#TrollTracker: Glimpse Into a French Operation

Inauthentic accounts posted on soccer, fashion hijabs, dad jokes, and Emmanuel Macron

(Source: @DFRLab)

A network of inauthentic Facebook and Instagram accounts impersonated French-speaking users whose posts ranged from soccer and fashion tips for Muslim women to attacks on French President Emmanuel Macron, in a manner similar to the Russian troll operation which targeted the United States from 2014 through 2018, according to traces of their activity left online.

Facebook removed the accounts from its platform for “coordinated inauthentic behavior,” meaning these pages, which posed as organizations and individuals from different parts of the political spectrum or focused on opposite sides of a debate, were centrally operated. Most of the accounts were focused on building their audiences among French users, suggesting that this was an operation in its early stages.

Facebook took these accounts offline on November 5, 2018, after a tip from U.S. law enforcement.

A week later, Facebook updated its announcement, enumerating the accounts taken down: 99 Instagram accounts, 36 Facebook accounts, and six Facebook pages. The majority of the accounts posted in English (analyzed here); however, a dozen Instagram accounts and all six Facebook pages posted in French.

The French-language accounts appeared focused on audience building, but they also posted political content, especially attacking President Emmanuel Macron. This resembles the behavior of earlier Russian troll operations, which used existing social concerns and tensions to promote division and attack specific politicians in various countries, especially the U.S.

The traces these accounts left online provide a snapshot of an operation. As in any open source investigation based on reconstituting closed accounts, questions remain over how large the full operation was, how long it had been operating, what other content the accounts in question posted, and if they were active on other platforms. This article provides an initial description of the traces left by the known accounts.

By using the online traces to approximate the number of these accounts’ followers, we estimate that they reached 135,000 users at a very minimum.

The Accounts

Before the November 13 announcement, Facebook shared the names of 11 French-language Instagram accounts, which the company identified as “inauthentic” with @DFRLab.

Three of the accounts posed as African women: @une_camerounaise_fiere, @femme_combattante, and @moonlight_en_france. One, @football_et_france, posed as a football fan group focused on encouraging the “Ultras” across all clubs. A more political account, @france__rouge, posed as a Trotskyist, while another, @espoir_de_france, posed as a nationalist.

Of the rest, @action_verte focused on environmental issues, @les_femmes_musulmanes on Muslim women and fashion, and @contre_guerre on conflict, especially in Africa. @la_voix_etranger and @france_pour_tous engaged on immigration issues.

In its November 13 update, Facebook provided screenshots from two Facebook pages, named “fée-ministr” and “la France libre.” Those screenshots showed posts promoting feminist messages.

Post by Fee-ministr, based on a famous feminist poster, and shared by Facebook. (Source: Facebook)
Translated from French : “Feminism is the radical notion that women are people.” The French translates the Portuguese text in the image. (Source: Facebook)

A Google search revealed two more posts by “fée-ministr,” one a feminist quote from author Colette, the other mocking Catholics for their opposition to in-vitro fertilization (IVF) rights for gay couples.

“Woman is capable of everything man can do, except standing up to pee against a wall.” (Source: Facebook / fee-ministr, via Google)
Post by “fée-ministr.” The full URL at the bottom left gives the headline: “Why are Catholics against IVF if Jesus had two fathers?” (Source: Facebook / fée-ministr / Google)

Facebook also shared the name of a twelfth Instagram account, @lafemme.libre (“the free woman”). The only traces left of this account online were uncached references to two posts it made on the hashtags #feminism and #feminismforeveryone.

Facebook blocked all the accounts as part of its pre-midterms takedown before @DFRLab could review them. This analysis is based on residual posts, either from online caches or from shares. It therefore provides a snapshot of the accounts’ behavior, not a full catalog of their output.

This was not the first set of inauthentic accounts known to have targeted French speakers. The operation run by the Russian Internet Research Agency from 2014 through 2018 ran at least 11 dedicated French-language Twitter accounts, as made evident in the data shared by Twitter last month.

A word cloud of the content of these accounts’ posts highlights the core themes they most engaged on, with “migrant” being the most-used word, and “Brexit” a close second.

Word cloud of posts by the 11 Twitter accounts run by the Russian troll farm. (Source: Twitter “information operations” public dataset, visualization by Graphika)

Scale and Impact

The impact of the 11 Instagram accounts is best measured by their followings. Only one, @les_femmes_musulmanes, counted more than 10,000 followers, according to caches of the various accounts’ profiles (figures vary from cache to cache, depending on when the snapshot was taken).

More than half of them followed substantially more accounts than they had followers, a strong indication that they were not having great impact yet, and were actively building their audience. Many of these accounts routinely used “audience building” hashtags such as #follow4follow or #like4like, encouraging French users to engage with their content.

Accounts following, and followed by, the accounts in question. (Source: data from Instagram, via online caches. These are therefore only estimates, as those caches may not reflect recent counts.)

In total, the French-language Instagram accounts had a little under 70,000 followers, half of that number being driven by the most-followed account in this network, @les_femmes_musulmanes. According to Facebook’s update, around 65,000 users followed at least one of the Facebook pages. This does not appear to have been a massively effective operation: nonetheless, the set is of interest as it illustrates the latest themes and techniques used by actors to target French users with coordinated inauthentic behavior online.

Anti-Macron

The most overtly political aspect of these accounts, which cut across their claimed identities, was hostility towards French President Emmanuel Macron, and his party, La République En Marche. Five of the 11 Instagram accounts left anti-Macron posts behind, even in the snapshot represented by cached posts. These accounts posted using hashtags such as #macrondegage (“Macron, get out”), or memes targeting the French President.

Right-wing account @espoir_de_france (literally “hope of France”) regularly posted anti-Macron memes, especially on the topic of migration, but also on more general economic and political topics.

Translated from French: “If we walk with our heads high in France, it’s because, with Macron, we’re up to our necks in sh*t.” The use of “#039 ;” in the place of an apostrophe is the result of a character encoding issue, not a reflection of what the account posted. (Source: Instagram / @espoir_de_france, via Google cache of picdove.com, October 28, 2018.)
Left to right, translated from French: “Anti-French!”, “I prefer migrants to French people,” and “I love to insult the French!” (Source: Instagram / @espoir_de_france, via Google cache of picdove.com, October 28, 2018)

Some of its memes were taken from other online resources, such as this play on words, dated October 13, 2018, which replicated a meme circulated online in the summer.

Translated from French: “A strong man, a suit, a boat…” The meme is a play on words, which is meant to leave the reader concluding that the label for Macron is “a bastard.” (Source: Instagram / @espoir_de_france, via Google cache of picdove.com, October 28, 2018)

Another account, @femme_combattante (“fighting woman”), claimed to be a French woman of African descent and mostly focused on positive posts about African women. Nevertheless, it also posted a meme showing Macron as a slave-driver whipping African slaves, in the curious context of a post about France’s victory in the soccer World Cup.

Translated from French: “The grandsons of these slaves are a credit, not just to France, but to Africa today. France is world champion.” (Source: Instagram / @femme_combattante, via Google cache of zozu.site, undated.)

A third account, @france__rouge (“red France,” written with a double underscore, and not to be confused with the unrelated @france_rouge), claimed to be a Trotskyist, an international revolutionary Communist follower of assassinated Soviet leader Leon Trotsky.

It, too, posted attacks on Macron, including a claim that both the Left and the Right called him a hypocrite, a post on anti-government demonstrations in Paris, and a post on migration. Some of its posts included the hashtag #Benalla, referring to a scandal around the behavior of one of Macron’s security officers, Alexandre Benalla, which seriously weakened Macron’s prestige.

Left to right,, translated from French: “Emmanuel #Macron” is called a hypocrite — by the Left in May #mamoudougassama — by the Right in August.” “Support to the #demonstrators in #Paris!” “#Macron #immigration # immigrants # Aquarius.” The bio reads “Trotskyist France!” (Source: Instagram / @france__rouge, via Google cache of hotsta.net, August 16, 2018)

Benalla related posts, such as posts that contained the hashtag #benallagate, were also found in online traces of @france_pour_tous and @espoir_de_france Instagram posts.

Another account, @france_pour_tous (“France for everyone”), posed as a progressive account and focused on issues of poverty and migration. Its posts suggested that Macron, a former banker, was a distant and elitist ruler who feared that “the people” would wake up.

Translated from French: “The two things which haunt bankers? Sleeping money… and the people waking up!” (Source: Instagram / @france_pour_tous / Google)

A fifth account, @action_verte (“green action”), also going by the name “Martina Leflerc”, largely focused on environmental and landscape posts. Nevertheless, it posted at least one hostile comment on Macron regarding the resignation of Interior Minister Gérard Collomb on October 2, 2018. These posts appeared between images of French landmarks, such the Calanques of Cassis, or animal pictures used to comment on biodiversity.

Translated from French: “‘There is a world between Gérard Collomb and Emmanuel Macron. The Interior Minister didn’t resign, he fled! He was mistreated by a generation which thinks it’s allowed everything.’ @ZohraBitan Collomb believed in Macron’s promise of a new world. With the Benalla affair, migrant crises and arrogance of macronia, he realized that it was the worst of worlds. — — Don’t forget that your likes / comments allows the greatest possible number of people to see the post, which helps to develop this account.” (Upper image source: Instagram / @action_verte, via Google cache of inkphy.com, October 6, 2018. Lower image source: Instagram / @action_verte, from Google cache of instapics.download, October 8, 2018.)

No other French politician was mentioned by so many of the residual posts left by the accounts in this cluster in a tone so systematically negative. Taking into account Facebook’s conclusion that these accounts were connected and engaged in coordinated inauthentic behavior, it suggests that one key purpose of the group was to post negative comment about Macron.

Audience Building

Far more of the group’s activity appeared innocuous and aimed at building an audience among specific target demographics, especially ethnic and religious minorities. This resembled the operation conducted by Russian trolls against the United States from 2014, which paid particular attention to divisive issues of race.

@moonlight_en_france (screen name “Banu Tadun”), @femme_combattante (“Malika Shakur”), and @une_camerounaise_fiere (literally “a proud Cameroonian woman,” screen name “Léa Camerounaise”), all posted positive and empowering images of black women. @moonlight_en_france focused on their beauty.

The English and French texts give the same message. The typo “craddle” wins @DFRLab’s nomination for Best New Word of 2018. (Source: Instagram / @moonlight_en_france via Google cache of deskgram.net, September 28, 2018)
Translated from French: “Two Anglo-Saxon fashion magazines chose to put twelve black stars on the cover. A fashion phenomenon, or recognition of the beauty of ethnic minorities?” (Source: Instagram / @moonlight_en_france, via Google cache of deskgram.com, September 6, 2018.)

Many of its posts consisted of pictures with no comment other than hashtags. Some of the more common hashtags translated as #beauty and #blackbeauty (#beauté, #beauténoire); some also used the more political hashtags #stopracisme and #stopdiscrimination.

Source: Instagram / @moonlight_en_france, via Google cache of picbon.com, October 22, 2018)

@femme_combattante focused more on feminist content and women’s strengths.

Center, translated from French: “I love playing a strong woman, but a strong woman can also be very fragile and vulnerable at the same time.” Right, translated from French: “I’ve often thought that it was unfair that women stay at home when fighting is needed. If a woman is strong enough to carry a child, she can wield a sword as well as any man.” (Source: Instagram / @femme_combattante, via Google cache of picdove.com, October 30, 2018)

The account regularly used the hashtags #Follow4follow and #Like4like, offering to follow and like other users who reciprocated. This is a classic technique for building an account’s follower stats and audience.

Summary of the hashtags most used by @femme_combattante. (Source: Instagram / @femme_combattante, via Google cache of picgra.com, October 17, 2018)

@une_camerounaise_fiere ( “Léa Camerounaise”) behaved similarly, posting pictures of African women in celebratory poses. Again, it used the hashtags #like4like and #follow4follow among others to build its audience.

(Source: Instagram / @une_camerounaise_fiere, via Google cache of pintaram.com, September 26, 2018)

Most of its posts were innocuous, but at least one strayed into more political territory, focusing on racial discrimination and reposting content from an article published in leading French newspaper Le Monde.

Translated from French. Cartoon: “I don’t want to rent it out to some bloke with an Arab name! You’ll hold parties at my place!” Post: “Discrimination spreads the social networks! [sic] It’s better worth to call yourself Isabelle then Djamila [sic] to rent a house on Airbnb. The owner of the house in Toulouse refused to rent it to someone with an Arabic first name!” We have attempted to convey the grammatical errors of the original. (Source: Instagram / @une_camerounaise_fiere, via Google cache of pintaram.com, September 26, 2018)

The account @contre_guerre (“against war”) posed as a pacifist account, focused on Africa, and criticized perceived Western exploitation. It spoke of a war against imperialism.

Translated from French. Meme: “Poor countries have long national anthems because they explain all their problems in them.” Post: “#againstwar #for peace in the world. What if the father was right…” (Source: Instagram / @contre_guerre, via Google cache of deskgram.net, October 13, 2018)
Translated from French, clockwise from top left. “Our fight today is to struggle against the colonization of our consciousnesses. We have to be a free and worthy people.” “A good start to the week to Africans. The West wants to make us believe that we are a wretched people, but in reality we are a worthy and fulfilled people. Proud to be Black. Like if you’re proud of it too.” “United, we can push the imperialists back. United, we can win the war for freedom and true independence.” “A like to support our brother.” “Our children deserve more for Africa’s development.” (Source: Instagram / @contre_guerre, via Google cache of mysocialmate.com, October 4, 2018)

The account @les_femmes_musulmanes took a similar approach to the accounts which focused on African women, but this time focusing on Muslim women. Its specialty was posting glamorous images of Muslim women in headscarves and a variety of fashionable outfits, together with uplifting mottos. Again, it invited viewers to follow the account, showing its desire to build audience.

The post on the right translated from French: “a woman in a hijab always beautiful.” (Source: Instagram / @les_femmes_musulmanes, via Google cache of yooying.com, September 30, 2018)

Hijabs were its specialty, as this image shows, with numerous hijab-related hashtags, including #hijablicious, #hijabchic and #turbanista.

(Source: Instagram / @les_femmes_musulmanes, via Google cache of picgra.com, October 17, 2018)

These tactics clearly had some effect; by September 30, it had over 20,000 followers.

Profile page for @les_femmes_musulmanes. (Source: Instagram / @les_femmes_musulmanes, via Google cache of yooying.com, September 30, 2018)

Posing As Political

Some of the accounts were more overtly political or activist. The most obvious was @france__rouge, whose bio proclaimed it to be a Trotskyist. As we have seen above, its surviving posts took an outspoken view of politics, from a far-left stance. It quoted revolutionary Marxist leaders including Fidel Castro and Hugo Chavez.

Posts by @france__rouge, including quotes from Castro and Chavez, as well as attacks on Macron. (Source: Instagram / @france__rouge, via Google cache of insta-stalker.com, November 3, 2018.)

@action_verte posed as an environmentalist account. Its bio called for “green activism” and carried the motto, “Preserve our future, save our planet!”

Cache of @action_verte, with the bio highlighted. The bio also urged users to send their own images directly. Bottom left to right, translated from French: “Cherry trees in flower,” “Hoooooooot,” “There is a world between Gérard Collomb and Emmanuel Macron. The Interior Minister did not resign, he fled! He was mistreated by a…” (Source: Instagram / @action_verte, via Google cache of inkphy.com, October 6, 2018)

Most of its posts fit with that bio, sharing pictures of wildlife and hashtags such as #RecYcle and #greenpeace.

(Source: Instagram / @action_verte, via Google)
(Source: Instagram / @action_verte, via Google)

On one occasion, it shared a picture of a spider’s web covered in dew, with a caption which called it simply “perfect.”

Source: Instagram / @action_verte / Google

The image included, at the top left, a Russian-language caption, “паутина,” “spider’s web.” This could be wholly innocuous, but appears noteworthy, in the context of suspicions that this network of inauthentic accounts was run from Russia.

Collage of images showing the enlarged Russian-language caption and, on the right, a separate cache of the @action_verte post, with attribution. (Source left and detail: Instagram / @action_verte / Google. Source right, Instagram / @action_verte, via Google cache of the-picta.net, September 5, 2018.)

Another apparently activist account was @france_pour_tous, which mainly posted on issues of migration, and sometimes used the screen name “Elisabeth Duval.”

Translated from French: “You can be a genius and a refugee. Einstein was a refugee.” (Source: Instagram / @france_pour_tous, via Google cache of picbear.online, September 4, 2018)
Left to right, translated from French: “We have to help those who are ready to work for the good of their families.” “We have to help those who are starting a new life.” “We have to help those who are searching for new opportunities.” (Source: Instagram / @france_pour_tous, via Google cache of picbear.online, September 4, 2018)

One account which was politically opinionated was @la_voix_etranger, whose profile picture showed author Albert Camus and whose name was a take on his famous novel L’Étranger (“The Stranger”).

(Source: Instagram / @la_voix_etranger, via Google cache of pikdo.net, October 10, 2018)

Many of its posts consisted only of hashtags; a few were written in a more informal French. The hashtags included #rebeu and #renoi, which are words in “verlan”, a form of French argot, referring to North African and black ethnic groups. It appears to have been an account in the early stages of audience building, with over 2,500 followers, but it followed over 7,000.

(Source: Instagram / @la_voix_etranger, via Google cache of hotsta.net, October 7, 2018)

The final account was a purely soccer-focused, audience-building one. Called @football_et_france, it promised “everything about French football and fans. ‘Ultras’ [extreme fans] of all clubs, unite!” Many of its posts focused on the World Cup, not surprisingly, given that France won.

Profile of, and posts by, @football_et_france. Translated from French, the bio reads, “Everything about French football and fans. Ultras of all clubs, unite!” (Source: Instagram / @football_et_france, via Google cache of insta-stalker.com, October 17, 2018)

Other posts dealt with club matches, and supported both sides. The screenshot below shows this account’s comments on a match between Olympique Marseille (OM) and Toulouse, described as the “first day of the season.” The two teams did indeed play the season opener on August 10, 2018; Marseille won 4–0.

Posts by @football_et_france. Note the bottom row of posts, which include “Go, Olympique Marseille!” (bottom row, center right) and “Go, Toulouse!” (bottom row, center left), for a match in which Olympique Marseille played against Toulouse. (Source: Instagram / @football_et_france, via Google cache of hotsta.net, August 15, 2018.)

Conclusions

Facebook determined that this network was one of “coordinated inauthentic activity.” There is insufficient evidence to provide a firm attribution to the Russian Internet Research Agency; the accounts certainly behaved like troll factory accounts, but such behavior is not confined to Russian information operations.

The accounts did not appear to have particular impact. Other than @les_femmes_musulmanes, none achieved a significant following. Their audience-building strategies suggest that the operation was in its early stages; their followings suggest that it still had some way to go.

While the content was largely innocuous, and even positive in some cases (quotes of famous French poets, empowering images), the fact that it was posted by a coordinated inauthentic network, and included strongly political messages, suggests that this was an attempt to gain influence and, potentially, push divisive and inflammatory messages to these audiences at a later stage.


Ben Nimmo is Senior Fellow for Information Defense at the Atlantic Council’s Digital Forensic Research Lab (@DFRLab).

Camille Francois is Research and Analysis director at Graphika and a Mozilla Fellow.

Follow along for more in-depth analysis from our #DigitalSherlocks.