23,998 Suspicious Naver Accounts Attacked Both Political Sides
A KAIST-Max Planck study found 23,998 suspicious accounts attacked both Moon Jae-in and Yoon Suk-yeol alike, with a 51% surge around elections.
SocietyNo Camp Was Spared: Both Moon Jae-in and Yoon Suk-yeol Got Attacked
Yesterday, a joint research team from KAIST and Germany’s Max Planck Institute released the findings of an analysis covering 112,660,000 comments on Naver (South Korea’s largest search portal) News. That’s the entire record left by 4,050,000 users over 20 years, from April 2006 to March 2025. Out of this dataset, they flagged 23,998 accounts suspected of foreign-linked influence operations, and the study is being formally presented today at USENIX Security, the top-tier academic conference in the security field.
But what’s more striking than the detection method itself is the list of who these accounts went after. The list of politicians these accounts attacked doesn’t split along left and right at all — both Moon Jae-in and Yoon Suk-yeol, presidents from opposing camps, were targeted by critical comments coming from the very same pool of accounts. An attack that doesn’t pick a side sounds, at first glance, like it doesn’t add up.
Precisely because the targets weren’t chosen by political camp, I read this activity as aimed at deepening domestic conflict — an interpretation centered on induced division that I’ll unpack below.
Progressive and conservative politicians alike were targeted by the same cluster of accounts
The starting point was a set of 70 foreign-linked accounts that the Institute for National Security Strategy (INSS), a South Korean state-run think tank, disclosed in 2024. The research team expanded the candidate pool to accounts connected to these 70 through follow relationships or that repeatedly swarmed the same articles, then analyzed comment language and behavioral patterns in stages to narrow the list down to 23,998 suspicious accounts — 0.59% of all users. These accounts left more than 15 million comments in total, and of those, 4.12 million classified as influence-operation activity are the subject of this strategic analysis.
When I tallied the targets of these accounts’ “Korea-bashing” comments that received only likes and no dislikes — that is, the ones that rose to the top of comment sections (based on figures in the paper’s main text and appendix) — 7 of the top 10 were politicians. Former President Moon Jae-in came in at 16,651 mentions, then-presidential candidate Lee Jae-myung at 13,522, former President Yoon Suk-yeol at 9,887, and former Minister Cho Kuk at 6,314. These are cumulative figures spanning 20 years through March 2025, so they have nothing to do with anyone’s current office. What matters isn’t the ranking but the composition: progressives and conservatives sit side by side on the same list. The non-political targets follow the same pattern — “South Korea,” “Hell Joseon” (a derisive term for the country), and the names of specific political parties fill out the list, and derogatory misspellings targeting a particular president showed up so often they were tallied as their own separate category.
The pattern gets even sharper when you break it down by administration. Roh Moo-hyun, Lee Myung-bak, Park Geun-hye, Moon Jae-in, Yoon Suk-yeol — across five administrations, whoever was the sitting president at the time always landed among the top 10 targets, regardless of political camp. Even administrations that were relatively friendly toward the accounts’ presumed country of origin were no exception. Professor Wonjae Lee of KAIST (Korea Advanced Institute of Science and Technology), who led the research, explained (as confirmed in domestic press coverage) that these accounts tended not to directly praise the foreign country in question but instead stirred up conflict by attacking Korea and its politicians. It looks less like backing one camp than like fueling conflict by taking turns attacking multiple camps.
For reference, the paper refers to the accounts’ presumed country of origin only as a “major neighboring country,” anonymizing the actual name. It’s a deliberate choice to focus on the tactics rather than get drawn into geopolitical disputes, and the research team kept the same phrasing in domestic interviews. I’m following the paper’s lead in this piece and not naming the country either. What matters in this research, I think, is the method — not the name of the country.
Accounts multiply when elections approach
The number of newly appearing suspicious accounts moved in lockstep with the political calendar. In the 30 days surrounding presidential, general, and local elections, newly created suspicious accounts averaged 34.19 per week — 51% more than the 22.61 seen in normal periods (per the paper’s tally, p<0.01). You might ask whether ordinary new-user signups simply rise during election season anyway — and the research team asked the same question. Regular user inflow rose only 24%, while the share of suspicious accounts among new users still climbed significantly, from 0.82% to 0.91%. That gap means the surge wasn’t just people showing up in greater numbers — it was a targeted mobilization aimed at the election itself.
The single largest inflow spike came in May 2017, during the presidential race that followed the president’s impeachment. Around that time, 635 new suspicious accounts appeared — the most in any month across the 20-year period. The peak in overall activity volume, though, came the following year, in 2018. That year alone saw 675,107 “anti-Korea” comments pile up, averaging roughly 1,800 a day. It overlaps with the period when the diplomatic dispute over THAAD deployment spilled into economic retaliation — and, as the paper notes, with the point when neighboring countries were institutionalizing organizations devoted to cognitive warfare1.
The sheer volume of comments left behind is too much for any one person to have written by hand. The 70 seed accounts that served as the starting point posted an average of 5,091 comments each. Even at one comment a day, that would take nearly 14 years — which is why the research team reads it as evidence of automation.
The pattern of activity wasn’t individual, either. The known 70 accounts followed one another and clustered together: the rate of mutual follows among them was 138 times higher than among ordinary users, and their average following count was 35 times higher (per the paper’s appendix data). That means these weren’t individuals acting independently — they moved as a single bloc, amplifying one another’s comments.
Only Anti-Korea Comments Cleared the Approval-Ratio Threshold
Why would these accounts bash Korea instead of praising their own country? The answer lies in how Naver’s comment section sorts comments. Naver is the gateway through which 63% of Korean adults get their news (Korea Press Foundation 2025 survey, as cited in the paper). And at that gateway, which comments rise to the top is determined by the approval ratio — the number of “likes” divided by the sum of “likes” and “dislikes.” Once that ratio crosses 0.5, it means likes outnumber dislikes, and the comment’s odds of reaching the top climb sharply.
Of the four rhetorical strategies used by suspicious accounts, only one cleared this threshold: bashing Korea. Its average approval ratio was 0.514. Praising neighboring countries scored 0.362, and praising allied states like Russia bottomed out at 0.241. The regression results point the same direction. The harsher the Korea-bashing, the higher the approval ratio climbed; the harsher the praise for neighboring countries, the more the approval ratio actually dropped. In other words, comments boasting about one’s own system only breed resentment among Korean readers, while comments trashing Korean society rise to the top. By the paper’s regression model, even when a comment’s anti-Korea character was detected at only about half confidence (probability 0.45), it had already crossed into territory where likes outnumbered dislikes.
The actual examples cited in the paper point the same way. Anti-Korea comments tend to frame conscription as state-run slavery, while comments praising neighboring countries tend to lecture Korea about how it should learn from its neighbors’ systems. The former rose to the top; the latter sank to the bottom.
There’s a theoretical basis for this. When Brady’s research team analyzed 500,000 political tweets in 2017, messages carrying moral emotion2 spread far more widely than those without it. Each additional word carrying moral emotion boosted spread by roughly 20% on average. In short, posts loaded with anger and contempt get shared more. The “moral condemnation” comments this study classified tap into the same emotions. And what actually pushed those comments to the top wasn’t bots — it was Korean users clicking “like” because the comments felt cathartic.
This creates a side effect worth noting. To evade detection, these accounts would need to drop the telltale language of moral condemnation — but that very language is what propels a comment to the top. Succeed at evading detection, and you lose your influence along with it. A well-designed detection standard, in other words, constrains this kind of activity simply by existing.
The NIS Comments, Druking, and These New Accounts
Here I found myself thinking of Britain’s divide-and-rule policy3 in colonial India. Divide and rule. The playbook of splitting Bengal along religious lines in 1905, then in 1909 creating separate electorates by religion — building conflict directly into the institutions. But there’s one crucial difference. Britain’s goal was direct rule, so it bore the cost of designing and maintaining the machinery of division itself. These accounts aren’t trying to rule Korea directly, so they don’t need to design or maintain any institution that manufactures division. The conflict already exists in Korean politics, and the “sympathy ranking” system already does the work of pushing hostile comments to the top — all these accounts have to do is pile on a few more comments. Because they don’t have to build and run the institution themselves, the cost is far lower.
And this isn’t the first time the top of the comment section has been targeted this way. Ahead of the 2012 presidential election, the psychological warfare unit of the National Intelligence Service (NIS), Korea’s spy agency, was mobilized to systematically post comments and cast approval/disapproval clicks. Won Sei-hoon, the former NIS director, had his 4-year prison sentence finalized by the Supreme Court in 2018. From December 2016 to April 2018, the Druking gang — a comment-manipulation ring — used a macro program called “King Crab” to push roughly 1,180,000 comments and some 88,400,000 approval/disapproval clicks across some 76,000 articles. Three entirely different actors — a state agency, a domestic political faction, and now a group suspected of foreign ties — all took aim at the same target: the belief that the top comment reflects public sentiment, and the sympathy-ranking system that decides which comment gets there.
The difference lies in intent. Both the NIS and Druking intervened in comment sections to get a specific candidate elected. These new accounts, by contrast, backed no candidate and no camp — they pushed to inflame domestic conflict regardless of political alignment. The methods differ too. Druking forged signals by mechanically pressing buttons, which left traces in server logs and eventually led to a courtroom. These new accounts get real users to click with their own hands. Since every single click is genuine, there’s no log to catch and no law written to punish it.
The timing overlaps as well. The peak influx of suspicious accounts identified in the paper (May 2017) falls right in the middle of the period when King Crab was running, and it also overlaps with 2018, the year activity peaked. In the very same comment sections, hands with entirely different agendas were moving at the same time.
The Limits of the Detection Results — and What Supports Them Anyway
But there are some caveats worth keeping in mind before taking this result at face value. First, “detection” isn’t “confirmation.” The research team itself flagged all 24,000 accounts as merely “suspected,” not confirmed state actors. The classification model behind this study is explainable AI4, which means its strength lies in producing sentence-level evidence for why an account is suspected — but that evidence is still a clue for humans to review, not a verdict.
There are numerical limits too. The account-classification model’s accuracy was reported as a high F1 of 0.94, but the validation sample was small — just 151 accounts — and the “moral sentiment” labels showed only middling agreement (0.512) even among the researchers themselves. And Naver has pushed back before: when a similarly themed study came out in 2024, the company countered that all the flagged accounts turned out to be Korean users (contemporary news coverage). Naver hasn’t yet issued a response to this new study.
On the other hand, there’s evidence that cuts in the study’s favor. When the test comments were rewritten wholesale by a language model, detection performance held up almost unchanged (an experiment in the paper’s appendix). That suggests the model reads the structure of rhetoric rather than memorizing specific words. The newly identified accounts’ activity timelines also moved in close lockstep with the 70 previously known accounts — a monthly correlation of 0.85, distinctly higher than the 0.70 seen among ordinary users exposed to the same articles. And because the entire dataset has been made public, this debate doesn’t have to end as a clash of assertions — other researchers can re-verify it. There’s also a process in place for users to check whether their own comments were included and request deletion.
Oswarld’s Lens
I read this data through the lens of market strategy. There’s one thing I learned while studying corporate strategy: the cheapest way for a challenger to shake up the market leader isn’t to boast about your own product—it’s to demolish trust in the market itself. Once you plant distrust across an entire category, you no longer need to prove a comparative advantage. It’s also why smearing competitors works so well in the short term when a new product launches.
20 years of these accounts follow exactly that structure. Persuading people that “our system is better” is expensive and doesn’t land well. In fact, comments praising neighboring countries drew an average approval ratio of just 0.362. By contrast, sowing the message “your society is rotten” is cheap, spreads easily, and even gets voluntarily boosted by readers in the very country being targeted.
So I think the criteria for judgment need to change. A standard that only asks “whose side is this comment on” is useless for this dataset—sitting presidents from all five administrations, Roh Moo-hyun, Lee Myung-bak, Park Geun-hye, Moon Jae-in, and Yoon Suk-yeol, all appeared in the top 10 targets. As someone who works with data, I’d add this: with research like this, you should look at the limits of measurement before you look at the conclusions—and the fact that this paper disclosed its own limitations openly is precisely what made it more credible to me. Instead, we should be asking: is this comment trying to make someone win, or trying to make us fight each other? And personally, the chilliest detail for me was this: the final step that actually pushed this hostile comment to the top wasn’t a bot—it was a Korean user clicking “like.”
Closing
Let me wrap up. The 24,000 suspicious accounts filtered out of 20 years of Naver comments didn’t push a particular camp. They took turns attacking politicians on the left and right, deepening conflict, their inflow rising every election season — and what pushed those hostile comments to the top was the like-ratio ranking and our own like button.
So I have one proposal. The next time you come across a comment on a political article that gives you that satisfying jolt of outrage, before you hit like, just ask yourself once: is this comment trying to help someone win, or is it trying to make us fight? If the answer leans toward the latter, that single like of yours could be the thing that pushes it to the top. I’m not saying suppress your anger. I’m saying remember that someone out there is trying to design where that anger goes.
Have you noticed any comment patterns lately that made you think, “this seems organized”? Tell me briefly in the comments — which article, what kind of pattern. If enough cases come in that are worth checking against public datasets, I’ll cover it in a future issue.
💬 Leave a comment if you’ve spotted something that looked “organized.” I’ll consider it for a future issue. 📨 If someone near you reads news comments often, share this piece with them.
Past issues worth reading alongside this one
I covered the “neighboring countries” of this story from the angle of industry and supply chains.
Keep the perspective, not the noise.
We choose one consequential shift and trace what sits beneath it, every other day.
Confirm once to finish subscribing.
Already a subscriber? Sign in to join the conversation
References & Further Reading
Primary sources
- Jaehong Kim, Hyeonseung Kim, Jiseon Kim, Alice Oh, Thorsten Holz, Wonjae Lee, Meeyoung Cha, “Cross-National Information Attacks: A Two-Decade Analysis of Troll Behavior in Korea”, USENIX Security Symposium 2026 (arXiv:2606.22785). Link ··· This is the backbone of today’s newsletter. The strategic analysis in Chapter 5 is the core, and Appendix Table 11 lists targets by administration.
- The research team’s public dataset, Zenodo. Link ··· The raw data behind 112,660,000 comments. Recommended if you want to verify things yourself.
- Electronic Times (Jeonja Sinmun), “20,000-plus Naver accounts stoked political conflict in Korea” (2026.8.12). Link ··· Coverage that includes the research team’s comments from their domestic presentation.
Background
- Institute for National Security Strategy (INSS), disclosure materials on foreign influence operations (2024). Link ··· The source of the 70 seed accounts that started this research.
- Kyunghyang Shinmun, “Suspected Chinese-linked accounts show signs of organized comment manipulation in Korea-China competition sectors” (2024.9.29). Link ··· Coverage of a 2024 precursor report. Note: the 77 Naver and 239 YouTube accounts mentioned here are a different tally from this paper’s 70 seed accounts — don’t conflate the two.
- Law Times (Beomnyul Sinmun), “Former NIS Director in ‘NIS Comment Manipulation’ Case Gets Final 4-Year Sentence After 5 Years” (2018.4.19). Link ··· The final conviction record of the first precedent in which a state agency manipulated the same comment sections.
- Newsis, “‘Druking’ (the online alias of a blogger convicted in a comment-manipulation scandal) Comment Manipulation Conspiracy’ Final 2-Year Prison Sentence Confirmed” (2021.7.21). Link ··· The source for the scale of manipulation: roughly 76,000 articles and 88,400,000 clicks. The figures in the main text are based on this ruling.
- William J. Brady et al., “Emotion shapes the diffusion of moralized content in social networks”, PNAS, 2017. Link ··· A landmark study on why moral emotions spread so effectively. This underpins the theoretical background in the third section.
📝 Glossary
Footnotes
-
Cognitive Warfare: A strategy that targets not military force but the perceptions and public opinion of a rival nation’s citizens. NATO defines it as external actors weaponizing public opinion to destabilize policy and institutions. ↩
-
Moral Emotions: Emotions like anger, contempt, and disgust that trigger moral condemnation of others, or admiration that elevates them. Numerous studies find these spread especially fast online. ↩
-
Divide and Rule: A strategy of stoking internal conflict within a subjugated group to prevent unity and make control easier. British rule in India is often cited as a classic example. ↩
-
Explainable AI: AI that doesn’t just output a verdict but also shows the reasoning behind it. In this study, it highlights the specific phrases in comments that triggered a suspicious rating. ↩

Your take shapes the next issue
What resonated most in this issue, or where has your experience been different?