Friday, February 5, 2021

Coordinated Behavior in Libya’s Regional Disinformation Conflict

An activist waves Libya's first post-independent flag in Benghazi, 2011. (Al Jazeera English, https://flic.kr/p/9mcRfg; CC BY-SA 2.0, https://creativecommons.org/licenses/by-sa/2.0/) In June 2020, forces aligned with Libyan General Khalifa Haftar suffered further losses in Libya’s long civil war. As news broke that his Libyan National Army was withdrawing from Tarhuna, social media was immediately flooded with jingoistic propaganda. Accounts loyal to both the Government of National Accord in Libya — supported militarily by Turkey — and the Libya National Army — supported by Egypt, the United Arab Emirates (UAE), Saudi Arabia and Russia — attempted to spin the dynamic events on the ground in their favor.  This near-immediate online propagandizing is nothing new in Libya or the Middle East. Propaganda and disinformation, particularly campaigns originating from state-backed entities, are long-standing features of the conflict. For instance, a recent report found evidence of coordinated online activity concerning Libya that dates as far back as 2013. As the conflict has evolved, so too have these foreign-backed information operations, reflecting shifting regional and international interests and alliances.  When Gen. Khalifa Haftar withdrew from Tarhuna in June 2020, we captured a tranche of Twitter data and discovered a likely state-backed information operation, demonstrating how regional actors attempted to manipulate the narrative of Haftar’s withdrawal in support of their interests.  Foreign intervention online, both real and perceived, has broadly undermined the confidence of civil society in the authenticity of political discourse across the region and beyond. State-backed information operations targeting Libya have led to a deeply polarized information landscape. Twitter and Facebook have been substantially polluted by automated accounts and fake pages; narratives pushed by these inauthentic networks are often filtered through news sources that are controlled by regional interveners but that masquerade as neutral journalism.  This information ecosystem obscures suspicious origins and legitimizes foreign-backed narratives. Non-state digital marketing firms have become increasingly important in creating this environment. These firms are often responsible for conducting and administering operations, allowing states to outsource the technical expertise necessary to conduct influence campaigns while also providing them with plausible deniability. The use of these third-party social media marketing firms to conduct information operations related to Libya’s civil war mirrors the use of foreign mercenaries on the ground, with varying degrees of state sanction and affiliation. Regional Information Operations and Haftar ’ s Withdrawal Egypt, the UAE, Saudi Arabia and Turkey have all been implicated in information operations throughout the duration of Libya’s civil war. These campaigns reflect sharply defined regional rivalries and evolving interests on the ground.  Previous campaigns exposed by researchers involved coordinated and inauthentic hashtags trending on Twitter, some of which would occasionally appear on Facebook. In March 2019, Democracy Reporting International identified a hashtag campaign that anticipated Haftar’s attempt to seize Tripoli. Later in 2019, the Atlantic Council’s Digital Forensic Research Lab identified another campaign supportive of Haftar; the strongly pro-UAE stance suggested it was created by supporters of the UAE. Twitter has also made a number of important removals of accounts that were affiliated with state-backed information operations related to the conflict. Notably, account takedowns announced in September 2019, December 2019 and April 2020 have been tied to Egyptian, Emirati and Saudi Arabian-backed information operations in Libya. Broadly, these campaigns strongly supported Haftar and the Libya National Army, opposed Qatar and Turkey, and were coordinated with events on the ground. There have also been multiple removals of Facebook pages that the company claims were tied to state-backed influence operations. Both Russia and Egypt have been implicated in state-backed operations on Facebook targeting Libya. As Libya National Army forces withdrew in June 2020, a series of highly politicized hashtags began trending on Twitter. We downloaded and analyzed the data from 10 separate hashtags that trended between June 5 and June 28. Our findings build on trends identified in previous research.  The first batch of hashtags we analyzed were strongly aligned with the Egyptian, UAE and Saudi axis. “The Egyptian Army” (#الجيش_المصري) trended in Arabic on June 8—the day the cease-fire outlined in Egyptian President Abdul Fattah al-Sisi’s “ Cairo Declaration ” was due to take place. In total, we collected and analyzed a dataset of 31,461 tweets with the hashtag and identified activity that suggests it was both coordinated and inauthentic. Activity that is coordinated and inauthentic uses multiple fake accounts in concert to mislead users about the popularity of a hashtag through artificial inflation. While definitive attribution of these campaigns is difficult, given the content of the hashtag and previous disclosures by both Twitter and Facebook, it is highly likely that this campaign was created by entities affiliated with the Egyptian state.  The hashtag was filled with extreme patriotic messaging in support of the Egyptian military. A time lapse of the hashtag revealed two suspicious tweet spikes: The first occurred at 2:51 a.m. on June 8, when 367 tweets with the hashtag were produced in a single minute; a few hours later, there was another spike of 356 tweets in a single minute (Figure 1).  Figure 1. Minute time-lapse of “The Egyptian Army” (#الجيش_المصري) hashtag, showing two suspicious spikes of tweets in a single minute. We also found two suspicious spikes in account births. The number of accounts created on a single day can potentially indicate coordinated activity; an application or a person may create a large group of accounts at once in order to artificially inflate a hashtag. After analyzing all the accounts that tweeted this hashtag, we found two suspicious spikes in account births: 61 of the accounts were created on Jan. 5, 2017, and 62 of the accounts were created on June 8, 2020 (Figure 2).  Figure 2. Graph of account creation dates for accounts tweeting on “The Egyptian Army” (#الجيش_المصري) hashtag, showing two suspicious spikes in account birth days. After manually investigating these 123 accounts, we found suspicious similarities in the style of profile pictures included within each group. Many of the accounts were already flagged by Twitter for suspicious activity and shared the same or similar profiles and banner photos as other accounts.  Figure 3. Accounts created on the two spiked account birth dates share the same or similar profile and banner photos. Figure 4. Many of the accounts created on these two dates were already suspended or restricted by Twitter. Analysis of the relationships between these accounts found the network to be incredibly dense, meaning that all 123 accounts were equally retweeting each other, with no single or smaller group of “influencer” accounts dominating (Figure 5). The network is an incredibly dense echo chamber, retweeting only within its own network and rarely interacting with accounts outside of those that were created on the same day.  Figure 5. Gephi graph showing the density of the network of these accounts. This coordinated, inauthentic campaign in support of the Egyptian army reflected changing dynamics on the ground. Whereas previous information operations strongly praised Haftar and supported his campaign for Tripoli, this online campaign did not focus on the Libyan general — indicating the departure of Haftar from the center of Egypt’s narrative on Libya.  As Haftar withdrew, Egypt’s emphasis shifted quickly to shoring up domestic support and promoting domestic interests — namely, security along the western border. The specious promotion of the Egyptian military online demonstrates how digital manipulation is a low-cost alternative to direct military engagement. The most extreme language appears online, providing an outlet for nationalistic militarism at arm’s length from the regime. Domestically, this approach creates the perception that the regime is responding aggressively to threats to Egypt’s western border; for Egypt’s regional rivals, it clearly signals that these threats are Egypt’s red line. Bellicose rhetoric is reserved for the online theater and reflects Cairo’s underlying strategic objective: securing its porous western border. Another hashtag, “Erdogan is a war criminal,” also exhibited suspicious characteristics. This tag trended on June 8, and we collected 12,995 tweets containing it between June 2 and 9. Tweets contained in the hashtag included vitriolic attacks on Turkish President Recep Tayyip Erdogan, with crude jokes and memes that often
Coordinated Behavior in Libya’s Regional Disinformation Conflict posted first on http://realempcol.tumblr.com/rss

No comments:

Post a Comment