CyberWiseCon Europe 2026

Andriy Kusyy: The Hidden Layer of Cyberattacks

30:25 · 19 May 2026 – 22 May 2026 · YouTube

About this talk

This talk delves into the blind spots in the kill chain related to information operations and disinformation, highlighting their growing role in cyber attacks. The speaker, Andriy, co-founder of Last Data, shares insights from his background in artificial intelligence and machine learning, discussing how his team detects signals of misinformation across social media platforms. He emphasizes that traditional security teams often overlook these channels, focusing instead on domains and malware. Through real-world case studies, he illustrates how bot networks and state-sponsored actors exploit social media and ads for manipulation, demonstrating the evolving landscape of influence operations. The session underscores the urgent need for organizations to enhance their monitoring strategies and develop robust playbooks to counter these emerging threats, especially as the entry barrier for running such operations has drastically lowered due to advancements in technology.

Full transcript

Yeah, thanks everyone. It's a It's a morning of the second day, so it's quite an attended session. I'm surprised. And it's very new to be in such layout. It feels like you're about to present a Christopher Nolan new movie, but it wouldn't be that interesting, no worries. So, um I'm here to talk about the kill chain blind spot about information operations and disinformation as they are used

in the cyber attacks and as an essential step. I'm Andriy, one of the co-founders at Last Data. My background is in engineering, but primarily in artificial intelligence and machine learning. And uh what we do at Last Data is that we scan media and social media primarily for the governments, but now for the enterprises, too, and detect early signals of information operations and disinformation for the last few

years. And um when we think about the concept of the open internet uh in which we operate, I think oftentimes last year we started more and more looking into the discussions with the uh CTI teams and security teams in the things that people picture there. It's usually about the um domains, cyber forums, dark web, threat feeds, and malware hashes. But I think uh especially last few years

we've noticed that many things like social media are being overlooked and lots of things are happening on Meta platforms, on TikTok, X, LinkedIn, Reddit, Telegram, public messaging channels. And additionally, what's happening there is that you have there paid ads that are being used to spread certain malware. You have there fishing attempts. You have organic posts. You have commenters that are um running social engineering, live stream, short

form, AI-generated video, and many of the other things. And uh uh those things are being used to run influence operations. So, this term IO or influence operation is is being used quite broadly and quite liberally. So, I would maybe define what we mean usually by the influence operations. So, in our view, it's a deliberate organized effort to drive an individual or a group of individuals such as

like a nation or a company uh to take an action or refrain from taking one by weaponizing information or infrastructure that distributes it. And you have here two parts. You have weaponizing information and infrastructure. So, think of it as a bullet and a gun. So, information is a bullet, which you can use to achieve a certain goals by firing it. And then you have an infrastructure. You

have accounts, uh you have pages, you have uh forums, you have ad channels that you can use to distribute it. And you cannot protect from one without watching the other. when it's um many of you of you would say it's problem that existed for very long time. Um but I have a few examples from the last year. We had uh cases of the bot network that uh

was um reposting the fabricated content 86 times per second for a few days. Uh we had the state-on-state information operations that have been quick stealing the identities of the real soldiers and targeting the people on the front line so that they in an attempt to make them abandon their positions. So, what they will do, they will take like random identities of the people from the social media,

generate the fabricated persona, and then they would target their second connections, like friends of friends, with those con with this content in an attempt to achieve a certain goal. In this particular case, abandon their position. Or we had independent election chatbots that were distributed as a something that can help you to understand for whom to vote. But in reality, those independent chatbots were really designed to make

you vote for a certain organization. Most of those had been done state-to-state. So, states been running influence operations against the states. we are not new to the concept that states are running information But I have a question like whose organization is having active monitoring of the social and ad layers as a security signal. Can you just raise your hands? One, two. Do you know the name of

the person who deals with that? How about you? No. Okay. Okay. So, wow. Yeah. Uh-huh. And you know the person who does this. That's you. >> [laughter] >> Mhm. Okay. So, yeah. I mean, that's uh So, we have two people who with whom with whose organization that's happening, and one person who knows the the person who deals with it. So, as you can see, the penetration of

this of the monitoring of this channel is not yet very widespread. I would say it's around 1 and 1/2% looking at the size of the audience. But I think what's important to understand is that things changed, and I you probably know why all things changed in the last 2 years. It's everyone would tell you that AI AI AI AI and in this particular case it's also AI

but many people would think that the problem is that AI made information operations and disinformation cheap. Which is true. The problem is that I never seen a Russian GRU care about the cost and unit economics of their information operations. Not really like that they need to do show a profitable book. Um the problem is that we like historically disinformation campaigns those been things that the state would

run against the state and you would have a very high entry bar. You would need to be a special unit with lots of people with a national experts who can translate the content create it. Right now that's no longer the case because the unit economic changed and now everyone runs information operations or at least everyone can. So state actors are still still doing that. We have cases

of state actors influencing elections in I mean many countries like say can starting from Moldova. We have elections in Armenia that are heavily influenced right now and multiple other ones. But also the cyber criminal groups started running information operations. They adopted the same playbook and I will show you exactly the case. And they are repurposing information operations for the other reasons. But then also a random guy

in Philippines with the laptop can run information operation against open AI and I will also show you the case. Um with like the budget of probably 55 bucks or something like that. So the lines are gone and the entry bar is very low. So there is lots of ROI right now because not everyone is protected and as a result there is lots of people trying to get

there. And I brought you a few cases to show you how it actually evolved. So the first case is a typical information operations that is happening was happening in the political context in the context of the elections. So, last year we've been monitoring check check elections and weeks before the elections we've seen there been multiple campaigns, but weeks before the elections we've seen one that is interesting

in particular. It was using deep fakes of the famous journalist and a political candidate that were generated and I'm sorry for the quality here something went off. But, the deep fakes were generated that the political candidate is being arrested with the handcuffs and being escorted by the police. Uh this those deep fakes and the Facebook page and the or like number of Facebook pages that were bought

that were previously running different marketplaces selling candies and stuff. They were bought and they were used to run those political ads. And the idea was that you see the ad, the ad transfers you to the replica of the most common of the biggest newspaper where you read an article how a certain political candidate has been arrested for a miss misused of something and it was 210 ads

run over the course of the 48 hours that in a crucial time in the lead to the Luckily this campaign was contained and like the idea was that you had the bait. The bait was this AI generated image which was distributed through the meta ads later leading you to the doppelganger like impersonation websites which later on would have a story. the thing is that when the elections

were over a few days after we were like something is off because exactly the same yes like so let's let's just like follow the chain. You had Facebook pages that were selling candies and like marketplaces for the bicycles and whatever, which were bought and last week they are running a political campaign showing the candidates in the handcuffs. The elections are over and in 3 days the pages

change and for 2 months they start to run crypto scam related ad targeting the clients of the major banks. So, it's exactly the same infrastructure, exactly the same pages. On the left you can see the ads that been running for to against the political candidate here in the handcuffs. [laughter] On the right what you are seeing or at least what you supposed to see is a lot

of the ads which show the deep fake images and the videos of the famous people. Usually either news anchors or um the TV stars, TV personalities that have been that we have the deep fake ads that say that they are sharing how they are doing the investment. And those like basically I've invested 500 bucks and in this new trendy thing from a big bank like Santander. And

that's how I'm making money on it. And that the then the logic will be exactly the same. So, you follow the um ad. The ad gets you to the replica of reputable news website. So, for example, that's how the websites would look like and you would have here like it was targeting Czech Republic and um UK. So, in the first one you would have um the same

basically it was the same operator, but this time it was bigger. It was 770 meta ads in 30 days. It's basically two ads per day in parallel running to the Czech Republic and UK geo segmented. So, the idea was you have like the ads like this one that lead you to the websites clones that of the websites like BBC and many of the other that show you

the articles how the TV stars present their hidden income schemes and how they say that the government is trying to shut them down because they found the way to make the money. And then later on in this particular case, those articles would eventually mention name of the app that you can install. Then you supposed to integrate your bank account and you never I mean, you leave your

credentials and that your bank account get compromised or eventually you also can do a deposit because with the bank account credentials they it didn't work for them that well. So you can do a deposit and then that you would your money would be in an instant and they would be targeting specifically customers of a certain big banks like Santander, HSBC in the UK and many others. So

they will be going to the forums with those customers posting underneath the those this ads targeting the their financial and so on. And the basically the idea is that they went as far as to manufacture the credence credibility. So they basically manufactured the whole set of pages like news pages new lots of news articles and eventually they also fabricated the endorsements so there were lots of endorsement

from the Sir Sir Keir Starmer, from Radcliffe, from and there was as well the whole forums of the bot comments on the reputable for and even they went as far as to build a trust pilot the trust pilot profiles with the comments. So as you can see it was quite extensive campaign that started in the ads eventually migrated users from the social media to the websites and

and then eventually migrated to the apps. The problem is that while this campaign was starting, um none of the websites or none of the domains and none of the apps has been present and marked as a compromise compromised infrastructure. So, the thing is that we already knew that something is off by a number of fingerprints that on like each finger fingerprint on its own is not that

much of a illustrative, but if you take all of them together, you would see that something is off. So, the fingerprints that we detected is that all three uh all two like all of the pages, all of the campaigns, they use the same basically code snippets, and the code snippets contain the comments in Russian. So, exactly the same types of comments. Um then secondly, that they were

generating uh they were geo-clocking their uh websites so that the trust and safety community and those who would be reviewing the content, they cannot get and uh check what's behind. So, only if you're entering from the Czech Republic APIs, you would see the Czech Republic uh copy of the Seznam Zprávy, basically like the biggest news outlet there. If you're entering from the UK, you would see the

BBC. If you're entering from anywhere else, you wouldn't see anything. And then you would also have that the pages, they will have a number of admins across different geographies. That's made because they choose the geographies in which the data protection is the weakest. So, that basically if you go for the moderation later on or like complain, the your complaints will go through United States or Indonesia. In

both of the cases, they will try to check the content, and uh they wouldn't see anything, and as well as the data protection wouldn't be that strict. So, the same campaign logic, the same idea was um basically coined by the Russian disinformation machine in around 2021 against the elections, but you can see now that the certain criminal groups are running and running those campaigns for a fraud

purposes against the customers of the bank. And the problem is that the customers of the bank who've been scammed by that, they eventually have their grievances with the bank and they ask and they around 13% of those customers eventually leave that bank for the other one. So, I think the question that I will have for you is like if you're if you've suddenly have your organization targeted

by 770 fake ads of your CEO, do you know who in your organization would be taking care of it? If you do, can you raise your hand? Okay, that's more people. So, who would be this person? Like, what would be the job title of this person from those who raised their hands? So, to which team? >> [clears throat] >> Ah, okay. So, you have a like internal

network team that would take care of it. Anyone else? I think you also raised their hand, right? Mhm. Ah, so you have a special channel to report stuff like that. Okay, I see. So, thanks. I mean, that that shows that again for majority they are not yet aware that there are that's great that many organization do have a team or like a chat or an email, but

not everyone yet. And in those previous two cases we've been dealing with the information operations that are run by like state grade organizations that can run again information operations against the elections or for a fraud or scam purposes. But the third case and the last case that I wanted to show you is just a guy with the laptop in the Philippines. Or like it's not really one

guy, it's a bit of a small small and medium organization in the Philippines and they launched an interesting attack last year. So we had a release of the open AI Sora model. And [snorts] what they did, they basically created a replica of the Sora Um which they later on as well as they bought a number of Facebook pages to run the ads and they were running ads

from the Sora website to the employees of major companies. Uh giving them the ability to and like luring them to the websites and to the domains eventually asking them to generate a certain like generate any video they would like to and then when they do a download from this website they will download the infostealer that will be installed on their laptop and then will eventually help to

get access to the data. So basically the idea is that you have social media channels and they have groups of people they would be targeting the communities of the people or like certain industries especially the financial sector of a certain companies and on behalf of open AI invite them to try the new open AI Sora and then they would lead them to the website through which eventually

they will install an infostealer. This campaign luckily was detected at the first ads it made only 53 ads at the point of detection it was shut down immediately. Luckily usually the biggest when you have campaigns like that the platforms like Meta and the others they don't care about like doing the fast response. Luckily probably the advertisement check of the open AI is big enough for them to

care. So when the like we contacted the open AI and the open AI contacted them within less than an hour everything was down and never reappeared. Um not all not always it works at that easy but in this case it was rather a success story. But the thing is that um this one, this campaign was run by Mud Ball Corporations. Basically, like a Vietnamese company that Eventually,

the original account and the original person was in the Philippines. And, this campaign was targeting users in a number of countries. So, you would have users in the US, Germany, Taiwan, China, and Um, and the idea would be to actually install the the info stealers. So, I think the problem with those campaigns is that there are a number of things that make them hard to catch. In

majority of the cases, you wouldn't have the keywords to match because the names of the banks that they are targeting and the institutions that they are targeting, they would oftentimes not be mentioned. The OpenAI Sora is a bit of a example is a bit of an exception. You they would mention that it's an OpenAI Um, but again, if you're an OpenAI, it's kind of difficult to check

everything. Majority of the claims would not be the fact-checkable because it's like they contain twisted or manipulated information. They rely 100% on the AI-generated content. Um, also, majority of those campaigns nowadays, they do run short-form video, not the text. So, the text is easier to work with, but majority would be using the short-form video like shorts, TikToks, and uh, similar um, things. Uh, and the problem the

main problem is this one is the central is that you wouldn't understand that this is a threat by looking at the single case, a ad, a single, um, channel, or an account because the reality is that you need to see a pattern. Like, it's the fact that 60 pages are running the same ads using the same generated content that leads you to the conclusion that this is

a campaign, not a single ad because you cannot fight back every single ad or every single page that is trying to run a fraud or impersonate your company. Another challenge is that many of those is multi-platform, so they are happening on the social media channels, but also on the ads, and then eventually they get to the domains and the websites. Um, and often times they look like

something else, like something completely benign. And the biggest challenge why they're happening so much because the infrastructure is getting reused. The problem is that for example, in the Czech cases, since the response of the platforms to the um, during the elections was rather slow, lots of the infrastructure wasn't uh, solved, uh, wasn't resolved after the, uh, wasn't taken down after the elections, so they were able to

reuse it and reap the profits again. And all of those campaign they follow the same playbook. So, you had basically three campaigns, uh, three actors, three objectives. The kill chain was identical, so it all started with identity fabrication. So, basically what is happening is that someone is either buying or creating new identities. And then they age those personas. So, it's not like they bought an account, usually

they wouldn't buy an account or create an fresh account and run it right away. Usually they will age the persona slowly changing the name, creating the credibility, adding connection. Then eventually they would fabricate the uh, to create again the credibility. And then basically they would do narrative seeding. It's basically through the paid ads or coordinated posting, they would attempt to create an organic growth. So, then the

next thing would be that was the infrastructure, so they will create a different um, websites, they will create domains, uh, redirect chains, geo-clocking, phishing kits, and so on. Um, and start targeting the audience, and only that we are getting, then we are getting to the full delivery and exploitation and impact. And the core is that this whole part here is being used primarily to get an organic

uh, discussion starting and then organic amplification so that basically the whole controlled infrastructure is meant to make this viral. And when it's viral, you cannot fight it back anymore because it will it you can take down the content which and the profiles and the platforms which are controlled and you can show that they are synthetic or the bots, but you cannot take down the organic content. And

even it becomes the organic, it's very difficult from the infrastructure standpoint what you can do to take to take it down. And I think when it comes to basically when it comes to the detection of this, the idea is that you the cases where we've seen it successfully being taken off is when the people are taking narrative intelligence or like intelligence teams of the data from the

media and social media the same way they would treat any other form of the intelligence. So, they would integrate streams from the brand and executive impersonation, coordinated posting, account creation. Then they would triage and assign where as where possible. is that Mitra wouldn't always have the tags for the for the things that we um are detecting. It's changing a bit. We are working with them to be

able to assign the TTPs, but you also have this arm. It's heavily used in the government sector. It's a bit difficult to use in in the corporate one, but you can still rely on it. As well as you had in the past Mitra pre-attack. I think it was deprecated, unfortunately. So, right now but to the extent possible, you should triage and score. And then enrich and attribute.

The problem is that lots of those content, they would be you would already have a signatures of the domains and the certificates and the IPs that are being used in the other campaigns against your organization. So, you can triage and understand if this particular number of ad pages, they lead people to to the to the domains which you already know that are being used in the fishing

infrastructure. And then the idea is to contain and disrupt. So basically, if you have active pages running ads or fishing forms, exposure windows, the idea is to have playbooks and the response the response playbooks that allow you to first of all collect the data in automatically and file the trust and safety requests. And finally one final one is to document and share. There are quite a lot

of the are collecting and sharing the information like that. If you If you for example would for in the cases of the banks that we've seen it successfully being done, you have you have national authorities with through which the banks can share information about the campaigns that are targeting them because most likely what is targeting one bank in one or in in the same geography is targeting

their peers as well. Um and the idea is that this thing should have a designated owner when I was asking who owns in the two cases I was asking if you know the owner, the problem is that this gap it's very you have not that much time usually when you have weeks in the cases. Sorry. In here, this thing takes weeks. This thing takes up to a

week. And this one is happening within hours. So the problem is that if you don't have an owner and you haven't detected it somewhere in here, in here if you don't have a real clear playbooks it you're that's I mean basically you're cooked. So that's a very difficult one place to start fighting back. So the idea is that you need to have an owner who would ingest

the signal somewhere in in this stage and in this stage instead of just relying to on the response, but once it's happening and you cannot always detect things at the pre-attack stage. In this stage, you should have the playbooks to respond and the connections to the other teams. Um so, basically, threat narrative as a The idea is that to treat the narrative intelligence as it's a combined

term for IO related attacks as a feed. Um wire that into the existing playbooks and have a clear owner who would be responsible for both triaging using it and building the playbooks and so on. And it is that some of the organizations, they already have some parts covered. For example, most organizations, they will have some form of brand monitoring that is already collecting the data from the

media and social media through the keywords. And almost organizations here, they would have a functions of the security functions in the fraud, which would already have the threat feeds and identity verification. Usually, the pre-attack behavioral signal from information operations comes just like as an addition, as an enrichment for those, which would cover things that fall behind and between. So, usually, that's a coordinated inauthentic behavior, synthetic persona,

cross-platform narrative seeding, um executive impersonation monitoring, and the spray attack signal scoring. So, the idea is that this feed come is really falling between those two, and the as the sooner you start integrating it, the bigger is the chance that you would be able to fight back when the campaign comes. And I was We have one of the advisors from Gartner, and they recently shared the paper

which stated that the adoption of the narrative intelligence among the um enterprise organization is currently sitting at around 5%. So, I think we are more or less representative of this of this research. Maybe like a few percent off. Um but the problem is that this is such a such a growing threat and such a growing market on the attacker's side that this adoption by 2029 should reach

around 50% of the organizations and eventually reach to around 75%, 80% by the end of the decade. So, it's changing fast and if there are a few things that I wanted you to take from this speech, it's actually that first of all, what is historically has been a domain of the national states running attacks one against the other. There is a market there and on this market

people are finding new revenue streams which are usually used for frauds, information stealing, social engineering and other means. The bar to enter is rather low, so you can have a small budget of around few hundred bucks and if one person organizations running attacks, but luckily you can detect that at the early stages if you have the relevant feeds, but that should be part of the security response

and if you can decide within your organizations who owns it and build the playbooks actually seen the cases of successfully fighting it back. And the more organization have the protection, the bigger is the chance destroy the infrastructure before it before it takes before it uses and used to attack the others as well. So, with this I think that's the part of the presentation I wanted to show

you