Threat Actors in the Information Environment: How They Operate

Harmful narratives rarely arrive by accident. When a false claim spreads about a brand, an election or a public institution, someone usually put it there. Analysts call that someone a threat actor. The term comes from cyber security, but it now covers a wider threat landscape: actors who attack perceptions rather than networks.

What Is a Threat Actor in the Information Environment?

In cyber security the term is deliberately wide. NIST counts any individual or group posing a threat, from ransomware crews to advanced persistent threat groups.

This article uses a narrower sense: a threat actor is a person, group or organisation that deliberately uses content to harm a target. Their weapon is content: false claims, distorted framings and manufactured outrage aimed at trust, reputation and decision-making. The Council of Europe's Information Disorder report separates any campaign into three elements: the agents who create and spread it, the messages themselves, and the interpreters who receive them.

The cyber and narrative worlds still overlap. The US Justice Department charged twelve GRU officers over the 2016 election hacks. The same indictment covers their release of the stolen material through the Guccifer 2.0 persona.

Not everyone spreading a harmful narrative is a threat actor. Intent is what separates disinformation from misinformation:

• Deliberate actors create or push content with intent to harm.

• Coordinated networks amplify content in an organised way, often for pay.

•     Unwitting amplifiers share content in good faith. They are an audience, not an adversary.

Insider threats count too. CISA, the US cyber security agency, includes insiders who act unwittingly, such as an employee who leaks material.

Types of Threat Actors Behind Harmful Narratives

Analysts describe threat actors by who sponsors them, what motivates them and how they reach audiences. These dimensions overlap. A state can hire a commercial firm, and that firm can work through a community of real supporters. This section groups actors as state-backed, commercial or ideological, then explains proxies separately. A proxy describes a relationship, not a kind of actor.

Threat actors

Threat actor types at a glance

Attribute State-backed actors Influence-for-hire operators Ideologically motivated groups
What drives them Foreign-policy goals Payment from clients Belief in the cause
Resources Standing budgets, dedicated staff, long time horizons Commercial services sold to any paying client Low cost: supporters produce and share content unpaid
Typical methods Influence operations, often alongside cyber operations such as hack-and-leak Fake engagement, troll farms, reputation attacks Volunteer content creation and sharing
Typical targets Elections, alliances, public trust Whoever the client names Opponents of the cause
Evidence in the article Oxford 2020 inventory: government agencies involved in 62 of 81 countries Oxford 2020 inventory: 48 instances in 2020; 65+ firms since 2018 Sincere belief alone does not make a group a threat actor
Proxies (a relationship, not a type). Any of the three groups can work through proxies: media outlets, think tanks and affiliated organisations that repeat aligned narratives. This lets the sponsor stay out of view.

These dimensions overlap. A state can hire a commercial firm, and that firm can work through a community of real supporters.

Nation-State and State-Aligned Actors

Nation-state actors run influence operations as an extension of foreign policy. Oxford's Industrialized Disinformation report, a 2020 inventory published in 2021, found organised social media manipulation in 81 countries. Government agencies were involved in 62 of them.

Repsense mapped Russia's adaptive propaganda system across 3.13 million media items for the NATO Strategic Communications Centre of Excellence. The study, Crisis, Control, Crusade, identified the first 18 hours after an unexpected event as the system's weakest point.

Some state services also recruit people online for paid offline tasks, as our article on Russia's disposable agents shows. That recruitment is a separate operation from narrative manipulation.

Influence-for-Hire and Financially Motivated Operators

Influence-for-hire operators sell manipulation as a service. The same Oxford inventory recorded 48 instances of private companies deploying computational propaganda on behalf of a political actor during 2020. It also counted more than 65 firms offering such services since 2018. Money, not ideology, motivates these operators. They sell fake engagement, troll farms and reputation attacks to anyone who pays.

Ideologically Motivated Groups

Extremist movements, conspiracy communities and single-issue activists push narratives because they believe them. Belief alone does not make a group a threat actor. Sincere activists, and people repeating mistaken claims, fall outside the definition used here. Costs stay low, because supporters produce and share content without payment.

Proxy Organisations and Affiliated Networks

Proxies let a sponsor stay out of view. Any of the three groups above can work through one. States and their clients often use media outlets, think tanks and affiliated organisations that repeat aligned narratives on their behalf.

Lithuania shows the pattern. Its State Security Department reports that Russian propaganda now arrives disguised as domestic voices. A study for the Radio and Television Commission of Lithuania found 54.6% of over 19,000 Telegram posts were pro-Russian.

What Threat Actors Want to Achieve

Motivation shapes everything else in a profile. Common objectives include:

• Undermining trust in institutions, media, science or a brand.

• Influencing perceptions or decisions: a vote, a purchase, a policy choice.

• Polarising audiences so that compromise becomes socially costly.

• Distracting from inconvenient stories by flooding the space with alternatives.

• Creating artificial consensus, where fake accounts simulate widespread agreement.

A single campaign can serve several objectives at once.

How Threat Actors Operate in the Information Environment

Threat actors work through recognisable tactics, techniques and procedures (TTPs). The DISARM framework catalogues these the way MITRE ATT&CK catalogues cyber attack techniques.

Seeding and Reframing Narratives

Actors often build narratives around existing events or grievances, then reframe them. Seeding starts in fringe forums and small channels, where actors test content before wider release.

Coordinated and Proxy Amplification

Amplification manufactures the appearance of consensus. Sock-puppet accounts post in synchronised bursts, and proxy outlets republish each other to simulate independent confirmation. Ben Nimmo's Breakout Scale measures how far that amplification travels. Its categories run from a single community on one platform to mainstream media and policy debate.

Impersonation, Content Laundering and Synthetic Media

Threat actors exploit trust in familiar sources. They spoof news brands, clone official accounts and forge documents. Content laundering passes material through intermediary outlets until its origin disappears.

In 2025 the EEAS found AI-related techniques in 27% of the FIMI incidents it analysed. FIMI is the EU's term for foreign information manipulation and interference. Its fourth threat report documents synthetic audio, imagery and multilingual production.

Adapting Tactics Across Platforms and Audiences

Sophisticated threat actors tailor one narrative to each platform. Blogs get long-form "analysis", short video gets emotive clips, closed groups get memes. When moderation tightens, activity migrates. Tracking this behaviour differs from tracing origins, which we cover in our article on source attribution techniques.

How Analysts Build a Threat Actor Profile

Analysts build a threat actor profile from behaviour observed over time and across platforms. At Repsense we build profiles across four dimensions.

Four dimensions of a threat actor profile

Profile

Four dimensions of a threat actor profile

What analysts describe when they profile behaviour rather than identity.

What outcome does the activity serve?

Objectives and motivations

Inferred from targeting choices, timing and message content.

How much can the actor sustain?

Capabilities and resources

Volume, consistency and production quality reveal resourcing. Multilingual output, paid promotion and synthetic media raise the estimate.

What does the actor do repeatedly?

Recurring tactics and behavioural patterns

Posting rhythms, narrative templates and amplification patterns form a behavioural fingerprint, mapped against frameworks like DISARM.

Who is being addressed, and where?

Targets, audiences and platform preferences

Some actors address regulators and journalists, others consumers. Language and platform choice narrow the picture further.

A profile describes a behavioural cluster. Attribution to a real-world identity is a separate discipline.

Objectives and Motivations

What outcome does the activity serve, and who benefits? Analysts infer objectives from targeting choices, timing and message content.

Capabilities and Resources

Volume, consistency and production quality reveal resourcing. Multilingual output, paid promotion and synthetic media all raise the capability estimate.

Recurring Tactics and Behavioural Patterns

TTPs persist even when accounts change. Posting rhythms, narrative templates and amplification patterns form a behavioural fingerprint, which analysts map against frameworks like DISARM.

Targets, Audiences and Platform Preferences

Who does the actor talk to, where, and in what language? Attribution to a real-world identity is a separate discipline, and a profile does not attempt it.

What a Threat Actor Assessment Can and Cannot Tell You

Honest assessments state their limits.

Observed evidence vs inference. Analysts observe posts, timing and network structure. Intent and sponsorship are inferences, and reports should label them as such.

Actor profile vs confirmed identity. A profile describes a behavioural cluster. It does not name a person, agency or company.

Confidence levels. Structured intelligence grades confidence as low, moderate or high, according to the quality and independence of the evidence.

Incomplete or obscured evidence. Actors delete accounts, launder content and plant false flags. A gap in the record can mean concealment or simply no activity. A profile records the gap rather than filling it.

Similar tactics do not prove attribution. TTPs are published, copied and sold, so they narrow the field without closing the case. Linking activity to one operation and naming who runs it are separate steps. NATO StratCom COE research on attributing influence operations treats the second as a distinct process with its own evidentiary standards.

Every output in our pipeline stays linked to its original content item and timestamp, which keeps evidence separate from inference.

How Repsense turns content into narrative data

Method

How Repsense turns content into narrative data

Six stages from raw content to validated, traceable narrative evidence.

01

Ingest

Collect text, audio, video, images and metadata from the relevant sources.

02

Extract

Run speech-to-text, OCR and visual analysis, preserving timestamps and source links.

03

Segment

Analyse content at sentence level, or another coherent unit of meaning.

04

Represent

Convert each unit into a semantic vector that captures meaning and context.

05

Operate

Discover emerging clusters, or compare content with predefined narrative statements.

06

Validate and analyse

Apply analyst review, then map actors, spread, coordination, impact and trajectory.

Every output stays traceable to the original content item and its timestamp.

Case Study: What Network Behaviour Can and Cannot Prove

This anonymised case from Repsense monitoring for a European renewable-energy developer shows where a threat actor profile's evidence ends. Read the full case study.

What we measured. Over 16 weeks in early 2026, we analysed 5,139 public Facebook posts and comments in two languages. Of these, 3,134 clustered into 76 topic threads. We set aside nine off-topic threads and the one central thread every active page joined, leaving 66 substantive threads. We counted two pages as linked when both posted at least once in the same thread.

Seven pages and groups, operating across a national border, carried most of the activity. Every pair shared at least one thread, and 24 on average. One call-to-action text was reshared word for word on four separate dates. Two health claims travelled through the network, presented as established science. The infrasound posts cite no peer-reviewed study. The cancer post misattributes a Norwegian blade-erosion report, then adds the cancer link itself. An infrasound post was the period's highest-reach item, at 2,765 users.

What the analysts assessed. The co-appearance rate and the verbatim resharing show a fully connected sharing network. The evidence offered for the two health claims does not support them. These measures show repeated, connected activity. They do not show central direction.

Likely objective (inferred). The activity appeared aimed at opposing the projects and the national consultation on wind acceleration zones. Funding and outside direction remain unknown.

Recurring TTPs. False health claims carried alongside genuine planning grievances, misattributed scientific citations, verbatim cross-posting, a shared hashtag system, and critical press coverage reframed as persecution.

Capabilities. Modest: identifiable residents and municipal activists working openly under their own names, plus one local politician’s page.

What the evidence does not show. Repeated claims, shared topics and cross-posting warrant investigation. On their own, they do not establish covert direction or malicious intent. The UK government's RESIST 3 guidance notes that robust debate can look aggressive without being insincere. Funding, outside direction and the claims' first point of entry remain unknown, since monitoring covered Facebook only.

Assessment. The pattern fits an organised civic opposition network working openly, not an anonymous influence-for-hire operation. The case shows careful profiling without confirmed threat-actor attribution. The profile describes behaviour, objective and capability, and names no one behind it.

How Brands and Governments Should Respond to Threat Actors

The response should match the actor, the objective, the scale and the confidence of the assessment.

What Brands Should Prioritise

Brands should prioritise early threat detection, baseline monitoring and clear escalation thresholds. Good practice includes pre-agreed playbooks, evidence preservation and restraint, since publicly engaging a small operation can hand it the reach it lacked.

What Governments and Public Institutions Should Prioritise

Governments should prioritise sustained monitoring capacity, transparent attribution standards, media literacy programmes and cooperation with platforms and researchers. Institutions should also secure their own systems, since stolen material often fuels state-aligned campaigns.

Understanding the Actor Changes How You Respond

The same false claim calls for a different answer depending on who pushes it, how far it has spread and how firm the evidence is. Correction can work with an ideological community, at the risk of widening a small claim’s audience. Platform enforcement and legal pressure are the usual levers against a commercial operation. A state-aligned network normally calls for coordination with government, and sometimes for public silence. The UK government's RESIST 3 framework makes the same point: responses should be proportionate, grounded in evidence, and designed not to restrict legitimate debate.

FAQ

References

Bradshaw, S., Bailey, H., & Howard, P. N. (2021). Industrialized disinformation: 2020 global inventory of organised social media manipulation (Working Paper 2021.1). Project on Computational Propaganda, University of Oxford. https://demtech.oii.ox.ac.uk/research/posts/industrialized-disinformation/

Cybersecurity and Infrastructure Security Agency. (n.d.). Defining insider threats. Retrieved September 28, 2026, from https://www.cisa.gov/defining-insider-threats

DISARM Foundation. (n.d.). DISARM framework. Retrieved September 28, 2026, from https://www.disarm.foundation/framework

European External Action Service. (2026). 4th EEAS report on foreign information manipulation and interference threats. https://www.eeas.europa.eu/eeas/4th-eeas-report-foreign-information-manipulation-and-interference-threats_en

Government Communication Service. (2025). RESIST 3: Building resilience to information threats. https://www.communications.gov.uk/publications/resist-3-building-resilience-to-information-threats

National Institute of Standards and Technology. (n.d.). Threat actor. In Computer Security Resource Center glossary. Retrieved September 28, 2026, from https://csrc.nist.gov/glossary/term/threat_actor

Nimmo, B. (2020). The breakout scale: Measuring the impact of influence operations. Brookings Institution. https://www.brookings.edu/research/the-breakout-scale-measuring-the-impact-of-influence-operations/

Pamment, J., & Smith, V. (2022). Attributing information influence operations: Identifying those responsible for malicious behaviour online. NATO Strategic Communications Centre of Excellence; European Centre of Excellence for Countering Hybrid Threats. https://stratcomcoe.org/publications/attributing-information-influence-operations-identifying-those-responsible-for-malicious-behaviour-online/244

State Security Department of the Republic of Lithuania, & Defence Intelligence and Security Service under the Ministry of National Defence. (2026). National threat assessment 2026. https://www.vsd.lt/en/reports/influence-activities-against-lithuania/russia-is-stepping-up-its-information-campaigns-on-social-networks-using-constant-propaganda-narratives-to-support-them/

U.S. Department of Justice. (2018, July 13). Grand jury indicts 12 Russian intelligence officers for hacking offenses related to the 2016 election [Press release]. https://www.justice.gov/archives/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-election

Wardle, C., & Derakhshan, H. (2017). Information disorder: Toward an interdisciplinary framework for research and policy making. Council of Europe. https://rm.coe.int/information-disorder-report-november-2017/1680764666

Next
Next

PESO Model vs NIIS Model: What PESO Measures and What NIIS Adds