Full Report
The US government has sanctioned Russian state-affiliated entity CGE, which used a vast GenAI infrastructure to spread disinformation during the US Presidential election
Analysis Summary
# Threat Actor: Center for Geopolitical Expertise (CGE)
## Attribution & Identity
**Attribution:** Russian state-affiliated entity.
**Aliases and Associations:**
* Directly received direction and financial support from the Russian Main Intelligence Directorate (GRU).
* Led by CGE Director Valery Mikhaylovich Korovin, who is also a GRU affiliate.
* The GRU provided a network of US-based facilitators to support operations.
## Activity Summary
The group executed a sophisticated, state-sponsored GenAI-based disinformation operation targeting the 2024 US Presidential election. Their goal was to sow discord and circulate disinformation about candidates. Sanctioned by the US Treasury Department for these activities.
## Tactics, Techniques & Procedures
- Use of Generative AI (GenAI) tools to rapidly create disinformation content.
- Creation of deepfakes to produce baseless accusations concerning a 2024 presidential candidate.
- Establishment of a network of at least 100 websites designed to imitate legitimate news outlets to create false corroboration between false stories.
- Infrastructure setup designed to avoid hosting services that would block their activity, thereby obfuscating their Russian origin.
## Targeting
- **Sectors:** Political/Electoral processes.
- **Geography:** United States.
- **Victims:** US Electorate (as targets of disinformation); US Presidential Candidates (as subjects of fabricated content).
## Tools & Infrastructure
- **Malware families used:** Not explicitly named, but utilized GenAI tools and deepfake technology.
- **Infrastructure (C2, domains, IPs):**
- Maintained an AI-support server.
- Utilized a network of at least 100 websites masquerading as news outlets.
- Employed US-based facilitators to build and maintain infrastructure.
## Implications
This activity highlights Russia's utilization of cutting-edge technology (GenAI and deepfakes) to interfere in democratic processes abroad. The operation shows a strategic emphasis on creating a deceptive information environment through synthesized media and extensive imitation of trusted news sources to amplify internal division within the US.
## Mitigations
- Increased vigilance against state-sponsored disinformation campaigns utilizing synthetic media (deepfakes, GenAI-generated content).
- Review of digital infrastructure to detect and block activity originating from known disinformation networks aiming to mimic legitimate journalism.
- Enhanced detection capabilities for deepfake manipulation in multimedia content.