Beyond the Narrative: Mapping the Hidden Infrastructure of Information Warfare

No ratings

Presented at BSides Tallinn 2026 by

Information warfare is usually examined through its visible outputs, including fabricated stories, coordinated accounts, bot networks and manipulated audiences, but every campaign also depends on a quieter technical layer that receives far less scrutiny. Developers, data systems, monitoring platforms and institutional relationships make influence operations scalable, measurable and sustainable over time. This talk presents an investigation into that hidden layer. Starting with a small collection of fragmented indicators, we followed traces across professional profiles, source code repositories, conference appearances, corporate records, procurement data and employment history. Although each signal appeared ordinary in isolation, their combined pattern revealed a previously undocumented relationship between software engineering, regional monitoring infrastructure and a state-linked influence ecosystem. Rather than focusing only on a single attribution, the session follows real life case study and shows the investigative flow by moving from weak signals to defensible hypotheses, correlating technical capabilities with operational requirements, separating confirmed relationships from circumstantial inference and communicating conclusions without overstating certainty. It also examines the complications that frequently appear in this type of research, including public-facing professional identities, opaque subcontracting arrangements, misleading corporate footprints and records that do not align cleanly across time. The broader lesson is that countering information warfare requires more than identifying false narratives after they begin to spread. Defenders must also understand the infrastructure, labour, organisations and supply chains that support these operations. When propaganda networks are treated as security systems with developers, dependencies, dashboards, data flows and operational weaknesses, investigators can apply many of the same techniques already used in threat intelligence and incident response.