← Back to Essays

When the Endpoint Lies: A Threat Model for Synthetic Information Environments

Published Jul 2026 synthesis Cybersecurity Threat Modeling Information Integrity Generative AI Influence Operations Endpoint Security

The conventional story of a serious network compromise is already familiar. An attacker gains privileged access, establishes persistence, collects credentials, watches the victim, and eventually turns that access into theft, extortion, espionage, or ransomware.

But privileged access creates another possibility that receives less attention: the attacker may begin changing not only the system, but the victim's perception of the system.

Imagine an attacker who controls a computer deeply enough to influence its network configuration, browser, trusted certificates, local applications, and security interfaces. The attacker does not need to construct a complete replacement for the Internet. They may only need to counterfeit a few strategically important observations: a news item, a market signal, a payment confirmation, an executive instruction, a service-status page, or the apparent absence of a security warning.

The victim continues to inhabit a mostly genuine information environment. Only the facts nearest an important decision are altered.

This essay calls that class of attack perception-layer compromise: persistent manipulation of the information presented to a target in order to change decisions, conceal reality, or manufacture an advantage. A more evocative name would be an epistemic man-in-the-middle attack. The attacker positions themselves not merely between two machines, but between a person and the evidence from which that person constructs a model of the world.

The premise sounds like science fiction when described as "replacing the Internet." It becomes technically credible once it is described more precisely.

The attacker does not have to fake everything

A person's behavior is not determined by every fact they could possibly observe. Most consequential actions depend on a small decision surface: a handful of prices, messages, warnings, approvals, identities, or deadlines.

We can write the idea abstractly as:

$$ A = D(O_1, O_2, \ldots, O_n) $$

Here, a victim's action (A) is produced by a decision process (D) operating on observations (O_1) through (O_n). An attacker does not necessarily need to control all (n) observations. If the decision is near a threshold, changing a small subset may be enough to change the resulting action.

This resembles an adversarial example, except the model under attack is a coupled human-machine decision process. The target is not necessarily the victim's beliefs in general. It is the boundary at which those beliefs become action.

That distinction matters economically. A botnet of 10,000 randomly infected consumer devices would not automatically give an attacker reliable control over a liquid financial market. The victims may not trade, may not act together, may notice contradictory information, and may be too small a share of the market to produce a predictable movement.

The stronger scenario is more selective. A smaller number of compromised systems belonging to people with common information dependencies—or a single system belonging to a consequential decision-maker—may offer more leverage than a large undifferentiated botnet. The attacker profits from an information asymmetry they manufactured: the attacker can observe reality while the victim acts on a counterfeit version of it.

Existing security concepts already contain pieces of the model

Perception-layer compromise is not a wholly new primitive. It combines several established attack classes.

MITRE ATT&CK's Data Manipulation technique describes adversaries inserting, deleting, or changing data to influence business processes, organizational understanding, or decision-making. Its Transmitted Data Manipulation sub-technique explicitly covers alteration of data moving between systems. Adversary-in-the-Middle covers attackers positioning themselves in a communication path to support sniffing, replay, or manipulation.

The closest established precedent is the man-in-the-browser attack. OWASP describes malware that modifies a transaction inside the browser while still displaying the user's intended transaction. The connection to the bank may be protected by TLS. The page may show the expected security controls. The endpoint lies anyway because the manipulation occurs before encryption or after decryption.

There are also network-scale precedents. Citizen Lab's analysis of China's Great Cannon documented malicious JavaScript injection into unencrypted web traffic. Kazakhstan's attempts to require installation of a government root certificate demonstrated the political value of controlling the trust layer; Mozilla and Chrome responded by blocking the certificate.

None of these examples is a complete synthetic information environment. Together, however, they demonstrate the necessary pieces: traffic positioning, trust manipulation, endpoint modification, selective content injection, and the ability to show a user one thing while a remote service receives another.

Why DNS control is not enough

The simplest version of this threat model begins with DNS. If an attacker controls name resolution, they can direct a domain name toward infrastructure they operate.

On the modern web, that usually does not produce a convincing forgery by itself. HTTPS authenticates the server and protects the connection. Redirecting a banking or news domain to an attacker-controlled server should cause a certificate error unless the attacker also controls an accepted certificate, controls a trusted certificate authority, or has altered the victim's trust configuration.

DNS-over-HTTPS and DNSSEC can strengthen parts of the resolution path, but neither can rescue an endpoint that is already deeply compromised. Malware with sufficient privilege may change resolver settings, alter the browser, install trust anchors, manipulate the rendered page, or simply lie about what the diagnostics say.

The important boundary is therefore not "Does HTTPS still work?" It is:

What component is trusted to present the result of the HTTPS connection to the human?

TLS can protect bytes between a legitimate server and a compromised browser while providing no guarantee that the browser displays those bytes faithfully.

A layered feasibility model

The attack becomes easier or harder depending on which layers the adversary controls.

Layer 1: Network path

The attacker controls DNS, routing, a gateway, an access point, an ISP position, or another part of the path.

This permits surveillance, blocking, delay, redirection, and manipulation of unencrypted traffic. Modern encryption makes silent alteration of correctly configured HTTPS services substantially harder.

Assessment: defensible today, but insufficient for a general counterfeit web.

Layer 2: Transport trust

The attacker can cause the endpoint to trust certificates or interception infrastructure under the attacker's control.

Enterprises legitimately deploy TLS inspection systems using related trust mechanisms, which demonstrates the technical feasibility. The attacker still has to cope with certificate pinning, application-specific trust stores, browser countermeasures, and artifacts visible to defenders.

Assessment: defensible under endpoint or administrative control; fragile against hardened applications and external inspection.

Layer 3: Browser or application presentation

The attacker controls the component that renders data for the victim. The network connection may remain genuine while selected text, images, forms, transaction details, alerts, or results are modified locally.

This is the most important layer. It avoids the need to reproduce every backend service and directly attacks the interface from which the user makes decisions.

Assessment: defensible today for selected applications and pages after serious endpoint compromise.

Layer 4: Operating-system presentation

The attacker controls the desktop shell, notification system, accessibility interfaces, security tools, update surfaces, or display pipeline. A replacement operating system could imitate another system visually, but reproducing application behavior, drivers, account state, peripherals, updates, and hardware-backed security would be expensive and brittle.

A rational attacker would usually preserve the victim's real operating system as camouflage and instrument selected presentation surfaces instead of replacing the entire environment.

Assessment: partial imitation is feasible; a durable, perfect replacement is implausible for ordinary criminal operations.

Layer 5: Accounts and platforms

The attacker also controls cloud accounts, mailboxes, social accounts, collaboration tools, or content-management systems. Manipulation performed at this layer follows the victim across devices and looks more legitimate because the false information is being served by the real platform.

This layer can be more valuable than network control. It also increases the chance that independent logs, other participants, or provider-side defenses expose the manipulation.

Assessment: defensible as a component of real intrusions; cross-platform consistency remains difficult.

Layer 6: Synthetic content generation

Generative systems produce supporting articles, images, comments, identities, messages, and explanations tailored to the target. Content can be generated quickly enough to respond to new questions or patch minor narrative inconsistencies.

AI lowers the cost of producing material. It does not automatically provide distribution, trust, or persuasion. OpenAI's October 2024 threat report described real attempts to use models in influence operations while also reporting that the election-related operations it observed had not achieved viral engagement or sustained audiences through model use.

Assessment: defensible as a scaling and personalization mechanism; unproven as an automatic route to influence.

What could an attacker gain?

The safest way to analyze attacker incentives is by impact class rather than by offering an operational recipe.

1. Synthetic normalcy

The most elegant use may be concealment.

Instead of presenting a spectacular false world, the attacker makes a compromised organization appear healthy. Security alerts disappear. Backups appear current. Administrative changes look authorized. Transactions appear to have reached their intended destinations. Service-status pages remain green.

The economic benefit is additional dwell time. Continued access may be more valuable than immediate ransomware because it extends opportunities for espionage, credential collection, data theft, or later extortion.

2. Transaction and approval distortion

A victim may see the instruction they expected, the recipient they intended, and a reassuring confirmation while a backend system receives materially different data. Man-in-the-browser attacks establish the feasibility of this narrow pattern.

At organizational scale, the target may be any workflow where a human approves a consequential action through a compromised interface. The decisive security property is not merely authentication of the user. It is authentication of the user's intent, including what exactly was approved.

3. Organizational misdirection

An attacker could selectively alter dashboards, internal messages, incident reports, inventory records, or executive instructions to make an organization respond to the wrong problem.

The benefit need not be direct theft. Misdirection can delay containment, create operational loss, damage trust, or cause the victim to allocate resources away from the attacker's real objective.

4. Negotiation and selection leverage

Many commercial decisions depend on information presented shortly before a choice: availability, pricing, deadlines, competing offers, risk assessments, and the apparent reputation of counterparties.

A party able to corrupt those observations may be able to bias procurement, contracting, hiring, or negotiation without fabricating an entire market. This remains risky because consequential decisions usually involve several people and leave records on independently administered systems.

5. Selective market influence

The botnet scenario belongs here, but it needs careful constraints.

Showing the same false signal to 10,000 arbitrary devices does not guarantee a market response. Feasibility depends on who the victims are, whether they act on the signal, whether their actions are correlated, how liquid the market is, and whether independent information channels contradict the injection.

The more credible threat is not universal prediction of market movement. It is localized distortion of a decision cohort or temporary suppression of information from people already positioned to act. Even then, the attacker faces substantial uncertainty and legal exposure. This is a plausible research question, not a demonstrated profit machine.

6. Coordination fracture

Different victims could receive different versions of the same event. Each version might be internally plausible while making collective verification harder.

This could be used for political influence, labor or community conflict, crisis manipulation, or disruption of institutional response. The goal may not be to make everyone believe one falsehood. It may be to prevent the group from forming a shared account of reality quickly enough to coordinate.

7. Controlled discovery

An attacker conducting espionage may want a target to discover selected evidence while remaining unaware of the larger compromise. Counterfeit search results, documents, or alerts could steer an investigation toward a convenient explanation.

This is epistemic containment: the victim is allowed to investigate, but only inside a prepared narrative corridor.

8. Extortion through integrity loss

Traditional ransomware demonstrates control by denying access to data. A perception-layer attacker could demonstrate that the victim can no longer trust what their systems display.

That threat may be especially damaging to organizations whose value depends on records, measurements, approvals, or public credibility. The attacker would still need convincing evidence of control, and displaying that evidence would risk exposing the mechanisms sustaining the attack.

The bottleneck is coherence, not generation

Generating a plausible news article is easy compared with maintaining agreement among:

Every independent channel becomes a potential witness against the counterfeit environment.

This suggests a practical law of the threat model:

Perception-layer compromise is strongest when the target is isolated, the decision window is short, and the relevant evidence passes through a small number of attacker-controlled surfaces.

It weakens as the target gains time, independent devices, separate network paths, out-of-band human contact, or cryptographically authenticated records tied to the intended action.

The perfect fake Internet is therefore the wrong object to study. A selective, temporary, decision-oriented counterfeit is both more plausible and more dangerous.

Defensive implications

Conventional confidentiality controls are not enough because this is primarily an integrity attack.

Treat the endpoint as a presentation authority

Security architecture often treats the endpoint as a recipient of trustworthy data. This model requires treating it as the final authority that tells a human what happened. Endpoint detection, application integrity, measured boot, secure boot, and hardware-backed attestation therefore protect not only code execution but the user's evidence surface.

These controls are not absolute. Secure boot can make wholesale OS replacement harder while doing little against permitted software abused after startup. The defense has to match the layer being attacked.

Bind authorization to human intent

High-consequence systems should confirm the material details of an action through a channel the potentially compromised interface cannot silently rewrite. The principle is already present in transaction-signing systems and out-of-band approval procedures.

A second factor that merely says "approve?" is weaker than a separately trusted display that says exactly what is being approved.

Preserve independent verification paths

A second browser on the same compromised computer is not independent. A separately managed device on a different network is better. A verified phone call to a known person may be better still.

Organizations should identify which decisions require this kind of independence before an incident occurs. During recovery, instructions displayed by a suspected endpoint should not be treated as authoritative.

Monitor information integrity, not just availability

Status dashboards, audit records, backup reports, and security consoles need independent logs and cross-checks. A green interface is not evidence of a healthy system if the interface and the system share the same compromise domain.

Make contradictions survivable

Users should have a clear path to report, compare, and escalate contradictory displays without being dismissed as confused. A perception-layer attack exploits the tendency to trust the machine's polished account over the human who notices that something feels wrong.

Claim tiers

Defensible now

Plausible but unproven

Speculative

Failure conditions

The strongest version of this argument should be rejected or narrowed if:

The market-manipulation sub-hypothesis specifically fails if compromised users cannot be selected with enough precision, do not act in correlated ways, or represent too little decision weight to create a measurable effect.

Conclusion

The disturbing possibility is not that a hacker can construct a flawless replacement universe.

It is that they may not need to.

Most of the Internet can remain real. Most messages can remain untouched. Most applications can continue to work normally. The attacker only needs control over the observations nearest a consequential decision, and only for long enough to push that decision across a boundary.

This reframes endpoint security as more than protection of files, credentials, and computation. The endpoint is part of a person's sensory apparatus. Once it is compromised, the attacker may gain the ability to manufacture evidence, suppress contradiction, and selectively edit the reality on which action depends.

Generative AI makes the surrounding fiction cheaper. Persistent system access gives that fiction a delivery mechanism. The combination does not create omnipotence, but it creates a serious integrity threat that sits somewhere between cybercrime, information warfare, and adversarial control of human-machine systems.

The right defensive question is therefore not only:

Is this connection authentic?

It is also:

What would tell us if the interface presenting that connection had begun to lie?

Links

Source code repository for this project.

GitHub