Operation “STORM-2035”: Iran-origin influence activity
OpenAI banned Iran-origin STORM-2035 accounts using AI to generate US and UK election content and publish it across sites.
This case study was originally published in OpenAI’s October 2024(opens in a new window) report.
Actor
We banned a set of ChatGPT accounts that were generating long-form web articles and short comments in English and Spanish. We identified the comments being posted by more than a dozen fake personas on X and one on Instagram, the articles on five websites. Microsoft previously reported some of the websites under the name Storm-2035; after our disruption and resulting information share, Meta confirmed that the Instagram account was connected to an Iranian network they disrupted in December 2022. Our visibility into this actor’s behavior allowed us to connect the social media posting and the websites for the first time.
Behavior
This actor engaged in two main parallel workstreams. The first used our models to generate long-form, English-language articles—typically of 700 to 900 words—that were then posted on a set of websites. Some of the websites posed as progressives, and some posed as conservatives. They primarily focused on the United States, including with references to the presidential and vice-presidential candidates in this year’s elections.

Headlines of two articles generated by this operation and published on two of its websites. We did not see evidence of these articles being widely shared on social media.
The second workstream used our models to generate short comments that were posted on X and Instagram. Some of these comments were in English and some in Spanish. We identified one Instagram account and more than a dozen accounts on X associated with this activity. The Instagram account posed as a supporter of Scottish independence, while different X accounts posed as partisans of both main candidates in the US presidential election.

Headlines of two articles generated by this operation and published on two of its websites. We did not see evidence of these articles being widely shared on social media.

Posts about U.S. election candidates generated by this operation, posted by two different accounts on X. These posts garnered low to no engagement before the accounts were suspended.
Supporting this activity, the accounts sometimes used our models to conduct basic research, such as looking for tips on how to improve their social media engagement. One ChatGPT user also asked our model to write an article saying that Microsoft’s exposure of their operation proved that Iranian cyber operations were more impactful than those from Russia or China. We did not identify the text thus generated being posted online.
Completions
The operation generated content about several topics. Key themes included the conflict in Gaza, Israel’s presence at the Olympic Games, and the U.S. presidential election. Some English-language content referenced Scottish independence, and content in both English and Spanish referenced politics in Venezuela and the rights of Latinx communities in the U.S.

Posts about politics in Venezuela and the rights of Latinx communities in the U.S., posted by two different accounts on X. These posts garnered low to no engagement before the accounts were suspended.
Alongside this political content, the actors generated and posted generic posts about topics such as beauty and fashion, possibly to appear more authentic or in an attempt to build a following.

Posts about beauty generated by the operation in English and Spanish, posted by two different accounts on X. We ran these images through our DALL·E 3 classifier, which identified them as not being generated by our services. These posts garnered low to no engagement.
Impact
Despite the operators’ apparent spinning of their exposure, the operation does not appear to have achieved meaningful audience engagement. The majority of social media posts that we.