China Unleashes AI-Powered Image Generation For Influence Operations

 Ai distorted

China has revealed a new cyber capability driven by artificial intelligence, enabling the automatic creation of images for influence operations. These operations seek to emulate US voters across the political spectrum, stoking controversy along racial, economic, and ideological lines.

The revelations stem from a recent report issued by the Microsoft Threat Analysis Centre (MTAC) on Thursday. Titled "Sophistication, scope, and scale: Digital threats from East Asia increase in breadth and effectiveness," the research highlights the growing threat of influence operations and cyber activities in the East Asia region.

In particular, China-linked actors are employing AI-generated media to target politically divisive subjects such as gun violence and derogatory US political figures and symbols. This technology surpasses previous campaigns with attention-grabbing content. The extent and timing of its widespread deployment remain uncertain.

Microsoft stressed the urgency of addressing the weaponisation of AI technology by cyber and influence threat actors.

Furthermore, China-based threat actors have been observed carrying out cyber operations centred on the South China Sea region, targeting regional governments and industries. The US defence industry and infrastructure are also under scrutiny. Notably, Storm-0558, a China-based threat actor, gained access to Microsoft customer email accounts from approximately 25 organisations, suggesting espionage motives.

For more information on Storm-0558, please read: Microsoft Accused of Negligence in Recent Email Compromise

China maintains a global presence with state-sponsored propaganda efforts aimed at enhancing its image abroad. More than 230 state media employees and affiliates pose as independent social media influencers, promoting CCP propaganda to a combined following of 103 million people across 40 languages on Western social media platforms.

However, unlike Iran and Russia, China has not yet combined cyber and influence operations, as noted by Microsoft. Meanwhile, North Korea focuses on intelligence gathering and cryptocurrency theft. The maritime and shipbuilding sectors are prime targets, with recent espionage activities directed at the Russian government and defence industry, along with support for Russia in the Ukraine conflict.

The report anticipates increasing threats from China and North Korea, particularly towards Taiwan and the United States, in the lead-up to the 2024 elections. Cross-industry collaboration is crucial to confronting these challenges as nation-state actors continue to exploit vulnerabilities and propagate damaging narratives on a global scale.
Read more on Storm-0558: Microsoft Accused of Negligence in Recent Email Compromise

Related Articles

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.