Operation "Doppelganger": Russian influence activity targeting Ukraine
OpenAI banned accounts associated with the Russia-origin operation "Doppelganger", using AI to generate anti-Ukraine social media comments, translations, and website copy across several languages.
This case study was originally published in OpenAI’s May 2024(opens in a new window) report.
Actor
We banned four clusters of accounts using our models linked to people acting on behalf of the Russian influence operation known as “Doppelganger”(opens in a new window). Each cluster displayed different tactics, techniques and procedures (TTPs), consistent with an operation made up of different functional teams.
Behavior
This activity targeted audiences in Europe and North America and focused on generating content for websites and social media.
The first cluster of accounts generated short text comments in English, French, German, Italian and Polish. These were posted on 9GAG and X alongside memes, videos, and links that do not appear to have been generated using our models. Some memes were copied from across the internet and appear to have been years old.
On 9GAG, the accounts that posted this campaign’s content typically featured profile pictures of celebrities or cats. They posted their memes and videos in a wide range of channels, including the “Random” channel and channels dedicated to pets, sports, humor, and even relationships and dating.

Comment about Ukraine, and video about Gaza, posted to 9GAG’s “Motor Vehicles” channel by an account which repeatedly posted content generated by this campaign. The reference to Ukraine and the US border was generated using our models. The video was a collage of news footage. The post received 11 upvotes and 93 downvotes.
Each time the campaign posted a meme or video on 9GAG, three to five accounts would reply, usually with simple messages such as “hahaha” or “lol”. Each of these accounts only ever engaged with this campaign’s content; most were created on the same date. This behavior often attracted critical comments from other users, many of whom called the accounts out as “bots”.

Comments on the video illustrated above. The bottom three accounts (earliest commenters) were all created in late April 2024, and repeatedly posted, upvoted or commented on this campaign’s posts and no others. The top three accounts, calling out the fakes, were created between one and ten years ago and showed a wide range of activity.
On X, the campaign’s comments were posted by accounts that typically only ever made one or two posts each. The comments were usually accompanied by an apparently random link, such as “solarpanelfor.sale”. These links redirected to a set of websites that have repeatedly been attributed to Doppelganger. The websites were geofenced, so that only people with an IP address in the target country could view them. However, the operators appear to have slipped up, so that some English, German and Polish articles could only be viewed from a French IP.

Post on X including a comment generated using our models. The comment translates as, “A shocking act! Politics should never be associated with violence. We need dialog, not violence”. The accompanying link redirects to the German-language edition of Doppelganger’s branded website, rrn.media. However, as of May 20, it could only be viewed from a French IP.
Likely in an attempt to evade detection, this cluster accessed our models using a service linked to companies in Russia and the Czech Republic. This service was aimed at allowing people in Russia to circumvent our supported countries access policy(opens in a new window). We’ve disabled this service’s API access.
The second cluster translated articles from Russian into English and French; the Russian texts appear to have been original compositions. Many of these articles were subsequently published on a website that has been repeatedly attributed to Doppelganger: rrn.media. The same cluster generated short comments about its articles that later appeared on social media.

Post on X generated using our models, alongside a link to an article on rrn.media.
The third cluster was used to generate, proofread and correct French-language articles. The articles were then published on a website that has also been attributed to Doppelganger, franceeteu.today.
The final cluster operated in German. It ingested content from a Doppelganger website, grenzezank.com, and used this to generate short posts for a Facebook Group and Page named after the website.
Content
The majority of the content that this campaign published online focused on the war in Ukraine. It portrayed Ukraine, the US, NATO and the EU in a negative light and Russia in a positive light. Typical comments argued that Russia is an important economic partner for European countries; that Western leaders who criticize Russia are out of touch with their own voters; and that Ukraine is weak, corrupt, and/or on the verge of defeat.
On some occasions, Doppelganger actors tried to get our models to generate cartoon images of prominent European politicians and critics of Russia. Our models refused these requests.
Impact assessment
None of the Doppelganger campaigns that we identified appears to have earned substantial positive engagement from authentic audiences.
On 9GAG, typical posts received 5-10 upvotes - mainly from accounts which also posted this campaign’s content - and anything from 15 to 200 downvotes. On X, typical posts had around 1,000 shares, zero replies and zero likes. This discrepancy is so wide that it suggests inauthentic amplification. One post had three replies, all of which called it out as a fake.

Reply on X to a Doppelganger post.
Using the Breakout Scale(opens in a new window) to assess the impact of IO, which rates them on a scale of 1 (lowest) to 6 (highest), we would assess the activity that was related to the use of our models as being in Category 2, marked by posting activity on multiple platforms, but with no breakout or significant audience engagement in any of them.