Skip to main content
OpenAI

February 1, 2025

Iranian influence nexus: Cross-platform activity

OpenAI banned Iran-linked accounts using AI to generate articles and social posts tied to IUVM and STORM-2035 influence activity.

Loading…

This case study was originally published in OpenAI’s February 2025(opens in a new window) report.

Actor

We banned five ChatGPT accounts that generated a small number of tweets and articles that were then posted on third party assets publicly linked to known Iranian influence operations. One of these operations is known as the International Union of Virtual Media, or IUVM(opens in a new window); Microsoft reported(opens in a new window) the other as STORM-2035. We disrupted and reported earlier activity by these two operations last year.

These two operations have previously been reported as separate efforts, but we found that one account that we banned was used to generate content for both of them. While small in scale, this suggests a potential previously unreported relationship, at least on the operator level.

Behavior

The ChatGPT accounts generated a range of content for different online entities linked to previously reported Iranian influence operations. Four of the five generated content that was published by entities connected to STORM-2035 by a range of analysts; the fifth generated some content published by entities publicly connected to STORM-2035, and some published by a website connected to IUVM.

One ChatGPT account used our models to generate long-form articles that were then posted on a website called al-sarira[.]com, publicly linked to STORM-2035. Two other ChatGPT accounts used our models to generate tweets that were posted by the al-Sarira domain’s X account, and by two other X accounts.

Tweets generated by Iranian influence activity.

Left, tweet generated by this network using our models and posted on X. Right, tweet generated by this network using our models and posted on X by the al-Sarira X account.

STORM-2035 is a wide-ranging operation, with websites reported by the open-source community in Arabic, French, and Spanish, as well as English. A fourth ChatGPT account used our models to generate a small number of Spanish-language articles for another website identified by public research(opens in a new window), lalinearoja[.]net.

Most notably, the fifth account used our models to generate occasional French-language texts that then featured on another website publicly linked to STORM-2035, critiquepolitique[.]com. This activity stood out for two reasons.

First, the same account also generated English-language articles that were published on another website, iuvmpress[.]co. This website is linked to IUVM, which Reuters first exposed in 2018(opens in a new window). To the best of our knowledge, public reporting had not yet identified overlaps between critiquepolitique[.]com and iuvmpress[.]co.

Second, the operator appears to have generated their articles using our models, but then to have rephrased them before publication. When we analyzed the semantic similarity between the two texts using our models, the analysis concluded that the published version was highly likely a rewrite of the version we identified. This suggests that the operator was using multiple rewrites, possibly to evade detection.

Completions

The content that these operations published was similar to that in our earlier disruptions of activity associated with IUVM and STORM-2035. It was typically pro-Palestinian, pro-Hamas and pro-Iran, and opposed to Israel and the United States. During the abrupt collapse of the regime of President Bashar al-Assad in Syria, the operation generated content that praised Assad and denied reports of his unpopularity in the country.

Some of the accounts we banned only occasionally used our models to generate content for the influence operations. More often, they asked our models to help design materials for teaching English and Spanish as a foreign language. This is of note because earlier Iranian threat activity has been publicly attributed to individuals with a background in teaching English as a foreign language.

Tweet generated by Iranian influence activity.

Tweet whose text was generated by this operation using our models.

Impact

As with previous Iranian covert influence operations focused on social media and web articles, this operation did not appear to build a substantial online following. As of January 16, 2025, the al-Sarira X account had 157 followers, even though it was following 895 accounts. Typical tweets received single-digit numbers of engagements, if any.

Using the Breakout Scale(opens in a new window) to assess the impact of IO, which rates them on a scale of 1 (lowest) to 6 (highest), we would assess this as being at the low end of Category 2 (activity on multiple platforms, but no evidence that real people picked up or widely shared their content).

Author

OpenAI