Skip to content
wiki.fftac.org

Modern Keyword Surveillance Systems - Source Excerpt 04 - Authoritarian State Surveillance: Russia’s SORM and China’s Great Firewall

Back to Modern Keyword Surveillance Systems

Summary

This source excerpt begins near Authoritarian State Surveillance: Russia’s SORM and China’s Great Firewall and preserves the surrounding evidence from 2IA.org/agent-file-handoff/Archive/2026-05-17-civil-liberties-overhaul/Content/Modern Keyword Surveillance Systems.md.

**Source path:** 2IA.org/agent-file-handoff/Archive/2026-05-17-civil-liberties-overhaul/Content/Modern Keyword Surveillance Systems.md

Masked engagement represents a substantial escalation in OSINT collection. According to leaked documents and reporting, over 6,500 DHS field agents and intelligence operatives are authorized to utilize alias accounts to passively observe public online activity, friend target users, join closed groups, and gain access to otherwise private photographs, friend lists, and restricted postings.32 While this tactic bars agents from interacting with users directly or assuming fully undercover false identities, it allows for the covert mapping of social networks without revealing government affiliation.32

Furthermore, agencies such as ICE and CBP have invested tens of millions of dollars into advanced, privately developed analytical platforms to track citizens and foreign nationals alike.25 Procurement records reveal a sweeping expansion of surveillance technology, including a $30 million investment in Palantir’s ImmigrationOS, which allows for highly granular tracking of immigrants by aggregating disparate data points.25 ICE has also secured a $3.75 million contract with Clearview AI, providing facial recognition capabilities that cross-reference operational targets against billions of scraped social media images.25 Officers equipped with mobile applications like "Mobile Fortify" can now scan individuals directly on the street, referencing over 200 million images aggregated across DHS, FBI, and State Department databases through super-query tools that bypass traditional keyword searches entirely.25

This aggressive expansion of monitoring has not occurred without incident. In early 2026, a major data breach highlighted the risks inherent in massive personnel and surveillance operations. A website known as the "ICE List" published a cache of data tied to roughly 4,500 DHS personnel, including front-line ICE and Border Patrol agents, allegedly leaked by a DHS whistleblower.33 The doxxing incident, which included work contact details and job information, prompted severe condemnation from the DHS and warnings regarding the safety of law enforcement officers.33

## **Authoritarian State Surveillance: Russia’s SORM and China’s Great Firewall**

While democratic nations utilize surveillance ostensibly for counter-terrorism, border security, and crime prevention, authoritarian states deploy parallel technologies expressly for political censorship, social control, and the suppression of domestic dissent. In these environments, keyword targeting is not merely an investigative tool; it is integrated directly into the foundational infrastructure of the national internet.

### **The Russian SORM Architecture**

Russia's domestic security organ, the Federal Security Service (FSB), enforces mass surveillance through the System for Operative Investigative Activities, universally known as SORM.11 Originally developed in the late 1980s and early 1990s for landline communications interceptions, SORM has evolved into a mandatory, multifaceted national dragnet.11 The system operates across three distinct technological generations:

* **SORM-1:** Collects and monitors mobile and landline telephone calls.11  
* **SORM-2:** Intercepts traditional internet traffic.11  
* **SORM-3:** The most advanced iteration, enforcing Deep Packet Inspection (DPI) across all media, including Wi-Fi, social networks, and enterprise data, while requiring ISPs to store all user data locally for a minimum of three years.11

A critical distinction between Russian surveillance and Western programs like PRISM is the mechanism of access. Russian law strictly mandates that all telecommunications companies and ISPs install SORM monitoring devices—referred to as "Punkt Upravlenia" (Control Points)—on their networks entirely at their own expense.11 These black boxes provide the FSB and seven other Russian security agencies with direct, unmediated backdoor access to network traffic without the knowledge, cooperation, or oversight of the service provider.11

The state internet censor, Roskomnadzor, utilizes this pervasive infrastructure to monitor public sentiment, dictate media licensing, and enforce ideological compliance.35 The granular nature of this censorship was exposed following the 2022 full-scale invasion of Ukraine. A Belarusian hacktivist group known as the Cyber Partisans successfully penetrated a Roskomnadzor subsidiary's inner network, downloading over 2 terabytes of internal documents and emails.37 The leaked documents revealed that the agency systematically targets users who post content linked to opposition leader Aleksey Navalny, particularly around contentious election periods.38 Furthermore, Roskomnadzor enforces restrictive measures that actively search for and mandate the removal of any online content that utilizes unauthorized terminology regarding the conflict, such as using the word "war" instead of the state-mandated "special military operation".38

Beyond passive domestic surveillance, Russian state-sponsored threat actors actively utilize keyword targeting for international cyber-espionage and financial fraud. Security analyses of Russian campaigns—such as those executed by the threat group Storm-2372—demonstrate attackers utilizing device-code phishing to compromise corporate and government networks.39 Once persistent access is achieved, these actors deploy automated keyword searches across victim emails to identify specific, high-value strings including username, password, admin, teamviewer, anydesk, credentials, secret, ministry, and gov in order to escalate privileges and exfiltrate state secrets.39

### **China’s Great Firewall and Semantic Erasure**

The Chinese internet censorship apparatus, colloquially known as the Great Firewall, represents the world's most sophisticated and expansive implementation of algorithmic keyword filtering. Research conducted by The Citizen Lab, which analyzed eight major search platforms operating in China—including Baidu, Weibo, Microsoft Bing, Douyin, Bilibili, and Sogou—uncovered a staggering matrix of over 60,000 unique censorship rules.9

Unlike Russia's reliance on physical black boxes, China enforces censorship through intermediary liability, holding internet companies directly responsible for the content hosted on their platforms.9 Failure to adequately control content can result in severe fines or the revocation of business licenses.9 Consequently, both domestic and foreign technology companies over-censor to comply with state directives. The Citizen Lab study noted that Microsoft Bing, operated by a North American company, actually implemented political censorship rules that were often broader and affected more search results than its chief Chinese competitor, Baidu.9

The Great Firewall utilizes two distinct methods of algorithmic censorship based on keyword triggers:

1. **Hard Censorship:** The total blocking and erasure of all search results for a specific query.9  
2. **Soft Censorship:** Selectively filtering results to only display content from state-authorized, "white-listed" domains, while actively hiding the existence of organic or dissenting results, preventing users from realizing they are being subjected to censorship.9

The targeted keywords are highly dynamic and reflect immediate political sensitivities. Target categories include attacks on the national political system, harming the image of revolutionary leaders, social stability rumors, pornography, and ethnic discrimination.9 Based on reporting statistics to the Cyberspace Administration of China, pornography accounts for the majority of censorship reports (61.7%), while political content accounts for roughly 7.7% to 29% depending on the year.9

Specific examples of the keywords and categorical targets enforced by the Great Firewall include:

| Censored Topic Category | Examples of Targeted Keywords and Context |
| :---- | :---- |
| **Political Leadership** | Direct references to President Xi Jinping, his surname (**"习" \[Xi\]**), and mocking or satirical references such as **"维尼"** are strictly blocked.9 |
| **Protests and Dissidents** | Keywords are rapidly updated to reflect real-world events. Following the Sitong Bridge protests, the specific character for bridge (**"橋"**) was immediately added to censorship lexicons, triggering widespread blocking in related contexts.9 |
| **Collateral Censorship** | Because the censorship algorithms are often character-agnostic and lack semantic awareness, entirely unrelated terms are frequently blocked. For example, searches for the Chinese actress **"习雪" \[Xi Xue\]** were collaterally censored because her name contains the character "Xi". The drug abbreviation **"ghB"** results in the soft censorship of musical artists whose names contain that specific alphanumeric string.9 The term **"AV"** is blocked as an abbreviation for adult video, unintentionally censoring non-pornographic queries.9 |