Empire Dragon Accelerates Covert Information Operations, Converges with Russian Narratives

Recorded Future’s Insikt Group attributes a long-running coordinated inauthentic information operation, dubbed ā€œEmpire Dragon,ā€ to actors likely aligned with the Chinese state; the operation uses multilingual accounts, impersonation, and content amplification to push narratives and has recently converged with themes from Russian disinformation. Insikt Group warns the network is refining tactics (including using large language and image models) to target US and Taiwanese elections and to improve reach and believability. #EmpireDragon #RecordedFuture

Keypoints

  • Insikt Group links the ā€œEmpire Dragonā€ network to a coordinated, inauthentic information operation likely based in China and aligned with Chinese government objectives.
  • The network has operated since early 2021 and shifted focus from Chinese domestic topics to U.S. and allied audiences after August 2022.
  • Empire Dragon uses multilingual posts across platforms, account impersonation, fringe groups and ā€œuseful idiotsā€ to amplify narratives, but has struggled to gain organic engagement.
  • There is a measurable convergence between Empire Dragon narratives and Russian disinformation, with the Chinese-aligned network amplifying Russian-origin narratives.
  • Poor content quality (machine translation, low-quality imagery) has limited impact so far, but adoption of multilingual LLMs and advanced image-generation models is expected to increase effectiveness.
  • Recorded Future predicts the network will refine tactics to influence major 2024 events (Taiwan and U.S. elections) by promoting candidates, attacking leaders, and polarizing voters.

MITRE Techniques

  • [T1585] Establish Accounts – Creating and operating inauthentic and impersonated accounts to conduct coordinated information operations (ā€˜coordinated and inauthentic operation…’).
  • [T1078] Valid Accounts – Using impersonated or otherwise leveraged accounts to publish and amplify narratives across platforms (ā€˜account impersonation’).
  • [T1583] Acquire Infrastructure – Deploying multilingual posting infrastructure and cross-platform distribution to reach global audiences (ā€˜engage in information operations… through various languages, topics, and platforms’).
  • [T1204] User Execution – Recruiting or manipulating ā€œuseful idiotsā€ and fringe political groups to disseminate and amplify content (’employing ā€œuseful idiots,ā€ fringe political groups’).
  • [T1588] Obtain Capabilities – Integrating multilingual large language models and image-generation models to improve content quality and believability (ā€˜improvements in multilingual large language models and image generation models’).

Indicators of Compromise

  • [Domain] Report and analysis hosting – recordedfuture.com (original analysis and blog post), go.recordedfuture.com (PDF report link).
  • [File] Report PDF – https://go.recordedfuture.com/hubfs/reports/cta-2023-0830.pdf (full analysis available as downloadable PDF).
  • [Asset] Image/content host – cms.recordedfuture.com/uploads/… (image assets used in the published analysis).

Recorded Future’s technical assessment identifies Empire Dragon as an organized information operation employing structured account and infrastructure tactics to disseminate narratives. The operation establishes and manages inauthentic and impersonated accounts across multiple platforms (establish accounts / valid accounts), builds or acquires multilingual distribution infrastructure to post and syndicate content, and uses third-party actors—described as ā€œuseful idiotsā€ and fringe groups—to artificially amplify messaging. These operational choices map to common adversary behaviors: account creation/establishment, exploitation of valid accounts for posting, and acquisition of dissemination capabilities.

Operational constraints observed include low organic engagement driven by poor content quality (machine-translated text and weak imagery) and sporadic amplification. Technically, the network is positioned to upgrade its toolchain: adoption of multilingual large language models and advanced image-generation models represents an Obtain Capabilities pathway that will likely increase content coherence and cross-language believability. Analysts note a shift toward amplifying externally originated narratives (notably from the Russian disinformation ecosystem), indicating reuse of third-party content and coordinated cross-campaign amplification techniques.

Recorded Future anticipates continued refinement ahead of 2024 geopolitical events; defenders should monitor account-establishment patterns, cross-platform posting infrastructure, sudden upticks in coordinated amplification, impersonation activity, and the emergence of higher-quality, AI-generated multilingual content as indicators of increased operational capability.

Read more: https://www.recordedfuture.com/empire-dragon-accelerates-covert-information-operations-converges-russian-narratives