Information Disorder: A CTI Analyst’s Guide to Fake News

You’re briefing senior leadership on your latest threat intelligence findings. You’ve spent hours validating sources, cross-referencing indicators, and building a solid intelligence product. Then someone interrupts: “So, is this fake news or what?”

If you’re a cyber threat intelligence analyst, you’ve faced this challenge. Stakeholders use “fake news” as a catch-all term for everything from innocent mistakes to sophisticated state-sponsored disinformation campaigns. This oversimplification makes it impossible to communicate the nuance of what you’re actually dealing with.

The solution? A framework called information disorder that provides precise classification based on two questions: accuracy and intent. This guide will teach you how to use this framework to classify information threats, explain it to stakeholders, and integrate it into your daily CTI workflow. Let’s get started!


Understanding Information Disorder

What exactly is information disorder? Think of it as the intelligence community’s answer to the “fake news” problem. Instead of lumping everything together, information disorder provides a structured classification framework based on two critical dimensions:

  1. Is the information accurate or false?
  2. Is there intent to cause harm?

These two dimensions determine everything. 

These two simple questions create a powerful classification matrix that helps you categorize any piece of questionable information you encounter. Here’s how it breaks down:

Information TypeAccuracyIntent to HarmExample in CTI
MisinformationFalseNoAnalyst unknowingly shares outdated malware analysis.
DisinformationFalseYesLeaked internal security docs were published to embarrass the organization.
MalinformationTrueYesLeaked internal security docs published to embarrass the organization.

The information disorder framework was developed by researchers Claire Wardle and Hossein Derakhshan for First Draft and the Council of Europe in 2017. While originally created to address challenges in online journalism and social media, it translates perfectly to cyber threat intelligence analysis. 

Why does this matter for CTI analysts? Because each category requires a different response:

  • Misinformation needs source validation and correction. 
  • Disinformation suggests adversary activity requiring threat actor profiling and attribution analysis. 
  • Malinformation requires assessing how authentic information is being weaponized.

Understanding information disorder isn’t just semantics—it’s a force multiplier for your intelligence work. When you can precisely classify the information threats you encounter, you can communicate more effectively with stakeholders, prioritize your response efforts appropriately, and demonstrate analytical rigor. 

Instead of telling leadership, “this might be fake news,” you can say, “this appears to be disinformation based on the deliberate misattribution of TTPs—I recommend we investigate for false flag operations.” That’s the power of speaking the language of information disorder.

Here’s a quick reference table you can use when encountering questionable information:

QuestionAnswerClassificationImmediate Action
Is it accurate?NoIntent? → No: MisinformationFlag with admiralty code, validate sources
Is it accurate?NoIntent? → Yes: DisinformationInvestigate as adversary activity, check for false flag
Is it accurate?YesIntent? → Yes: MalinformationAssess weaponization context, identify beneficiary

Now, let’s dive into each category and explore how to identify them in your day-to-day CTI work.


Misinformation

Misinformation is false or inaccurate information spread without intent to cause harm. The person sharing it genuinely believes it to be true. 

In the CT, misinformation is surprisingly common. 

  • An analyst might share an outdated malware analysis without realizing the threat actor’s tactics have evolved. 
  • A security researcher might misidentify indicators of compromise and publish them in good faith. 
  • A vendor report might incorrectly attribute an attack to the wrong threat actor group because it relied on superficial technical similarities.

The key characteristic of misinformation is a lack of malicious intent. The person spreading it isn’t trying to deceive anyone—they’re just wrong. This distinction matters because it affects how you respond. You don’t need to profile threat actors or investigate adversary motives. You simply need to improve your source validation and quality control.

When evaluating sources in CTI, always ask: Is this a primary or secondary source? Did they conduct the malware analysis themselves, or are they reporting on someone else’s work? Primary sources are generally more reliable because you’re closer to the original data. Secondary sources introduce the risk of misinterpretation. 

How should you handle misinformation when you encounter it? Flag it using the admiralty code.

The Admiralty Code uses a rating system where A-F indicates source reliability (A=Completely reliable, F=Cannot be judged) and 1-6 indicates information credibility (1=Confirmed, 6=Cannot be judged). 

If you suspect misinformation, downgrade your credibility assessment and document why. This ensures your intelligence consumers understand the limitations of the information without you having to write lengthy caveats.

But there’s one form of misinformation that’s particularly dangerous in CTI: circular reporting.

Circular Reporting

Circular reporting is the intelligence equivalent of a hall of mirrors—false information that appears to be corroborated by multiple independent sources when, in reality, all sources trace back to a single origin.

Here’s a real-world example: In 2019, a single security researcher attributed new malware to the “Fancy Bear” group. Within 48 hours, five different security blogs reported “confirmation from multiple sources.” 

When researchers traced the citations, they found that all five articles cited the same original report, which had never been independently verified. The “new malware” turned out to be a misattributed variant of existing tooling. No independent analysis was ever conducted—just circular reporting creating the illusion of consensus.

This is citogenesis—the process by which false information creates its own citation trail and becomes a “fact.”

The term “citogenesis” comes from the webcomic XKCD. It perfectly captures how false information on Wikipedia is picked up by journalists, who are then cited back on Wikipedia as proof. In CTI, this happens with vendor reports, threat intelligence platforms, and industry blogs. 

Why is circular reporting so dangerous in CTI?

  • Sources are obscured: CTI moves fast and often lacks transparency about original sources. A vendor report might say “according to industry sources” without specifying who.
  • Speed incentivizes republication: Security firms race to publish, creating pressure to amplify others’ findings without independent verification.
  • Technical data appears authoritative: Hashes, IPs, and MITRE ATT&CK techniques feel credible, but technical data doesn’t automatically mean good intelligence.

How to combat circular reporting:

  • Trace to original sources: Don’t settle for “industry sources report.” Find the original report, researcher, and data. No clear origin? That’s a red flag.
  • Never use Wikipedia as primary intelligence: Wikipedia is highly susceptible to circular reporting. Use it as a starting point, but always validate against original sources.
  • Cross-reference between truly independent sources: This means sources with different collection methodologies, geographic regions, or information access. Two vendors aggregating VirusTotal submissions aren’t independent—they’re looking at the same data.
  • Include circular reporting in ACH analysis: When evaluating competing hypotheses, explicitly test whether “this information exists due to circular reporting” fits the evidence better than other explanations.
  • Verify via different source types: If Vendor A claims new malware exists, can you find samples in your environment? Can you reproduce the analysis? Can you find an underground forum discussion predating the vendor report?

Circular reporting spans the collection and analysis phases of the intelligence lifecycle, making it particularly challenging if your organization maintains sterile corridors between collectors and analysts to obscure information for operational security reasons. If you work in such an environment, you’ll need to work closely with your collection management team to implement circular reporting checks without compromising necessary source protection.

The bottom line? Circular reporting turns misinformation into an apparent fact through the illusion of corroboration. As a CTI analyst, your job is to be skeptical, trace information to its origins, and never assume that multiple reports equal multiple independent sources


Disinformation

Now we enter adversary territory. Disinformation is false information deliberately created and spread to deceive, mislead, or cause harm. This is a calculated manipulation of your understanding of the threat.

In CTI, disinformation manifests as:

  • False flag operations misattributing attacks
  • Fabricated threat reports are manipulating security priorities
  • Fake researcher personas are spreading false technical information
  • Planted “evidence” in malware designed to mislead attribution

The key question when you suspect disinformation is: What is someone trying to achieve by spreading this false information? This is where you need to work backwards from impact.

When you encounter questionable information, map the potential impacts if people believe it. Who benefits? Does it serve the interests of a specific threat actor? Does it redirect security investments? Does it damage reputations? 

If you identify a clear beneficiary and the information appears deliberately crafted to achieve that benefit, you’re likely dealing with disinformation. Let’s explore two specific forms of disinformation that CTI analysts frequently encounter.

Active Measures

The term “active measures” comes from Soviet intelligence tradecraft, where it was known as aktivnyye meropriyatiya. It refers to a comprehensive strategy of covert political warfare operations designed to influence world events, sow discord, undermine adversaries’ credibility, and advance strategic objectives.

The term “active measures” originates from Soviet intelligence operations during the Cold War. Russian intelligence services have evolved these tactics for the digital age, making them highly relevant for modern CTI analysts tracking state-sponsored threats. 

Here’s what makes active measures different from a simple piece of disinformation: Active measures are campaigns, not individual incidents. They’re orchestrated, multi-faceted operations that might include:

  • Fabricated content: Completely false threat reports or “leaked” documents.
  • Imposter content: Fake researcher personas, imitation security blogs, or spoofed threat intelligence platforms.
  • Manipulated content: Real malware samples or network traffic modified to support a false narrative.
  • Malinformation: Leaked authentic documents placed in a misleading context.
  • Propaganda: State-affiliated media amplifying specific threat narratives.

In 2016-2017, Russian intelligence conducted active measures operations that included hacking the Democratic National Committee (DNC), selectively leaking authentic documents through DCLeaks and WikiLeaks (malinformation), while simultaneously spreading fabricated narratives about the content through fake news sites and social media personas (disinformation). The campaign blended truth with fiction, making it difficult to parse fact from manipulation.

When you suspect active measures, look for:

  • Orchestration: Multiple narratives emerging simultaneously across platforms with suspiciously aligned messaging
  • Strategic beneficiary: Who gains at the state level if this narrative is believed?
  • Technical inconsistencies: Fabricated intelligence often contains timeline misalignments, TTPs that don’t match known behaviors, or infrastructure patterns that break established tradecraft

False Flag

False flag operations involve deliberately misattributing attacks to disguise the true attacker’s identity. In CTI, threat actors plant false indicators, adopt another group’s TTPs, or leave misleading artifacts.

NotPetya (2017) is a textbook example of a false flag operation. The malware included a ransom note and a Bitcoin wallet, mimicking the typical ransomware tactics of cybercriminals. However, technical analysis revealed that the decryption capability was impossible. 

The disk encryption was deliberately designed to be irreversible. The “ransomware” facade was a false flag masking a state-sponsored destructive attack by Russian military intelligence (Sandworm/APT28) targeting Ukraine. The attack caused $10 billion in global damages while initially misdirecting attribution to cybercriminals.

False flag operations can be categorized using the PSYOPS (Psychological Operations) framework, which classifies information operations by their attribution and truthfulness:

  • White: Fully attributed and truthful. This isn’t really a false flag—it’s legitimate, attributed communication. Example: An official government cyber security advisory accurately describing a threat.
  • Grey: Attribution not given or unclear, mixes true and false information. Example: A threat intelligence report that’s technically accurate but comes from an unattributable source with potential ulterior motives—perhaps a front organization trying to shape threat perceptions.
  • Black: Deliberately misattributed and deliberately misleading. This is the true false flag operation. Example: A nation-state attack that plants extensive false indicators to blame another country, complete with fabricated “evidence” and misattributed TTPs.

Most false flag operations in cyber security fall into the “black” category—they’re deliberate deception operations designed to shift blame.

How to identify false flags:

  1. Contradictory technical indicators: Does code quality match the supposed actor’s known capabilities? Sophisticated APT groups don’t produce amateur code.
  2. Inconsistent TTPs: Does the attack chain match established tradecraft? A group known for spear-phishing, suddenly using a watering hole, warrants investigation.
  3. Too obvious attribution: Multiple blatant indicators all pointing to the same actor might be deliberately staged. Real operations have messier, mixed indicators.
  4. Work backwards: Who benefits if this attack is attributed to Group A instead of Group B?

Next up, information used to generate malicious outcomes!


Malinformation

Here’s the conceptually challenging category: genuine, factual information shared with the intent to cause harm. The information is true, but it’s weaponized through exposure, timing, or context manipulation.

Wait. How can true information be problematic? 

The key is in how it’s used. Information that would typically remain private is deliberately exposed. Information that’s accurate is deliberately placed in a misleading context. Information that’s real is weaponized through selective disclosure or framing.

In CTI, malinformation manifests as:

  • Leaked security documentation from breaches is published specifically to embarrass an organization or expose its defensive gaps.
  • Doxing of researchers and analysts to intimidate or punish them for their work.
  • Out-of-context vulnerability disclosure that is designed to cause panic or economic harm.
  • Selectively leaked breach data framed to damage reputation rather than inform defense.
  • Legitimate threat intelligence weaponized through biased framing in vendor reports.

The “out of context” aspect is critical. The information itself is true, but the presentation, timing, framing, and selective omissions weaponize that truth.

Imagine a researcher discovers a critical vulnerability in a piece of enterprise software. Responsible disclosure involves privately notifying the vendor, allowing time to patch, and coordinating public disclosure with mitigation guidance. 

Malinformation would involve publicly disclosing that vulnerability with no advance notice, causing maximum disruption, perhaps motivated by a grudge or a desire to create market chaos. The vulnerability information is true. But the method and intent of disclosure transform it into malinformation.

How to identify weaponized true information:

  1. Check the framing: Is there an editorialized narrative designed to provoke emotional reaction? What’s emphasized versus downplayed?
  2. Identify omissions: What critical context is missing? Partial truths can be more misleading than outright lies.
  3. Assess timing: Why release this now? Does the timing serve a strategic purpose?
  4. Examine sourcing: How was private information obtained? Hacks, leaks, or unauthorized access signal malinformation.
  5. Find the beneficiary: Who gains from the reputational damage, operational disruption, or strategic impact?

Doxing

Doxing refers to the act of researching and publishing private or identifying information about individuals with malicious intent. In cyber security, this typically targets security researchers, CTI analysts, incident responders, or executives.

The information published—real names, addresses, family details, social media accounts—is usually true. That’s what gives it power. The intent is to intimidate, harass, retaliate, or create vectors for physical threats.

Real-world examples of doxing:

  • In 2016, “The Shadow Brokers” doxed NSA analysts by leaking employee information after stealing NSA hacking tools.
  • In 2020, the Russian Energetic Bear (Dragonfly) group targeted researchers investigating their operations with doxing and harassment campaigns.

Doxing creates a chilling effect on threat research. If analysts fear personal reprisal for publishing threat actor profiles or attribution assessments, the entire CTI ecosystem suffers.

From an analytical perspective, track doxing campaigns as a form of threat actor activity. Which researchers are targeted? What work were they conducting? Which threat actors have the motivation and capability? This intelligence helps implement appropriate safety measures for analysts.

Propaganda

Propaganda is information, often true but selectively presented, used to influence an audience and further an agenda through manipulation rather than balanced presentation.

Here’s the tricky part: Propaganda can be both disinformation (includes false claims) and malinformation (uses cherry-picked true facts). The defining characteristic is intent to persuade at all costs.

In CTI, you’ll encounter:

  • State-sponsored threat intelligence: Technically accurate but serves strategic state narratives
  • Vendor fear marketing: Real threats, but risk assessments inflated to drive product sales
  • Politically motivated attribution: Technical evidence mixed with a political agenda
  • Lobbying-backed research: “Independent” research funded by groups with policy objectives

Some security vendors mix legitimate research with propaganda to drive product sales—this is malinformation. A vendor might publish sound malware analysis but frame the threat level as “critical, widespread emergency” when their data shows limited distribution, specifically to drive fear-based purchases. 

When evaluating potential propaganda:

  1. Identify the agenda: Who produced this? What are their strategic interests?
  2. Separate facts from assessments: The technical IOCs might be accurate even if the threat level is inflated. Extract technical intelligence while questioning the framing.
  3. Look for emphasis and omissions: What’s highlighted? What’s buried? What’s completely ignored?
  4. Check for loaded language: Objective intelligence uses measured language and confidence levels. Propaganda uses emotional terms like “devastating,” “existential threat,” and “unprecedented.”
  5. Cross-reference diverse sources: The antidote to propaganda is information sources with different incentive structures.

Recognizing propaganda doesn’t mean the underlying information is false. It means you need to mentally strip away the manipulative framing and evaluate the facts independently. A source can be both valuable and biased. You just need to account for that bias in your analysis.


Integrating Information Disorder into Your CTI Workflow

When should you apply this framework? 

At three critical points in the intelligence cycle:

  1. During Collection: Flag suspicious sources immediately. If a report can’t be traced to a credible primary source, mark it as potential circular reporting before it enters your analysis. Use your collection management framework to document source reliability concerns.
  2. During Analysis: When using structured analytic techniques like ACH, explicitly include “information disorder” hypotheses. Ask: “Could this be disinformation designed to mislead attribution?” Consider competing explanations for why information exists.
  3. Before Dissemination: Review your CTI report one final time. Are you inadvertently spreading misinformation? Have you verified all technical claims independently? Run your sources through the decision tree before publishing.

Build these checkpoints into your standard operating procedures to make information disorder assessment automatic, not exceptional. Include information disorder classification in your intelligence requirements and collection planning.

You now have a professional framework that elevates your analysis beyond “fake news” terminology. But why does this matter? 

When briefing stakeholders: Precision drives better decisions. 

When you tell leadership, “we’re dealing with a potential active measures campaign, disinformation designed to misattribute this attack” instead of “this might be fake news,” you communicate the threat nature, appropriate response level, your analytical rigor, and clear next steps. That’s infinitely more actionable than “fake news” could ever be!

The CTI field moves fast, and information warfare constantly evolves. But the fundamental questions—”Is it true?” and “What’s the intent?”—remain your north star.

Frequently Asked Questions

What Is Information Disorder?

Information disorder is a classification framework that categorizes false and misleading content based on accuracy and intent. It encompasses misinformation (false, unintentional), disinformation (false, intentionally deceptive), and malinformation (true, weaponized). This framework provides the precision that “fake news” lacks, enabling CTI analysts to determine appropriate threat responses.

What Is the Difference Between Misinformation, Disinformation, and Malinformation?

Misinformation is false information shared without intent to harm or honest mistakes. Disinformation is false information deliberately created to deceive—adversary activity. Malinformation is genuine information shared with the intent to harm through out-of-context presentation or unauthorized disclosure. The differences lie in accuracy and intent, which determine response actions.

What Is Circular Reporting in Cyber Threat Intelligence?

Circular reporting occurs when false information appears corroborated by multiple sources but actually originates from a single source. One report publishes information, others cite it without verification, and then the original cites those as “confirmation.” This citogenesis loop makes false information appear credible. Combat it by tracing to original sources and cross-referencing truly independent sources.

How Can CTI Analysts Identify Disinformation?

Work backwards from impact. Map who benefits if the false information is believed. Look for deliberate fabrication signs: false flag indicators (inconsistent TTPs, contradictory technical details), orchestrated campaigns (coordinated messaging), and clear strategic beneficiaries. If you identify a beneficiary and information appears deliberately crafted to achieve that benefit, it’s likely disinformation.