Russia hack, China fake
TC Lee | Chairman of CDAT, Founder of the Ganghu Civil Defense Team
I met with a Ukrainian independent journalist recently, and we talked about the information warfare reality they’ve observed on the front lines.
He used one line that nailed it precisely: Russia hack, China fake.
Russia’s hacking capability is genuinely strong.
Google’s Mandiant published a full report in 2024 on Sandworm, the hacking unit under Russia’s military intelligence agency GRU (Note 1), documenting in detail how they breached Ukraine’s power grid, disabled water utilities, and deployed destructive malware.
Breaking into systems, crippling infrastructure, stealing intelligence — they’ve been doing this for a long time, and it’s become routine since the war began.
But when it comes to mass-producing deepfake content with AI and manipulating public opinion on social media, China has invested far more resources and built up far more experience than Russia.
Microsoft’s 2024 Digital Defense Report (Note 2) compared Chinese and Russian tactics within the same document: both countries’ AI image and audio/video capabilities were rated “high,” but their preferences differ — China leans heavily on AI-generated images (like the AI cartoons of the “Taizi Flood” campaign), while Russia leans toward AI voice cloning (such as fake documentaries narrated by a cloned Elon Musk voice).
The Jamestown Foundation’s analysis is even more direct — the report is literally titled “Deepfakes with Chinese Characteristics” (Note 3), documenting how China is preparing to weaponize deepfake technology for fabricated news anchors and election interference.
The two aren’t entirely separate, of course.
China also runs operations like Volt Typhoon, pre-positioned inside US infrastructure, and Russia has its own disinformation tradition dating back to the Soviet era.
But the relative specialization is unmistakable: Russia is strong at breaking into systems, China is strong at producing and manipulating content.
China’s investment in AI isn’t limited to external cognitive warfare.
They’ve poured enormous resources into using AI for internal surveillance and governance.
Facial recognition, public-opinion monitoring, social control — this whole system has been running and evolving for years.
A late-2025 report from the Australian Strategic Policy Institute (ASPI) (Note 4) documented how China uses large language models for automated censorship, public security stability maintenance, smart courts, and smart prisons.
Carnegie’s research, tracking this since 2019 (Note 5), found that even back then, Huawei alone had already exported AI surveillance technology to at least 50 countries.
By 2026 (Note 6), AI censorship tools on platforms like WeChat and Douyin can already scan massive volumes of text, images, and video in real time.
When it comes to “how to use AI to control the information environment,” China has the most mature real-world experience in the world.
Ukraine is facing the same thing.
Germany’s Mercator Institute for China Studies (MERICS) published an analysis this year by Ukrainian think-tank researcher Yurii Poita (Note 7), who personally crawled 1,800 posts from high-visibility Weibo accounts and identified four recurring pro-Russia, anti-Ukraine narrative patterns.
What they’re up against isn’t just Russian missiles and hackers, but increasingly sophisticated disinformation and deepfake content built on a foundation of Chinese technology.
Taiwan has long stood on the front line of Chinese information operations, while Ukraine fights Russian hackers and disinformation on the battlefield every single day.
These two sets of experience are highly complementary.
Taiwan understands how China manipulates content; Ukraine understands how Russia wages systems warfare.
We should be exchanging more actively with Ukraine — not just sharing notes, but learning together.
Because what really deserves our attention is where this is heading next.
Technical exchange between China and Russia is already happening.
A 2025 report from the European External Action Service (EEAS) (Note 8) tracked foreign information manipulation activity spanning at least 25 platforms and 38,000 accounts, with Russia as the primary actor and China second.
A 2025 study from the Center for European Policy Analysis (CEPA) (Note 9) used the word “convergence” directly to describe the direction of Sino-Russian cooperation on information manipulation.
Concrete examples are already surfacing: in early 2025, Putin publicly directed the Russian government and Sberbank to cooperate with China on AI development (Note 10), and even earlier, China’s Dahua Technology had already partnered with Russia’s NtechLab to co-develop facial recognition cameras (Note 11).
For now, the cooperation still looks more like “strategic parallelism” and “narrative convergence” — Microsoft’s report notes there’s no evidence yet that the two countries are directly sharing resources or using the same criminal infrastructure (Note 2).
But the trend is clear.
If China hands its AI content-generation and opinion-manipulation technology further over to Russia — Russia already has top-tier hacking capability, able to break into almost any system — pairing that with China-level AI manipulation technology would create a combination that’s extremely difficult to counter.
One side can get inside your systems. The other can rewrite what you see.
This is exactly why Taiwan and Ukraine need more substantive exchange.
We face different threats, but the sources of those threats are starting to converge.
Waiting until the convergence is complete before starting to prepare will already be too late.
(Note 1): Mandiant, “APT44: Unearthing Sandworm,” 2024. https://cloud.google.com/blog/topics/threat-intelligence/apt44-unearthing-sandworm
(Note 2): Microsoft, “Digital Defense Report 2024,” 2024. https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2024
(Note 3): Jamestown Foundation, “Deepfakes with Chinese Characteristics,” China Brief Vol. 24 Issue 7, 2024. https://jamestown.org/deepfakes-with-chinese-characteristics-prc-influence-operations-in-2024/
(Note 4): ASPI, “The Party’s AI: How China’s New AI Systems Are Reshaping Human Rights,” 2025. https://www.aspi.org.au/report/the-partys-ai-how-chinas-new-ai-systems-are-reshaping-human-rights/
(Note 5): Carnegie Endowment, “The Global Expansion of AI Surveillance,” 2019. https://carnegieendowment.org/research/2019/09/the-global-expansion-of-ai-surveillance
(Note 6): Carnegie Endowment, “China’s AI-Empowered Censorship: Strengths and Limitations,” 2026. https://carnegieendowment.org/research/2026/03/chinas-ai-empowered-censorship-strengths-and-limitations
(Note 7): Yurii Poita (MERICS), “Russian propaganda abounds in Chinese social media debate on Ukraine,” 2026. https://merics.org/en/comment/russian-propaganda-abounds-chinese-social-media-debate-ukraine
(Note 8): EEAS, “3rd Report on Foreign Information Manipulation and Interference Threats,” 2025. https://www.eeas.europa.eu/sites/default/files/documents/2025/EEAS-3nd-ThreatReport-March-2025-05-Digital-HD.pdf
(Note 9): CEPA, “Sino-Russian Convergence in Foreign Information Manipulation and Interference,” 2025. https://cepa.org/comprehensive-reports/sino-russian-convergence-in-foreign-information-manipulation-and-interference/
(Note 10): Reuters, “Putin orders government to work with Sberbank on AI development with China,” 2025. https://www.reuters.com/technology/artificial-intelligence/putin-orders-russian-govt-work-with-sberbank-ai-development-2025-01-17/
(Note 11): ASPI / public records, Dahua Technology’s collaboration with Russia’s NtechLab on wearable facial recognition devices, 2019.