engblogs

summaries of the latest blog articles from your favorite tech companies.
OpenAIOpenAI

Operation “A2Z”: Multilingual influence activity

Case study of Operation A2Z: an AI-driven, multilingual influence operation that automated fake social-media personas to post political content across X and Facebook, and how its disruption revealed AI-enabled manipulation.

10/1/2024
OpenAIOpenAI

Operation “STORM-2035”: Iran-origin influence activity

Technical breakdown of Operation STORM-2035, the Iran-origin influence campaign that used AI-enabled ChatGPT accounts to generate US/UK election content and coordinated social posts across websites, X, and Instagram, illustrating dual long-form article and short-comment workflows and platform disruption.

10/1/2024
OpenAIOpenAI

Bet Bot: Gambling spam network

A technical overview of Bet Bot, a gambling-spam network that used OpenAI-enabled conversations via an Israel-based startup to create fake social-media personas on X and DM users with gambling links through a public-comment and direct-message pipeline.

10/1/2024
OpenAIOpenAI

Rwandan election content: Political commenting network

A technical breakdown of how a Rwanda-focused AI-generated partisan commenting network was detected, disrupted, and analyzed across multilingual posts and coordinated hashtag campaigns around elections.

10/1/2024
OpenAIOpenAI

STORM-0817: Iran-linked malware and scraping activity

Analysis of STORM-0817 reveals Iran-linked malware leveraging AI-assisted debugging, Android payloads, Instagram scraping, and Persian translation of profiles to inform reconnaissance and a developing command-and-control infrastructure.

10/1/2024
OpenAIOpenAI

Tort Report: Abusive reporting activity

A technical case study of OpenAI's Tort Report, detailing AI-generated abusive reporting aimed at Vietnamese public figures and independent media on Facebook and YouTube, its limited evidentiary impact, and categorization as a low-impact Category 1 operation.

10/1/2024
OpenAIOpenAI

STORM-0817: Iran-linked malware and scraping activity

Analysis of STORM-0817 reveals an Iran-based malware operation leveraging AI-assisted debugging, Instagram scraping, and Persian translation to support reconnaissance and a WAMP-based command-and-control infrastructure.

10/1/2024
OpenAIOpenAI

Corrupt Comment: Anti-corruption foundation criticism

A technical case study of an operation that used the OpenAI API to generate English-language comments criticizing Russia's Anti-Corruption Foundation (FBK), deployed via fake X accounts, with analysis of deployment patterns and impact.

10/1/2024
OpenAIOpenAI

SweetSpecter: China-linked cyber activity

An in-depth technical case study of SweetSpecter, a China-linked adversary that uses AI to research vulnerabilities, develop scripts, and execute spear-phishing, with MITRE ATT&CK-aligned LLM analysis and defense lessons from OpenAI's response.

10/1/2024
OpenAIOpenAI

CyberAv3ngers: Iran-linked cyber research activity

Explores how the Iran-linked CyberAv3ngers used AI-assisted reconnaissance and scripting to research ICS/PLCs and exploit weak credentials, highlighting implications for water, energy, and manufacturing infrastructure.

10/1/2024
OpenAIOpenAI

SweetSpecter: China-linked cyber activity

Case study of SweetSpecter, a China-linked adversary using AI to research vulnerabilities, perform spear-phishing, and map LLM-informed techniques to MITRE ATT&CK, with emphasis on threat intelligence sharing and defense implications.

10/1/2024
OpenAIOpenAI

Hoax: Fake Russian “troll” error message

Technical analysis of a hoax involving a fake ChatGPT error message attributed to a Russian troll, tracing its viral spread on social media, distinguishing AI-generated versus manually crafted content, and examining implications for AI accountability and misinformation management.

10/1/2024