Before the Breach: How AI-Driven Information Operations Create the New Cyber Pre-Attack Surface

Ksenia Iliuk

BSides Seattle 2026 · Day 1 · Track 1

A specialist with a national security background in countering hostile state information operations presented a compelling case that social media has become a critical cyber pre-attack surface. Drawing on direct experience countering Russian influence campaigns and a detailed case study the team internally called "Sora Ganganger," the speaker demonstrated how generative AI has fundamentally changed the economics of information operations, enabling smaller actors -- not just nation states -- to run sophisticated, multi-language, cross-platform campaigns that converge with cybercrime, fraud, and malware distribution.

AI review

A well-constructed case study showing the convergence of information operations and cybercrime, with the Sora Ganganger campaign demonstrating AI-generated malware delivery through Meta ads that evaded VirusTotal. The talk is more operational intelligence than technical research, but the specific indicators -- infrastructure reuse patterns, keyword evasion, geoclocking -- provide actionable detection methodology for CTI teams.

Watch on YouTube