Operation “Sneer Review”: China-origin influence activity
OpenAI banned accounts using AI to generate posts criticizing a Taiwanese social media influencer and related US topics.
This case study was originally published in OpenAI’s June 2025(opens in a new window) report.
Actor
We banned ChatGPT accounts that we detected using our models to bulk generate social media posts consistent with the activity of a covert influence operation. Over the course of our investigation, we also observed these accounts drafting internal performance reviews.
These accounts primarily issued prompts in Chinese and focused on political and geopolitical topics relevant to China. One user stated in a prompt that they worked for the Chinese Propaganda Department; however, we do not have independent evidence to verify this claim.
Behavior
The accounts that we banned engaged in two primary workstreams. The most prolific involved generating short social media comments in English and Chinese, with a few in Urdu. We identified many of these comments being posted on TikTok and X, with some additional content appearing on Reddit, Facebook, and various websites.
A typical pattern involved posting an initial comment from a “main” account, often apparently created solely for that post, followed by a series of reply comments from other accounts. This behavior appeared designed to create a false impression of organic engagement.

TikTok post titled “Shutting down #USAID is just the #BEGINNING!” associated with this activity. The name of the channel, the text of the video subtitles, and all the comments visible in this screenshot, were generated by this network using ChatGPT.
On TikTok, the commenting accounts used screen names in a variety of languages and alphabets, often unrelated to the language of the content they posted. For example, an account with a Korean name posted a comment in Urdu, while accounts with Thai and Hebrew names posted comments in English that were generated by this network. On X, commenting accounts typically used cartoon profile images and, in some cases, had names associated with cryptocurrency.

Tweet and comments replying to it, all generated by this network using ChatGPT.
The network was less active on Facebook. Its activity primarily involved generating names and profile pictures for two Pages that posed as news outlets. Neither Page had any followers or likes, and each featured only a handful of posts.

Facebook post sharing a video that we identified as likely linked to this operation.
The network occasionally generated longer-form posts in Chinese or English. We identified one such post on Reddit and two others on various web forums. The second workstream consisted of using ChatGPT to generate what appear to have been internal policy or performance review documents.
Completions
The social media content generated by this threat actor covered a range of topics, all closely aligned with China’s geostrategic interests.
Some content focused on Taiwan, specifically targeting “Reversed Front”(opens in a new window) (“逆統戰”), a Taiwan-centric video and board game that imagines resistance against the Chinese Communist Party. The network generated dozens of critical comments in Chinese about the game, followed by a long-form article claiming it had received widespread backlash. This was the operation’s most distinctive activity: on this basis, we have dubbed this operation “Sneer Review.”
Other content, in English and Urdu, targeted Pakistani activist Mahrang Baloch, who has publicly criticized China’s investments in Balochistan(opens in a new window). A TikTok account and Facebook Page linked to the network posted a video falsely accusing Baloch of appearing in a pornographic film. The operation then generated hundreds of short comments in both languages to simulate widespread engagement.

Shocked comments on the Mahrang Baloch TikTok video.
A final set of content centered on the closure of the U.S. Agency for International Development (USAID), generating short comments that either praised or criticized the move. These comments were posted on TikTok and X.

Tweets tying the question of aid to the question of tariffs, generated by this network using ChatGPT.
Finally, the threat actors used our models to generate what appear to have been internal documents, including a detailed essay written in the style of an official public security document and a performance review describing the steps taken to establish and run the operation.
Impact
This operation appears to have been in its infancy when we disrupted its use of our models. Neither Facebook Page had any followers. On Reddit, one post received 44 upvotes, while two others were blocked or removed from the subreddits where they posted.

Screenshot of a post by a Reddit account we identified as part of this network, showing that it was removed by the platform’s filters.
Engagement on X and TikTok was more varied; the two TikTok videos amassed a combined 25,000 likes, while tweets by this operation’s main account typically received around 10,000 views each. However, many of the comments on these posts were generated by this network using ChatGPT, indicating at least some inauthentic engagement. All engagement figures should thus be treated with caution.
Using the IO impact Breakout Scale(opens in a new window), we would assess this as being at the low end of Category 3 if the figures for engagement on X and TikTok were authentic. We would revise this downwards if more evidence emerged to support the hypothesis that the majority of likes and views, like the majority of comments, were inauthentic.