OpenAIOperation “A2Z”: Multilingual influence activity
Case study of Operation A2Z: an AI-driven, multilingual influence operation that automated fake social-media personas to post political content across X and Facebook, and how its disruption revealed AI-enabled manipulation.
OpenAIOperation “STORM-2035”: Iran-origin influence activity
Technical breakdown of Operation STORM-2035, the Iran-origin influence campaign that used AI-enabled ChatGPT accounts to generate US/UK election content and coordinated social posts across websites, X, and Instagram, illustrating dual long-form article and short-comment workflows and platform disruption.
OpenAIBet Bot: Gambling spam network
A technical overview of Bet Bot, a gambling-spam network that used OpenAI-enabled conversations via an Israel-based startup to create fake social-media personas on X and DM users with gambling links through a public-comment and direct-message pipeline.
OpenAIRwandan election content: Political commenting network
A technical breakdown of how a Rwanda-focused AI-generated partisan commenting network was detected, disrupted, and analyzed across multilingual posts and coordinated hashtag campaigns around elections.
OpenAISTORM-0817: Iran-linked malware and scraping activity
Analysis of STORM-0817 reveals Iran-linked malware leveraging AI-assisted debugging, Android payloads, Instagram scraping, and Persian translation of profiles to inform reconnaissance and a developing command-and-control infrastructure.
OpenAITort Report: Abusive reporting activity
A technical case study of OpenAI's Tort Report, detailing AI-generated abusive reporting aimed at Vietnamese public figures and independent media on Facebook and YouTube, its limited evidentiary impact, and categorization as a low-impact Category 1 operation.
OpenAISTORM-0817: Iran-linked malware and scraping activity
Analysis of STORM-0817 reveals an Iran-based malware operation leveraging AI-assisted debugging, Instagram scraping, and Persian translation to support reconnaissance and a WAMP-based command-and-control infrastructure.
OpenAICorrupt Comment: Anti-corruption foundation criticism
A technical case study of an operation that used the OpenAI API to generate English-language comments criticizing Russia's Anti-Corruption Foundation (FBK), deployed via fake X accounts, with analysis of deployment patterns and impact.
OpenAISweetSpecter: China-linked cyber activity
An in-depth technical case study of SweetSpecter, a China-linked adversary that uses AI to research vulnerabilities, develop scripts, and execute spear-phishing, with MITRE ATT&CK-aligned LLM analysis and defense lessons from OpenAI's response.
OpenAICyberAv3ngers: Iran-linked cyber research activity
Explores how the Iran-linked CyberAv3ngers used AI-assisted reconnaissance and scripting to research ICS/PLCs and exploit weak credentials, highlighting implications for water, energy, and manufacturing infrastructure.
OpenAISweetSpecter: China-linked cyber activity
Case study of SweetSpecter, a China-linked adversary using AI to research vulnerabilities, perform spear-phishing, and map LLM-informed techniques to MITRE ATT&CK, with emphasis on threat intelligence sharing and defense implications.
OpenAIHoax: Fake Russian “troll” error message
Technical analysis of a hoax involving a fake ChatGPT error message attributed to a Russian troll, tracing its viral spread on social media, distinguishing AI-generated versus manually crafted content, and examining implications for AI accountability and misinformation management.