” icon to the right? That’s X telling us not to trust the location as the user is on a VPN.
We also happen to know this about Homan: abcnews.go.com/Politics/doj...
Let me be *really* clear. Confirmation bias is NOT believing your eyes when you have multiple clear data sources *all* confirming what they see. Check the bodycam footage. Check the NYT multi-angle reconstruction, and the witnesses statements. This was plain murder.