Executive Summary
OpenAI terminated multiple accounts tied to state-aligned influence campaigns in Russia and Iran. These threat groups ran deceptive false front operations to launder propaganda into genuine news outlets. Consequently, security analysts alerted global editors and public institutions about these covert deception methods.
What Happened in the Deceptive Campaigns
Foreign influence groups are changing their distribution playbooks across the internet. Earlier influence networks relied heavily on fake social media accounts to spread propaganda. In contrast, newly uncovered groups planted fabricated stories directly into legitimate publications. Both campaigns established deceptive false front operations to hide their state sponsors. The operators used artificial intelligence to polish English drafts, translate scripts, and write internal reports.

Russia-Origin Operation Dark Clark
The Russian operation operated under the internal code name Dark Clark. This network established a self-described research platform called the Social Research Center in Latin America. Furthermore, the Russian operators created a fake online persona named Mia Clark to manage regional staff. The local employees conducted authentic interviews and drafted original research papers on regional politics. According to investigators, these Latin American employees had no knowledge of their Russian handlers.
The Russian operators also generated forged documents to provoke public controversy. In Peru, the actors sent forged emails to local schools from a fake regional education account. The emails directed teachers to celebrate controversial historical figures during cultural events. When schools complied, the operators placed news stories in Peruvian and Polish outlets to trigger outrage. Similarly, the network fabricated audio recordings of Ukrainian officials to disrupt local politics in Ecuador and Bolivia.
Iran-Origin Operation Bogus Bylines
Meanwhile, the Iranian influence network operated a project dubbed Bogus Bylines. This network created seven fictitious Western journalist personas to approach independent newsrooms. These personas included fake American writers such as Ervin B. Hoskins, Sophia Gonzalez, and Michael Harrison. Additionally, the operators built fake social media profiles on Medium, Facebook, and Instagram to backstop each persona. However, mobile application store records showed that the accounts originated from Iran.
The Iranian operators prompted language models to refine opinion essays on international conflicts. The operators instructed the software to format drafts according to specific outlet submission guidelines. Once the drafts were ready, the operators generated personalized pitch emails to news editors. Multiple independent websites accepted and published these opinion pieces without realizing their true origin. In addition, the actors created batches of social media comments to praise their own published articles.
Who Is Behind the Activity
Security investigators determined that state-linked networks in Russia and Iran backed these operations. Open-source evidence ties the Dark Clark campaign to a Russian political organization known as Politology. Independent researchers consider Politology a successor to entities formerly run by Yevgeniy Prigozhin. OpenAI expressed high attribution confidence regarding the Russian origin of these user accounts. The users prompted the models in Russian and masked their internet protocol addresses with commercial virtual private networks.
In contrast, investigators maintain moderate attribution confidence regarding the Iranian campaign. Analysts suspect an independent digital marketing agency conducted the operation on behalf of state sponsors. The operators prompted the models in Persian and generated content in both Persian and English. However, investigators have not named a specific private enterprise or military intelligence unit. OpenAI shared technical data on both networks with law enforcement agencies and commercial cybersecurity partners.
Assessing Operational Impact and Scale
Both influence networks achieved unusual reach compared to ordinary social media bot campaigns. On the international influence breakout scale, researchers assessed Dark Clark at Category 5. OpenAI stated, “This is the first Category 5 operation we have disrupted since we began our reporting.” The Russian campaign triggered public statements from cabinet ministers in Ecuador and lawmakers in Poland. Furthermore, the group published over sixty original analytical reports through its unwitting Latin American think tank.
Similarly, the Iranian campaign achieved substantial distribution across independent digital publications. The personas successfully placed nearly 100 opinion pieces across more than a dozen online outlets. Several of these digital publications maintain social media followings exceeding one million users. The company detailed this activity in an alert examining disrupting AI-enabled false front operations across modern media. Researchers explained that threat groups use language models to support deceptive false front operations. As researchers noted, “The operators can use these advantages to exploit unsuspecting victims, such as employees or editors, and plant their content in front of audiences who have no idea who was behind it, or what their motivations were.” However, the group generated minimal engagement on public social networks.
What Comes Next and How to Stay Protected
Public exposure remains an effective countermeasure against deceptive influence networks. Previous investigations by Meta forced similar entities like PeaceData to shut down completely. Therefore, rapid public reporting helps researchers identify and remove malicious infrastructure before it spreads. Defending modern media requires active cooperation between technology platforms, journalists, and public institutions.
Verifying Freelance Contributors
Newsroom editors must adopt rigorous identity verification standards for freelance submissions. Editors should verify contributor identities through live video conversations or established institutional affiliations. Additionally, publications should inspect contributor domain registrations and social media histories. Newsrooms must also establish protocols to detect coordinated submission patterns across regional publications.
Protecting Public Institutions
Public agencies and educational institutions must also guard against digital deception. School administrators should confirm unexpected directives by contacting official government offices directly. Furthermore, organizations should deploy protective domain filtering and audit inbound communications for spoofed headers. Ultimately, vigilant human verification will defeat deceptive AI false front operations across global media.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!