Before the Breach: How AI-Driven Information Operations Create the New Cyber Pre-Attack Surface
Ksenia Iliuk
BSides Seattle 2026 · Day 1 · Track 1
Overview
A specialist with a national security background in countering hostile state information operations presented a compelling case that social media has become a critical cyber pre-attack surface. Drawing on direct experience countering Russian influence campaigns and a detailed case study the team internally called "Sora Ganganger," the speaker demonstrated how generative AI has fundamentally changed the economics of information operations, enabling smaller actors -- not just nation states -- to run sophisticated, multi-language, cross-platform campaigns that converge with cybercrime, fraud, and malware distribution.

Key moments
- 0:00 Introduction: from national security IO to the cyber attack surface
- 2:00 How generative AI changed the economics of influence operations
- 4:00 Sora Ganganger: 53 AI-generated Meta ads delivering malware
- 8:00 Infrastructure reuse: Facebook page transparency as detection signal
- 12:00 Vietnamese disinfo-for-hire company behind the campaign
- 14:00 500 deepfakes of Fortune 500 bank chairman with $20 ad budget
- 20:00 AI-generated soldiers on TikTok with no text or hashtags
- 26:00 Future threats: agentic IO, microtargeting, influence-as-a-service
Before the Breach: How AI-Driven Information Operations Create the New Cyber Pre-Attack Surface
Speakers: Unknown (National Security / Information Operations Specialist, Ukrainian background)
Conference: BSides Seattle 2026
YouTube: https://www.youtube.com/watch?v=i3g51q6ibtw
Overview
A specialist with a national security background in countering hostile state information operations presented a compelling case that social media has become a critical cyber pre-attack surface. Drawing on direct experience countering Russian influence campaigns and a detailed case study the team internally called "Sora Ganganger," the speaker demonstrated how generative AI has fundamentally changed the economics of information operations, enabling smaller actors -- not just nation states -- to run sophisticated, multi-language, cross-platform campaigns that converge with cybercrime, fraud, and malware distribution.
The talk is significant because it bridges a gap that most security organizations still have: information operations (IOs) are typically treated as a geopolitical or communications problem, not a cybersecurity problem. The speaker showed that the initial stages of IO campaigns and cyber attack campaigns are indistinguishable until the final click, which means the detection and response responsibility falls into an organizational gap that few enterprises have addressed.
Background
▶ Watch: Introduction: from national security IO to the cyber attack surface (0:00)
Historically, information operations were the domain of large hostile states -- Russia, China -- with intelligence agencies running long-term, expensive campaigns. The cost was not in acquiring social media profiles (buying Facebook pages has always been cheap) but in maintaining them, personalizing content, and operating across multiple languages. Traditional detection relied on keyword monitoring, plagiarism detection (copy-paste reuse of identical posts), and spotting Google Translate errors in low-resource languages.
Generative AI has collapsed these barriers. Content can be rewritten in unlimited variants (defeating plagiarism detection), localized into any language with near-native fluency (defeating translation-error detection), and personalized with country-specific imagery from a single prompt. The speaker referenced the EU's new term FIMI (Foreign Information Manipulation and Interference) as another indicator of the evolving landscape, alongside the well-known Russian Doppelganger IO campaign that cloned major media websites (CNN, BBC).
Key Findings
▶ Watch: Sora Ganganger: 53 AI-generated Meta ads delivering malware (4:00)
The "Sora Ganganger" case study was the centerpiece. The team discovered 53 unique AI-generated Meta ads promoting OpenAI's Sora model (before its public release), targeting the US, Ukraine, Vietnam, Germany, Taiwan, and China. Each ad was localized with country-specific AI-generated video (the Ukrainian variants featured the Kremlin burning). Clicking the ads led to perfect replicas of the ChatGPT interface where users could enter prompts and receive a "video download" that was actually malware installed directly on the device.
Critical operational details emerged:
- At the time the campaign was active, none of the malicious domains were flagged by VirusTotal or any other provider as malicious
- The campaign used 31 Facebook pages, some newly created with random names, others repurposed from previous campaigns -- the reuse of infrastructure was a key detection signal
- Meta's transparency features (showing page name change history) were one of the strongest signals for identifying infrastructure reuse
- The infrastructure traced back to a corporation in Vietnam (Mudbau Corporation) that showed indicators of being a "disinfo-for-hire" entity, reusing the same pages for election interference, crypto scams, and credential harvesting on different days
- Keyword evasion was deliberate: many ads promoted Sora without mentioning "OpenAI" by name, specifically to avoid keyword-based monitoring
Two additional cases demonstrated the convergence pattern: a Fortune 500 bank was attacked with over 500 deepfakes of their chairman promoting a fictitious banking feature (with a $20 Meta ad budget to test detection speed), leading to phishing infrastructure; and a celebrity deepfake campaign directing to a crypto scam. All three cases -- malware, phishing, fraud -- looked identical in their social media patterns until the final payload.
Technical Deep Dive
▶ Watch: Vietnamese disinfo-for-hire company behind the campaign (12:00)
The speaker outlined several technical dimensions of modern IO detection. Behavioral indicators are more reliable than content analysis because threat actors weaponizing social media infrastructure exhibit distinctive patterns regardless of the narrative content. The fact-checking approach fails because the content itself may be technically accurate -- there is nothing to "fact-check" in a post promoting an AI tool.
Bot detection remains the easier case: the team caught a Balkan bot infrastructure reposting sanctioned RT articles 89 times per second, which is trivially identifiable. The harder case is paid amplification using real accounts, where individuals (often stay-at-home parents in Eastern Europe) are recruited on Telegram for as little as $5 per day to post content.
TikTok was identified as the trickiest platform for detection because it is not account-based in the same way as Meta: a newly created account can post a single video that goes viral immediately, giving defenders almost no window for identification. Additionally, video content is rarely monitored by corporate security teams -- they typically only monitor captions or subtitles. The speaker cited a case of AI-generated soldiers reporting from a frontline, calling on comrades to abandon positions, with no title, no hashtags, and no text -- discoverable only through pattern recognition and a custom model performing descriptive video analysis.
Geoclocking (showing different content based on geographic location) was identified as an increasingly common tactic, previously seen primarily in fraud but now adopted by IO campaigns. The speaker also emphasized data availability challenges: detection quality is only as good as the data lake, and discovering new Telegram channels requires fundamentally different methodology than discovering new Facebook groups due to Telegram's non-algorithmic structure.
Demo / Proof of Concept
▶ Watch: 500 deepfakes of Fortune 500 bank chairman with $20 ad budget (14:00)
The talk did not include a live technical demo but functioned as a detailed case study walkthrough. The speaker showed screenshots of the Meta ads, the fake ChatGPT interface, the domain infrastructure, and the Facebook page transparency data revealing historical name changes. This evidence-based approach effectively demonstrated the operational reality of the threat.
Defensive Implications
▶ Watch: Future threats: agentic IO, microtargeting, influence-as-a-service (26:00)
The speaker posed a critical organizational question: if a hybrid IO/cyber campaign targets your organization, who is responsible for detecting it? The response plan requires coordination across security, legal, and communications teams. Key defensive considerations:
- Takedowns are not always feasible. Only clear impersonation cases have reliable takedown timelines (24-48 hours). Bot network takedowns require extensive proof and can take much longer. For cases where takedown is impossible, communications teams may need to counter-narrate (as in the case of a hostile state organizing a bank run via Telegram by claiming massive layoffs).
- Social media monitoring must expand beyond dark web and Telegram. TikTok, YouTube, and Facebook are where preparation for attacks increasingly starts.
- Organizations need hybrid response plans that connect security teams directly with legal, communications, and business stakeholders, with pre-established relationships and practiced coordination.
Looking ahead, the speaker anticipated agentic IO campaigns, extreme microtargeting at the level of individual preferences and personal data, LLM-powered engagement in comment sections that can reason and discuss, deepfake clusters (like the 500-deepfake bank attack), and growth of influence-as-a-service companies within the next 6-12 months.
Key Takeaways
- Generative AI has democratized information operations: the Sora Ganganger case was traced to a Vietnamese corporation, not a nation state, and the same infrastructure cycled between election interference, crypto scams, and credential harvesting
- Social media IO campaigns and cyber attacks are indistinguishable in their early stages -- both use the same infrastructure, tactics, and platforms until the final payload delivery
- Traditional detection methods (keyword monitoring, plagiarism detection, translation-error spotting) are increasingly ineffective against AI-generated, multi-variant, multi-language content
- Behavioral and coordination indicators are more reliable than content analysis; Meta's page transparency features showing name change history are among the strongest signals
- Organizations need to answer the question: who detects a hybrid IO/cyber campaign, and can security, legal, and communications teams coordinate a response within operational timelines?
- The Romanian election cancellation due to TikTok-based IO interference that went undetected because nobody was monitoring TikTok is a cautionary tale for coverage gaps
About the Speaker(s)
The speaker comes from a national security background focused on countering hostile state information operations, with particular expertise in Russian IO campaigns. They are Ukrainian and have firsthand experience with information warfare. They work in a product capacity focused on detecting and analyzing information operations across social media platforms, and this was their first time presenting at a conference in Seattle.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A well-constructed case study showing the convergence of information operations and cybercrime, with the Sora Ganganger campaign demonstrating AI-generated malware delivery through Meta ads that evaded VirusTotal. The talk is more operational intelligence than technical research, but the specific indicators -- infrastructure reuse patterns, keyword evasion, geoclocking -- provide actionable detection methodology for CTI teams.
Heather Calloway (CISO) — STRONG ACCEPT
This talk directly addresses a critical governance gap: most organizations have no owner, no playbook, and no cross-functional coordination for the convergence of information operations and cyber attacks. The Sora Ganganger case study and the Fortune 500 bank deepfake attack make the business risk tangible, and the speaker's organizational readiness questions are exactly what CISOs and boards need to hear.