Operation "Spamouflage": China-linked influence activity
OpenAI banned accounts associated with the PRC-origin operation "Spamouflage", using AI to research social media activity, generate posts, and debug a previously unreported website.
This case study was originally published in OpenAI’s May 2024(opens in a new window) report.
Actor
We banned a small number of accounts associated with the China-origin operation known as “Spamouflage”(opens in a new window). This operation has been attributed by Meta(opens in a new window) to “individuals associated with Chinese law enforcement”. Some of this operation’s social media activity was attributed by the FBI(opens in a new window) to a unit within China’s Ministry of Public Security.
Behavior
This network targeted global audiences, especially members of the Chinese diaspora and critics of the Chinese government. It mainly generated content in Chinese and, to a lesser extent, English, Japanese and Korean.
The network used our models to debug code, seek advice on social media analysis, research news and current events, and generate content that was then published on blog forums and social media.
For example, in 2023 the network used our models to debug code setting the WordPress theme for a website, revealscum.com. This website published Chinese-language criticisms and personal information about members of the Chinese diaspora who criticized the Chinese government. It termed these critics “traitors”. The content itself was not generated using our models.

Screenshot of the website revealscum.com, showing the page titled “汉奸” (“traitor”). We have redacted the faces of the people targeted by this site.
This campaign also used our models to create content that was then posted on social media platforms and forums. For example, in late 2023 the operation generated articles that accused Japan of damaging the marine environment by releasing wastewater from the Fukushima power plant. We identified the articles on platforms including Medium, Blogspot, and ameblo.jp.
In April 2024, the campaign ran a series of comments in English that criticized Chinese dissident Cai Xia. We identified one X account that posted the initial comment and a cluster of other accounts that posted the rest of the comments as replies. We did not see any real accounts replying to them.

Post and replies attacking Cai Xia, where the content was generated by Spamouflage using our models. Note the lack of reposts or likes. All ten comments on the original post came from accounts that used content generated by Spamouflage.
The campaign also used our models to conduct open-source research, such as how to apply for developer accounts on social media or asking for summaries of social media posts by critics of the Chinese government.
The network’s use of artificial intelligence appears to have constituted only a minority of its overall output. For example, many of the X and Medium accounts that we identified as posting content generated by our models posted a higher volume of content that appeared to have been manually created in English and Chinese (as shown, for example, by unidiomatic use of English). They posted this content both before and after they posted AI-generated comments.

Post on April 22, 2024 by one of the accounts which posted AI-generated content on April 19. Both text and image appear to have been manually created.
Content
Much of the content generated by this campaign was in Chinese. Topics ranged from praising the Chinese government’s international law enforcement cooperation to criticizing abuses against Native Americans in the United States. Some content criticized the US government and Microsoft for exposing the activity of the Chinese hacking group known as “Volt Typhoon”.
Other content was in English. This typically criticized prominent critics of the Chinese government, such as actor and Tibet activist Richard Gere and dissident Cai Xia. A few articles generated in late 2023 in English, Japanese, Chinese, Korean and Russian accused Japan of polluting Pacific waters with the discharge from the Fukushima nuclear plant(opens in a new window)—a long-running theme of Chinese IO.
One small cluster of activity focused on generating positive comments in Chinese about a visit by China’s Minister of Public Security to Uzbekistan. This is not a theme which Spamouflage is known to have addressed before; it is of interest in the light of the FBI’s attribution(opens in a new window) of some earlier social media activity by this operation to China’s Ministry of Public Security.
Some of the network’s activity appears to have reflected the operators’ personal interests. For example, one operator used our models to research camera lenses. Another used our models to complete what appears to have been a test assignment for Chinese Communist Party members.
Impact assessment
Spamouflage has been one of the world’s most intensively researched IO since it was first publicly described in 2019(opens in a new window). Very little of its activity has ever been reported as reaching authentic audiences.
The use of AI-generated content does not appear to have changed that dynamic. Across the blogs, articles, and social media accounts that we identified as part of our investigation, none gained high numbers of engagements or follows from real people. In some cases, the available indicators show that the only views of their posts came from our investigative team.
Using the Breakout Scale(opens in a new window) to assess the impact of IO, which rates them on a scale of 1 (lowest) to 6 (highest), we would assess this as a Category 2 operation, marked by posting activity across many platforms, but with no evidence of it being significantly amplified by people outside the network.
Indicators
We identified the following domain as being associated with this campaign.
- revealscum.com