Skip to main content

The Same Door, Two Operations

Manipulation Breakdowns · 11 min read · By D0

Introduction

In early 2026, six Facebook pages appeared in the Philippines with names like “Kasama LR true colors” and “Communism Unmasked PH.” They existed to do one thing: flood the comment sections of leftist student and labor groups with accusations that the activists behind them were fronts for a communist insurgency. Around the same posts, on the same pages, a second operation was running — fifty Facebook profiles with a completely different agenda. They weren’t interested in whether the activists were communists. They were using the activists’ comment sections as a free amplifier to call for the sitting president’s death and promote his vice president’s ascension.

Neither operation knew the other existed. Neither needed to. That’s the finding the Digital Forensic Research Lab (DFRLab) published on June 30, 2026, and it’s worth sitting with, because it breaks a habit built into most disinformation reporting: the assumption that a coordinated campaign has one author, one motive, and one story to tell. Here, the same twenty-seven pages hosted two adversarial operations, run for opposite reasons, converging on the same target purely because it was an easy one.

Two Networks, One Comment Section

DFRLab’s report centers on twenty-seven Facebook pages tied to labor rights groups, youth activist organizations, women’s groups, and progressive party-lists in the Philippines — among them the League of Filipino Students, the labor federation Kilusang Mayo Uno, its national chairperson Jerome Adonis, and former Gabriela Women’s Party representative Arlene Brosas. These pages became a flashpoint after April 19, 2026, when the killing of student activists triggered a wave of protests.

What DFRLab found sitting on top of that flashpoint wasn’t one influence operation. It was two, run by unrelated actors, with incompatible goals, both treating the same real people as raw material for something else entirely.

The Domestic Network: Building the Terrorist Frame

The first operation was a cluster of six interconnected Facebook pages — “Kasama LR true colors,” “UPLB Perspective Exposed,” “Pamalakaya Cavite true colors,” “Cvsu Kilos Na Busted,” and “Communism Unmasked PH” among them — created between February 26 and April 24, 2026. Each ran under 200 followers, which would normally mean negligible reach. DFRLab found the opposite: heavy inauthentic engagement propping the pages up well past what an organic audience that size could generate, plus shared naming conventions, shared creation windows, and a shared network of amplifier profiles tying them together.

The content was consistent across all six: infographics and AI-generated images framing the CPP-NPA-NDF (the Communist Party of the Philippines’ armed wing and its political apparatus) as terrorists who exploit Filipino youth through front organizations, with the named student groups and labor federations recast as those fronts. The goal was narrow and legible — take activists demanding accountability for the killing of their peers and relabel them as insurgent sympathizers, using the exact vocabulary of a counter-insurgency framework.

DFRLab traced a moderate connection to the Armed Forces of the Philippines’ 2nd Civil-Military Operations Battalion, a unit whose public mandate includes exactly this kind of narrative work. The report is careful not to oversell that link: self-reported employer fields and military insignia in profile data “cannot be independently verified; they may be inaccurate, outdated, or fabricated,” and open-source evidence alone can’t establish institutional authorization or rule out a private contractor running the same playbook. A moderate connection to a named unit is a real finding. It is not proof of a chain of command.

Spamouflage: The Page as a Megaphone, Not a Target

The second operation looked nothing like the first, because it wanted nothing the first one wanted. DFRLab identified fifty Facebook profiles — one documented segment of the broader Chinese influence network known as Spamouflage — commenting on the same posts from the same activist pages. But these accounts weren’t accusing the activists of anything. They were using the activists’ already-large, already-engaged comment threads as free real estate to broadcast a message aimed past the activists entirely: at Philippine President Ferdinand “Bongbong” Marcos Jr.

The messaging pushed the hashtag #SaraForPresident, amplified statements from labor and opposition figures including Elmer “Ka Bong” Labog, the same Jerome Adonis the domestic network was trying to discredit, and Senator Bam Aquino. It spread rumors about Marcos’s health. One post, translated, read: “Little Marcos, die quickly, Support Sara to become president.” These accounts also called for Molotov cocktails at planned protests.

The technical tells were distinct from the domestic network’s. DFRLab found protest videos posted by these accounts days before the protests they depicted were scheduled to occur — a timing error that only makes sense if footage was staged, mislabeled, or recycled from an earlier event and dropped in ahead of a real calendar date. The accounts also carried a visible history: many had previously posted generic pro-China content unrelated to the Philippines entirely — narratives blaming the United States for drug trafficking, promotions for visa-free travel — before pivoting to Philippine activist pages once the April protests made them a live target. And DFRLab traced shared Telegram vendor links selling ready-made Facebook profiles, plus AI-generated images matching patterns already documented in Spamouflage’s operations on X.

Same comment sections. Same named activists. A completely different sponsor, a completely different goal, and not one point of contact between the two operations that DFRLab’s report identifies.

The Tells Were Technical, Not Ideological

What makes both networks detectable at all has nothing to do with what either one believed. DFRLab didn’t identify the domestic network because its politics were extreme, and it didn’t identify Spamouflage because its message was pro-China. It identified both through behavior: pages created in a tight window with shared naming schemes and follower counts too low to explain the engagement sitting on top of them; account histories that don’t match their current messaging, because the accounts used to exist for a different campaign entirely; content posted before the event it depicts could have happened; and a commercial supply chain (the Telegram vendor links) visible underneath accounts that otherwise look like organic Filipino Facebook users.

That’s a methodological point worth sitting with on its own. A detection approach tuned to catch “pro-China narratives” or “anti-activist narratives” would have needed two separate rulebooks to catch what happened here, and would still have missed the structural similarity between them — both networks used AI-generated imagery, both relied on inauthentic account clusters, both treated a real protest movement as an opportunity rather than a subject. A detection approach tuned to the behavior — timing anomalies, account history mismatches, engagement-to-follower ratios that don’t add up — catches both without needing to know, or care, which side either one was on.

Why No Coordination Was Necessary

The instinct in reporting like this is to look for the connection — a shared vendor, a shared handler, some thread tying the domestic network to Spamouflage because they showed up in the same place at the same time. DFRLab’s report doesn’t make that claim, and the more interesting explanation is that no such thread needs to exist.

A viral protest movement with weak moderation on its own communication channels is a resource, and resources get used by whoever notices them first, independent of who else is also using them. The domestic network needed a discredited enemy and found one in a visible activist movement. Spamouflage needed a receptive, already-mobilized audience to route anti-Marcos messaging through, and found the same movement’s comment sections sitting open and unguarded. Both got what they needed from the same twenty-seven pages without either one needing to know the other was there. That’s not a conspiracy. It’s two opportunists finding the same unlocked door.

What This Is Not

This is not a claim that the Philippine government and Chinese state actors coordinated, colluded, or were even aware of each other’s operations — DFRLab’s report contains no such claim, and the two campaigns’ goals are directly opposed, which is itself evidence against any alliance. The domestic network wants the activists discredited. Spamouflage wants Marcos discredited using those same activists’ platforms as a channel. Those are not compatible objectives run by cooperating actors. They’re two separate exploits of the same weakness, running in parallel.

This also is not a confirmed institutional finding on the domestic side. DFRLab’s own language — “moderate connection,” evidence that “cannot be independently verified” — belongs in any fair account of what was found. A military unit’s apparent fingerprints on a narrative campaign is a serious lead. It is not the same claim as a confirmed military operation, and collapsing that distinction would overstate what open-source research can actually establish.

And this is not a story about Meta’s moderation failing once. DFRLab notes a persistent enforcement gap dating back to a 2020 takedown of similar Philippine assets — the same vulnerability being exploited repeatedly over years, by different actors, because removing one set of accounts doesn’t close the door they walked through.

Key Findings

  • Two unrelated, adversarial influence operations targeted the same 27 Philippine activist Facebook pages simultaneously, for opposite objectives, with no evidence of coordination between them.
  • A domestic network of six pages (created February 26–April 24, 2026) used AI-generated images and infographics to frame labor and student activists as communist insurgent fronts, propped up by inauthentic engagement despite sub-200 follower counts.
  • A moderate, unconfirmed link ties the domestic network to the Armed Forces of the Philippines’ 2nd Civil-Military Operations Battalion — DFRLab is explicit that open-source data cannot verify self-reported military affiliation or prove institutional authorization.
  • A 50-profile segment of the Chinese Spamouflage network used the same activist pages as a staging ground to attack President Marcos and promote Vice President Sara Duterte, including a post reading “Little Marcos, die quickly, Support Sara to become president.”
  • Spamouflage accounts carried recycled histories — prior posts on unrelated pro-China topics — and posted protest footage days before the depicted protests’ scheduled dates, a timing tell pointing to staged or mislabeled content.
  • Both networks used AI-generated imagery and inauthentic account clusters despite having nothing else in common, evidence that the tools of manipulation converge even when the motives don’t.

Implications

The Influence Tactics Protocol scores manipulation by mechanism, and this case argues for treating multi-actor convergence on a single target as its own detectable signal — separate from, and prior to, the harder question of who’s behind any one campaign. A detection system built to attribute a single sponsor to a single narrative will naturally struggle here, because the honest answer is two sponsors, two narratives, zero relationship. A detection system built to flag the underlying behavior — engagement that doesn’t match follower count, account histories that don’t match current content, footage that predates its own subject — catches both operations without needing to resolve attribution for either one first.

There’s a sharper point underneath that for anyone being targeted this way. Being simultaneously cast as a communist front by one operation and instrumentalized as an anti-government megaphone by another is a strange, doubled kind of exposure: correcting the record on one narrative does nothing to the other, because they were never the same claim. An activist group defending itself against the insurgency accusation has no defense against being quoted approvingly by an account calling for the president’s death — that association was manufactured entirely by someone else, attached to their name without their participation, and it will outlast any correction of the original accusation it has nothing to do with.

For platforms, the persistent enforcement gap DFRLab flags — the same pages vulnerable to the same style of attack years after a prior takedown — suggests the fix was never actor-specific in the first place. Removing one network’s accounts doesn’t patch the underlying weakness a second, unrelated network can walk through using the exact same low-follower, high-engagement pattern six months later.

Conclusion

Twenty-seven Facebook pages run by Filipino students, laborers, and women’s rights advocates became, for a few months in 2026, the shared property of two governments’ worth of influence operations that never spoke to each other and wanted opposite things. One wanted the activists discredited as insurgents. The other wanted the activists’ visibility rented out, without consent, to call for a president’s death. Both got what they came for using the same unlocked door, on the same unremarkable pages, because neither one needed permission from the other — or from the people whose names were doing all the work.


This article is part of Decipon’s Manipulation Breakdowns series, examining specific influence operations through the Influence Tactics Protocol.


Sources: