Cheaper By the Database
Welcome to Memetic Warfare.
This week we’ll dive into the election interference documents declassified by Trump not long ago. There are a few dozen documents in total, some of which are more interesting than others. Regardless, they’re a great look at finished analytical products from the US intelligence community and include a few interesting datapoints.
The documents go back to the 2020 elections.
One analytical document covers how China runs cyber operations for espionage targeting senior US leadership and other bodies - nothing super interesting or groundbreaking here, but still interesting to see how that’s covered, including the use of APT taxonomy.
The more interesting component, to me at least, was China’s use of public data, namely US voter registration data, for targeting and presumably to run influence operations. We don’t see much on where they get it in some of the earlier documents,
This is a recurring trend, with other documents referring to Chinese use of other databases, including consumer, military and other databases.
While for some reason some of this is redacted below, it’s possible to reasonably infer that the second half’s reference to to “conduct REDACTED opinion… analysis” on the US elections, is in fact referring to public opinion or voter opinion analysis.
We get some other interesting documents later on, in which we see that China has a “document” that contained a list of entities and relevant data. This includes datasets of PII, such that “bulk collection of such PII had been their goal”, with some focusing on voter registration.
Below we even see that 97 entries in the list are US-origin.
It’s obvious that the document is referring to hacked or purchased databases, with China creating their own fused databases of global data based on the targets they hit.
This becomes clearer below, in which we see actual lists of databases acquired by China.
We see a wealth of voter databases:
Medical and private-sector DBs are here as well:
Same goes for other companies:
Below we even see that they’re definitely buying data, with one set called “America“ taken from the hacking forum Exploit:
They of course fuse social media databases as well:
We see some other specific orgs targeted, with another one also being taken from a hacking forum I presume - the “2014 business cards” one:
So, China is making their own databases of global breached data. It’s what I’d be doing if I were them for sure, giving them broad information on US citizens as well as useful selectors for targeting, cyber and influence operations.
It’s fascinating to see just how available voter registration data is as well, with one Chinese APT simply downloading it from a website:
We also get some references to China running online IO, but what I can’t understand - why redact what is probably Spamouflage?
We also get some other fun graphics from internal reporting, which I’m including mainly for fun:
On that note, we’ll wrap things up.
Imagine being able to pull up a normalized database of hundreds of millions of Americans with their name, address, age, email address and phone number, social media accounts and more - the potential for targeting is endless. That’s what China is doing, and don’t be surprised - I’m sure that the US and other countries are doing this as well. If there are commercial companies out there doing it well, there’s no reason that governments aren’t.
So we get the potential for fusing databses, but the next step, which is scarier if more targeted, would be aggregating infostealer logs. And on that positive note, we’ll end this week’s post. Thanks for reading.



















