A Deeper Dive: Looking into the Data

We’ll explore the details of these themes diving into data and content below.

Retweet Network Visualization

A Gephi retweet network extracted from tweets targeting the Hong Kong protests from June 2019 onward. This network consists of 4,139 Twitter accounts and 4,449 connections between them (representing retweets).

A magnified view of the main political cluster the retweet network. @HKPoliticalNew, @bindarsou, @ctcc507, @simsoer, and @ctcc507 are the most influential nodes in this cluster³, making them five of the most influential accounts in this disinformation campaign.

Content Themes: Discrediting Protests as Operations of the CIA, Western NGOs and the “American Empire”

One of the most common themes in this dataset is that Hong Kong’s current protests have been staged and funded by the CIA and Western NGOs and activist groups. The US in particular is seen as a chief funder and manipulator behind the scenes. Much of the disinformation spread in this regard takes on a xenophobic flare, using derogatory terms such as Western dog (洋犬) or Western ghost (洋鬼子) to describe foreigners⁴. Several of these tweets came from @HKPoliticalNew, one of the most influential accounts in the dataset.

RT @HKpoliticalnew: 圖中外國人Larry於香港多次暴亂中提供資助及訓練和幕後指導和策劃行動，呢就系黃屍一直隱瞞及唔願提及嘅外國勢力。#顏色革命 #外國勢力 #Larry #暴動策劃者 RT @ HKpoliticalnew: The foreigner in the picture, Larry, has provided funding and training in several Hong Kong riots, as well as plotting and directing the moves from behind the scenes. These are yellow corpses⁵, always concealing (their intent) and never willing to mention foreign powers. #ColorRevolutions #ForeignPowers #Larry #RiotPlotter Tweetid: 1143150702820126722 Brian的公開身份是國際學校的退休教師，1990年在內地搞罷課後赴美讀書，後在多國教導「人權」課程，散播顏色革命思想，又帶學生赴印度「藏獨」村學習。11年前來港定居，於國際學校教授請願、留守等技巧，向學生「洗腦」反華。現已退休的佢由幕後走到台前，在激進反對派隊伍充當軍師，衝擊法治。#洋犬 Brian is a retired professor at the international school. In 1990, after spending time in the mainland getting students to skip school and protest, he went to study in America. Afterwards, in many countries he taught “human rights” courses and disseminated color revolution thought, and brought students to a pro-Tibetan independence village in India. He’s lived in Hong Kong for 11 years now, teaching skills like petitions and protests, “brainwashing” students to be anti-Chinese. Now this retired teacher has stepped out from behind the scenes and taken center stage, playing the role of war advisor for the opposition, attacking the rule of law. #WesternDog Tweetid: 1144525809828474880 記者調查發現：反對派背後有一股強大的勢力在組織操控！反修例團體「香港人權監察」長期收美國國家民主基金會（NED）撥款共1500萬港元。NED創辦人Allen Weinstein直認NED大部分工作與美國中央情報局的秘密工作無異，只是以「人權」等公開模式進行，掩飾背後的隱蔽工作。#香港 #NED資助 #顏色革命 Investigative reporters found out: a large force is controlling the opposition. The Hong Kong Human Rights Monitor, a group opposing the amendment, has received funding totaling $15 million HKD ($1.9 million USD) from America’s National Endowment for Democracy (NED). NED’s founder Allen Weinsten admitted that the majority of NED’s work is no different from the secret work of the CIA, it simply uses “human rights” as a framework to do it. #HongKong #NEDFunding #ColorRevolution Tweetid: 1143372491789877248 也並非真嘅自發，利益使然！國外特工，諜影重重！#顏色革命 #香港 People did not do this (protest) purely out of their hearts, it’s because there are interests involved.Signs of foreign spies are piling up! #ColorRevolution #HongKong. Tweetid: 1140123806138294272 外國勢力策反香港政府嘅12個步驟【2】The 12 steps taken by foreign forces to overthrow the Hong Kong government【2】#香港 #顏色革命 #外國勢力 #香港時政直擊 https://t.co/U1e4aeuxpm Tweetid: 1139769001859403776

The allegation that the protests are paid or part of a centralized “color revolution” scheme is a de-legitimizing tactic that has been frequent in Russian disinformation campaigns. In his new book, This is Not Propaganda: Adventures in the War against Reality, expert Peter Pomerantsev describes the goal of these narratives:

“When the Kremlin crawls inside protest movements online, the very notion of genuine protest starts to be eroded, making it easier for the Kremlin to argue that all protests everywhere are just covert foreign influence operations. This reinforces the larger narrative the Kremlin (and Iranian and Chinese) media are trying to reinforce, that movements such as the color revolutions and the Arab Spring are not genuine but US-engineered regime-change plots, that there is no such thing as truly bottom-up, people-powered protest.”

Other tweets in the set more directly accuse the “American empire” (美帝) or the CIA itself of fomenting the protests.

RT @HKpoliticalnew2: 今天美帝指令要實行民主的地區是香港,明日的香港便如….. #香港 #顏色革命 RT @HKpoliticalnew2: Today the American empire orders that Hong Kong become a democratic territory, and tomorrow it’s like this…. #HongKong #ColorRevolution (This Tweet presumably was accompanied by a photo before being removed. Non-URL media is not currently publicly available. ) Tweetid: 1148235379188752384

Hashtags re-framing the protests as a question of support for the Hong Kong police were also frequent. #撐警行動 (#SupportPoliceAction) was the 25th most common hashtag in tweets occurring since the beginning of the protests in March 2019. #香港警察 (#HongKongPolice) and #警察 (#police) were also figured among the most frequent hashtags in this set.

Chinese Communist Bots — Dawn of the CCB

The usage of automated accounts to spread disinformation is a salient feature of this dataset. Several patterns in this data are tell-tale signs of bot activity — the usage of custom Tweet clients, identical original content posted simultaneously by multiple accounts, and high posting volume of several users in the set. While this is a well-documented phenomenon, the particulars of bot usage in this archive highlight the porous border between commercial spambots and political disinformation bots. This problem is particularly grave given the ease of buying fake accounts online, even on Facebook itself.

One account, @ranvijaysowle, created in April 2016, waited one year before making a post, and then averaged 274 posts per day until it was suspended. This account posted over 177,000 tweets in two years. Nine users in the set waited over 10 years before posting their first tweet. As DFRLab has noted, there is also a high linguistic diversity in the set, and several dates on which batch creation of fake accounts took place. Fourteen accounts in this set averaged over 100 tweets per day.

Escort services and sex-oriented accounts also feature prominently among these bots. @thesexxxtweets, @gonewildvids, @adultflixx are accounts that promote porn and escort services. Another user, @ronetaper, promoted the Ferris Wheel Hookup Platform on WeChat (摩天轮约炮平台), which is referred to as “China’s first hookup platform” and advertised as being available in China, Europe, and California. Several accounts on Twitter are still actively promoting this platform. These users do not appear to have any tweets mentioning Hong Kong or politics.

FaWave — a Custom Client for Automating Disinformation Attacking Dissidents

Custom clients — third-party software that post tweets for a user through Twitter’s API — were frequent in this dataset. While custom clients can be everyday tools popular with non-tech savvy users (such as TweetDeck), they can also be used for implementing bots or malware on Twitter. In this archive, several custom clients were used to help amplify spam or disinformation.

In particular, a Google Chrome PlugIn called “FaWave” was frequently used to send messages out from multiple accounts simultaneously. Over half of the 10,552 tweets sent from FaWave mention at least one of five Chinese dissidents⁶.

The Chrome Web Store developer description of FaWave, a Chrome extension that was frequently used to attack Chinese dissidents from multiple Twitter accounts simultaneously. The description reads “FaWave supports logging into accounts on common domestic and foreign social media. It was previously maintained by @QLeelulu and @Python发烧友, but later chrome removed it from the store. I’m also a user of this plugin and don’t want to let this good of a plugin disappear forever, so after obtaining @Python发烧友‘s consent, it’s back in the store.”

Several tweets criticizing Guo Wengui, sent simultaneously from multiple bot accounts using this plugin, remained live on Twitter after the official takedown. What’s more, many of these tweets matched word-for-word with multiple posts in Twitter’s released and attributed dataset, which meant several accounts showing significant signs of belonging to the same Chinese disinformation network were still active on the platform after the official takedown.

One of these users, @shouyuliu had the same profile photo as attributed user @katiushaegorov2. In another pair (1, 2), two bots criticize Guo’s “profiteering personality” for allegedly selling out and cooperating with foreign militaries. One of these users, @nick98486375, was only active for 19 days in October 2017. During this time the account tweeted nearly exclusively about Guo and produced over 1,200 tweets. Another triplet of centrally controlled bot accounts (1,2,3) — all created within the same 70 second window on February 5th, 2018 — posted identical messages about a Chinese court’s ruling on Guo’s alleged crimes the exact same minute on October 11th last year. Yet another pair of bot accounts (1,2) attack Guo and predict his demise at the hands of President Trump.

#郭文贵 郭文貴兩面三刀，懷疑一切的同盟，毫無任何誠信可言，相信同為商人出身的美國總統特朗普，將如此市儈的郭文貴掃地出門只是時間問題。而郭文貴與法輪功沆瀣一氣，為法輪功背書，直接導致其誠信徹底破產，成為一個國際小丑與笑話。郭文貴被美國掃地出門，被遣返回国接受審判將會是其最終結局。 #GuoWengui Guo Wengui is a backstabber. He’s suspicious of all alliances and completely untrustworthy. There’s no doubt that President Trump, who used to be a businessman as well, will get rid of Guo — it’s just a matter of time. The fact that Guo Wengui is in cahoots with Falun Gong and supports Falun Gong has completely destroyed his credibility and turned him into an international clown and joke. Guo Wengui’s final ending will be being swept out of America and standing trial at home. -@huolu6206284062 and @shenpanzhett

After official takedowns, accounts likely linked to the same Chinese disinformation network also remained active on Facebook — the message above can be found in messages posted by several suspicious Facebook accounts. For instance, a user named 范龍飛 posts the first part of the message above three separate times in 2017 — on September 28, October 1 and October 12.

Facebook user “范龍飛” posts near identical messages on three separate dates attacking Chinese dissident Guo Wengui. This exact phrase is contained within at least eight tweets from attributed Chinese state actors in Twitter’s public disinformation archive⁷. The majority of those tweets were also posted in the same time frame — September and October 2017.

Several other accounts posted identical messages during the same time frame.

A second Facebook user posting the exact same message as 范龍飛 in October 2017. (Archived here)

A third Facebook user posts the same message — the core substring beginning after “作為一個商人” (“as a business person”) is an identical match with the tweets from the Twitter bot accounts @huolu6206284062 and @shenpanzhett above. (Archived here).

Another Facebook account used multiple word-for-word matches from tweets in Twitter’s attributed archive in a longer post attacking Guo.

Another Facebook user weaved multiple word-for-word matches from Twitter’s attributed archive of disinformation spread by the PRC into a long form post attacking Chinese dissident Guo Wengui. Paragraphs in red rectangles above are text that matches attributed tweets in Twitter’s archive word-for-word. This account was removed from the platform after Facebook was notified of our research (post archived here).

The Daily Beast noted the presence of bot swarms attacking Guo on Twitter during this same time frame — October 2017. Twitter formally announced changes to the API to prevent posting similar content from multiple accounts in early 2018. Several pairs of accounts in the released dataset continued to post simultaneous messages from multiple bot accounts from the FaWave plugin after this date, such as @gwalcki4 and @mauricerowleyx. Twitter’s changes do seem to have reduced tweets from more than two profiles. Identical messages emanating from more than 10 accounts before the 2018 announcement occur multiple times in the data — with as many as 18 accounts posting simultaneous, identical messages on several occasions before early 2018.

While many of the tweets emanating from this client were political, not all were — this is, after all, the nation for which the term “cheerleading” propaganda was coined. For instance, nine users in this set used this custom client to promote a famous poem by Tang dynasty poet Li Bai about the nostalgic beauty of moonlight.

Messaging in Taiwan

While the focus of political messaging in this dataset was Hong Kong, some tweets in the set target foreign countries — specifically Taiwan and the United States. One Tweet from @lingmoms, a user claiming to be based in Las Vegas, Nevada, alleges that Taiwan has an unequal enforcement of freedom of speech.

台灣只有台獨的言論自由 沒有支持統一的言論自由？ Taiwan only has freedom of speech for those who support Taiwanese independence — what about freedom of speech for supporting unification? Tweetid: 1140998162640846848

This post also links to a debate of the same name on YouTube from Chung T’ien Television (CTI/中天電視), a Taiwanese TV channel. Simplified Chinese comments supporting the host’s pro-China stance dominate the comment sections of both the YouTube channel and Facebook page for the show.

This TV channel is part of the China Times Media Group (中時集團). In 2008, this group was acquired by a food company in Taiwan, the Wang Wang Group (旺旺集團), whose owner Tsai Eng-meng (蔡衍明) is an outspoken advocate for unification with the mainland. In Taiwan, concern has been growing about China’s influence on local media. Reuters recently revealed that Beijing is even purchasing positive coverage of the mainland in Taiwanese media. Protesters in Taiwan demonstrated in June against China’s influence on local media.

Other posts from @lingmoms link to additional content promoting the idea of unification — such as a speech from CTI TV host Huang Zhixian (黃智賢) supporting “returning Taiwan to our ancestors’ country” — or highlight America’s lack of commitment to Taiwan’s future. While all of these sources are local Taiwanese ones, China has shown a clear pattern in promoting content that idealizes unification of Taiwan and China.

Messaging in the United States

One account, @LibertyLionNews, also live-tweeted protests that ended in violence in Portland, Oregon on June 30th. This account described itself as “Conservative News from the USA and Abroad. #Catholic Defender of the Constitution of the United States. #Qanon #MAGA #BUILDTHEWALL #TRUMP #2A #1A ❌❌❌” and had garnered over 180,000 followers at the time of its suspension. Messages alleging that mainstream journalists supported antifa and decrying fact-checking organizations as biased featured among these tweets.