Giada, M., Fabio, G., Anwesha, C., Massimo, T., & Samuel, O. (2026). Exploring the Zombie Internet: Anatomy of Three Deceptive Information Operations on Facebook. MEDIASCAPES JOURNAL.

View paper

Summary

This paper introduces Deceptive Information Operations (DIOs) as an analytical framework designed to move beyond false-news taxonomies and capture a wider spectrum of manipulative activity on social media. Rather than treating false content as the defining feature of manipulation, the authors argue that DIOs are constituted by the convergence of three dimensions: deceptive intent in content and identity, strategic exploitation of platform affordances, and multi-account coordination. Through three empirical cases on Facebook — a pro-Putin propaganda network, a coordinated gambling promotion campaign, and a cluster of poorly moderated groups distributing adult content and fraudulent links — they show that structurally distinct operations pursuing different harms share a common operational logic. The paper operationalises the notion of a “Zombie Internet,” where engagement-driven design and inconsistent moderation blur the line between human and automated, authentic and manipulated activity, and argues that Meta’s enforcement categories (CIB and CSH) are drawn too narrowly to address these structural conditions.

Key Contributions

  • Proposes the DIOs framework, synthesising deception theory, strategic information operations, and coordinated inauthentic behaviour into a single analytical lens.
  • Demonstrates empirically that operations differing in actor, content, and intent nonetheless share a common structural logic, making motivational distinctions analytically secondary.
  • Identifies critical gaps in platform governance frameworks that focus on content inauthenticity rather than structural enabling conditions, with direct evidence of enforcement failure.
  • Offers a reusable codebook and an automated, cyclical detection workflow using the Meta Content Library for scalable monitoring of coordinated deceptive activity.
  • Empirically operationalises Koebler’s “Zombie Internet” concept as a systemic ecosystem condition emerging from engagement-oriented design.

Methods

  • Purposive case selection of three cases from 17 networks detected by the vera.ai monitoring workflow, chosen for typological, actor, and coordination-mechanism diversity representing epistemic, economic, and social-normative harm.
  • An automated, adaptive detection workflow (VeraAI Alert System) using CooRTweet to detect synchronous sharing, seeded from 1,225 fact-checker-flagged accounts and a corpus of 36,091 Meta-flagged pages (2017–2022).
  • Data collection via the Meta Content Library (among the first large-scale uses), analysing account-level metadata and the 500 most-viewed posts per network (Oct 2023–Aug 2024).
  • Inductive category development informed by constructivist grounded theory across three theoretically motivated dimensions (identity management, behavioural coordination, content manipulation), with a primary coder per case and 30% cross-coding by the lead author.

Findings

  • Pro-Putin network: 27 public groups with replicated naming conventions and synchronised name changes preceding geopolitical events; an anti-Zelenskyy meme was shared across six groups within a six-minute window, accumulating over 1.1 million views. AI-generated heroic imagery of Putin was blended with benign urban-development content to obscure intent.
  • Gambling network: 260 groups (30,000 to ~600,000 members) using automation and generative AI, some producing up to 10,000 posts per month; anomalous metrics (e.g. 169.1K views, 44.1K comments, 7 reactions, 0 shares) indicated artificial comment inflation, alongside brandjacking of names like Orion Stars and Juwa. 368 of the 500 top posts were removed by analysis time.
  • Unmoderated groups: 222 groups in two communities exploiting weak moderation, with repeated renaming (one group changed names 13 times) and adult content disguised via activity-status links, empty Musician/Band pages, and unrelated BMW-history blurbs with tinyurl links to evade CIB detection; a Coca-Cola alcohol hoax reached 3.5 million views and 37,300 shares.
  • Cross-case synthesis: all three conceal intent behind benign content, rely on coordinated sharing and synthetic/AI-generated material, and exploit engagement-driven ranking, differing mainly in user engagement (genuine amplification, near-total synthetic activity, and inadvertent amplification).
  • Facebook’s enforcement framework failed across all cases to distinguish automated from genuine participation; reports to Meta in 2023 and 2024 received acknowledgement but limited follow-up.

Connections

This paper extends the coordinated-sharing detection tradition developed by the same research group, connecting directly to Giglietto2020-9d8acdd7, Giglietto2022-0e951ac5, and Giglietto2023-fa71a001 on coordinated link sharing and inauthentic behaviour, and to Giglietto2026-9b6a992d and Marino2023-9137f448. Its grounded-theory approach to categorising information operations builds on Starbird2025-jj, while its critique of engagement-driven governance and CIB categories relates to broader platform-manipulation work such as Graham2025-gp, Luceri2025-tr, and Pierri2025-hm.

Podcast

A research-radio episode discusses this paper: Listen