2023–2025

AI-Enabled Influence Operations: The 2024 Disruption Reports

In May 2024 OpenAI published the first detailed account by an AI developer of covert influence operations using its models. It described five networks, run from Russia, China, Iran and Israel, that used ChatGPT-family models to write comments and articles, translate and proofread, invent persona names and bios, debug posting code, and generate replies to their own posts. Meta's report for the first quarter of 2024, Microsoft's April 2024 East Asia report and Google's January 2025 Gemini misuse report describe the same pattern from their own vantage points. The shared conclusion is the notable part: the tools made operators faster and more fluent, and did not win them audiences. OpenAI wrote that the campaigns "do not appear to have meaningfully increased their audience engagement or reach as a result of their use of our services", and described the landscape as "evolution, not revolution". This page treats the cluster as one case because the lesson is the same across all of them, and because the set spans adversary states and a commercial contractor in a Western-aligned country.

Attribution

Not one operation but a cluster of separately run networks that were each caught using commercial generative-AI tools. OpenAI's May 2024 report names five: "Bad Grammar" (Russia), "Doppelganger" (Russia), "Spamouflage" (China), the International Union of Virtual Media or IUVM (Iran), and "Zero Zeno", run by STOIC, a commercial firm in Israel. Later reports from OpenAI, Meta, Microsoft and Google add further networks from the same countries and from others.

Attributed by: OpenAI ("AI and Covert Influence Operations: Latest Trends", 30 May 2024, and later threat reports); Meta (Adversarial Threat Report, Q1 2024); Microsoft Threat Analysis Center (April 2024); Google Threat Intelligence Group (January 2025). Each company attributes only what it saw on its own services.

Confidence, in their words: In the reports' own words. OpenAI: Bad Grammar was linked "to individuals from Russia"; Doppelganger accounts were "linked to people acting on behalf of the Russian influence operation"; Spamouflage is a "China-origin operation" that "has been attributed by Meta to individuals associated with Chinese law enforcement"; IUVM is "an Iranian entity"; Zero Zeno "was operated by STOIC, a political campaign management firm in Israel". Meta says its Israel-origin network had "links to STOIC, a political marketing and business intelligence firm based in Tel Aviv". Microsoft calls Storm-1376 a Chinese Communist Party-linked actor. None of the reports publishes the underlying account data, so outside researchers cannot independently check the attributions.

Objective

Varied by network, as described in the reports. Bad Grammar posted comments on Telegram about Ukraine, Moldova, the Baltic states and U.S. politics. Doppelganger continued its long-running effort to weaken European and North American support for Ukraine. Spamouflage praised China and attacked critics of the Chinese government, including diaspora dissidents. IUVM published articles supporting Iran and criticising Israel and the United States. Zero Zeno generated content about the Gaza conflict aimed at audiences in the United States, Canada and Israel, and to a lesser extent about the Histadrut trade union federation and, from May 2024, the Indian elections. The common operational objective was to lower the cost of producing plausible text in volume and in several languages.

Target audiences

  • Telegram users in Russia, Ukraine, the United States, Moldova and the Baltic states (Bad Grammar), addressed through invented personas from both sides of the U.S. political spectrum
  • Audiences in Europe and North America (Doppelganger), in English, French, German, Italian and Polish
  • The Chinese diaspora and critics of the Chinese government worldwide (Spamouflage), in Chinese, English, Japanese and Korean; Microsoft separately describes Storm-1376 content aimed at voters in Taiwan and at divisive issues in the United States
  • Global English- and French-language readers of IUVM websites
  • People in the United States and Canada, including U.S. lawmakers whose pages were targeted with comments, plus audiences in Israel and India (Zero Zeno / STOIC). Meta says the fake accounts posed as Jewish students, African Americans and concerned citizens

Timeline

  1. 2019–2023
    The older operations in the cluster are already well known before they touch generative text tools: Spamouflage was first described publicly in 2019, IUVM in 2018, Doppelganger in 2022. Persona networks had used GAN-generated profile photos since at least December 2019.
  2. 2023
    OpenAI later reports that Spamouflage-linked accounts used its models in 2023 to debug code for a website that published personal information about Chinese dissidents; the site's content itself was not model-generated.
  3. January 2024
    Around Taiwan's presidential election, Microsoft observes Storm-1376 posting suspected AI-generated audio of Terry Gou and AI-generated memes about William Lai, which it calls the first time it has seen a nation-state actor use AI content in an attempt to influence a foreign election.
  4. February – March 2024
    DFRLab reports on a network of inauthentic accounts on X pushing pro-Israel and anti-Muslim content at Canadian and U.S. audiences. This public reporting leads Meta to the corresponding activity on its platforms.
  5. 4 April 2024
    Microsoft Threat Analysis Center publishes "Same targets, new playbooks", documenting the increased use of AI-generated media by China-linked actors and noting that its impact on audiences remains low.
  6. 29–30 May 2024
    Meta publishes its Q1 2024 Adversarial Threat Report, removing the Israel-origin network (510 Facebook accounts, 11 Pages, one Group, 32 Instagram accounts), banning STOIC and sending it a cease-and-desist letter. OpenAI publishes its report on five disrupted operations the next day.
  7. June 2024
    The New York Times reports, citing officials and documents, that Israel's Ministry of Diaspora Affairs commissioned and funded the STOIC campaign with about $2 million. The ministry denied involvement. Neither OpenAI nor Meta attributed the campaign to the Israeli government.
  8. 9 July 2024
    The U.S. Justice Department announces the disruption of a separate Russian bot farm that used AI-enabled software called Meliorator to create fictitious personas on X, seizing two domains and searching 968 accounts.
  9. October 2024
    OpenAI's update says it has disrupted more than 20 operations and deceptive networks since the start of the year, including activity touching elections in the United States, Rwanda, India and the European Union, and that it has not seen any of them attract viral engagement or build sustained audiences through its models.
  10. January – June 2025
    Google reports that Iranian, Chinese and Russian information-operations actors used Gemini for research, content generation, translation and localisation, concluding that generative AI lets them "move faster and at higher volume" rather than enabling disruptive change. OpenAI's June 2025 report describes further networks, including "Sneer Review" (China-origin), "High Five" (Philippines) and the Iran-linked STORM-2035.

Channels

  • Telegram comment sections (Bad Grammar)
  • X and 9GAG, with links redirecting to geofenced Doppelganger websites that impersonate or imitate news outlets
  • Blog platforms, forums and X (Spamouflage)
  • IUVM's own website, with small branded accounts on TikTok, VKontakte and Odnoklassniki
  • Facebook, Instagram, X, YouTube and several purpose-built websites (Zero Zeno / STOIC), including comments left under the pages of media organisations and politicians
  • Purchased engagement: Meta says the STOIC-linked network appeared to buy likes and followers from Vietnam

Techniques

Synthetic Personas at Scale

OpenAI says Zero Zeno used its models to create fictional personas and bios based on variables such as age, gender and location, and that Bad Grammar generated English comments in the voices of invented personas from different demographics on both sides of the political spectrum.

LLM Comment Flooding

Bad Grammar and Zero Zeno generated large quantities of short comments. Meta observed that many of the STOIC-linked comments were unrelated to the posts they appeared under and that real users often replied by calling them propaganda.

AI-Translated Localization

Doppelganger produced comments in English, French, German, Italian and Polish; Spamouflage in Chinese, English, Japanese and Korean; IUVM proofread English and French articles. Google reports the same translation and localisation use of Gemini.

AI-Generated News Sites

IUVM used models to write and proofread articles, headlines and website tags for its own outlet; on one occasion the published tags included the model's response message. Zero Zeno generated web articles for its branded sites.

Synthetic Profile Photos

Meta reports that threat actors continue to use GAN-generated profile photos for fake accounts and says this has not affected its ability to detect the networks behind them.

Astroturf Bots

What OpenAI calls "faking engagement": Zero Zeno and Spamouflage generated both an initial post and the replies to it, so that an entire apparent conversation was produced by the operation.

Sockpuppeting

On X, Doppelganger comments came from accounts that typically made only one or two posts each; on 9GAG the accounts that upvoted the campaign's posts had been created days earlier and engaged with nothing else.

Impersonation Accounts

Meta says the STOIC-linked accounts posed as locals in the countries they targeted, including as Jewish students and African Americans.

Typosquatting Domains

Doppelganger's long-documented core method is a network of websites spoofing legitimate news outlets; the AI-generated comments served mainly to push links toward those sites.

Deepfakes/Synthetic Media

Microsoft documents Storm-1376 using AI-generated audio, memes and video news anchors around the Taiwan election. OpenAI notes that Doppelganger asked for images of European politicians and was refused by the model.

Actors, behaviors, content

Actors. Four state-linked or state-aligned networks and one commercial contractor. Two are from Russia (one previously unreported), one from China with reported ties to law enforcement, one from Iran, and one run by an Israeli political marketing firm. The set shows that generative tools are being picked up by persistent, well-known operations and by hired firms alike, not by a new kind of actor.

Behaviors. Generating short comments in bulk; translating and correcting grammar; drafting long articles; inventing persona details; scripting fake reply threads; debugging automation code; summarising and sentiment-scoring social media posts. All five mixed AI output with older material such as hand-written text and recycled memes. OpenAI stresses the operators' errors: refusal messages posted as comments, model messages published as website tags, a Ukraine caption attached to a Gaza video.

Content. Familiar narratives in cleaner prose: Ukraine and NATO, praise of China and attacks on its critics, Iran against Israel and the United States, the Gaza war and campus antisemitism, U.S. partisan talking points from both directions. The reports do not describe any persuasion technique in the content that was new because of AI.

Did it work? What is actually known

By the vendors' own assessment, small. OpenAI rated each operation on the Breakout Scale devised by Ben Nimmo and published by Brookings in 2020, which runs from Category 1 (one platform, one community) to Category 6 (triggers a policy response or violence). Bad Grammar was rated Category 1; Doppelganger, Spamouflage, IUVM and Zero Zeno were rated Category 2, meaning activity on multiple platforms with no breakout to authentic audiences. OpenAI's details are specific: very few Bad Grammar comments received any likes or replies; Doppelganger posts on 9GAG drew 5–10 upvotes, mostly from its own accounts, against 15–200 downvotes, and its posts on X showed around 1,000 shares with zero replies and zero likes, a gap OpenAI read as inauthentic amplification; IUVM's social accounts had 10, 76 and 274 followers; one Zero Zeno YouTube channel had a single video with no views. Meta reported about 500 followers for the STOIC-linked Pages and about 2,000 for its Instagram accounts, and said it removed the network "before they were able to gain engagement among authentic communities". OpenAI's October 2024 update and Google's January 2025 report reach the same conclusion across more cases. The limits of this evidence matter. These are self-reports by companies with a commercial interest in showing both that their products are not dangerous and that their safeguards work. They cover only activity the companies detected, on their own services; operations using open-weight models run locally, or tools from less cooperative vendors, would not appear. Public engagement counts cannot capture private sharing, and the raw data is not available for independent replication. The honest summary is that the detected operations failed to build audiences and that nobody can say much about undetected ones.

How it was caught

Mostly by behaviour and by building on earlier public research, not by recognising AI-written prose. OpenAI says its investigations drew on years of work by EU DisinfoLab, Meta and Microsoft on Doppelganger, by Graphika, ASPI, Meta, Microsoft and the FBI on Spamouflage, by Mandiant and Reuters on Iranian operations, and by DFRLab on the STOIC network, and that it used its own models to speed up analysis. Meta says its investigation began from DFRLab's public reporting about activity on X and that many of the fake accounts had already been disabled by automated systems before the investigation started. Operator mistakes helped: leftover model messages in published text, accounts created days before they began voting on one another's posts, and ordinary users replying that the accounts were bots. The companies then shared indicators with one another, and OpenAI published associated domains for open-source researchers.

Lessons

  • »Production was never the bottleneck. Distribution is. A network that cannot reach real people gains little from writing faster, and the reports show volume rising without engagement following.
  • »Good grammar is no longer a signal of authenticity, and bad grammar is no longer a reliable signal of a foreign operator. Judge accounts by behaviour: age, history, whether they engage with anything else, and whether a supposed conversation consists of accounts that only talk to one another.
  • »Ordinary users did a lot of the catching. On 9GAG and Facebook, real people called the accounts out as bots and as propaganda. Healthy scepticism expressed in replies is a form of community defence.
  • »Covert influence is also a commercial service. One of the five cases was a private firm working for a client, in a country allied with the West. Assuming that operations only come from adversary states leads to blind spots.
  • »Read vendor reports as valuable but interested evidence. They are the best public record available, and they are written by the companies whose products were misused. Look for cases where independent researchers, such as DFRLab on STOIC, reached similar findings separately.
  • »Proportion is part of literacy. Predictions that AI would swamp the 2024 elections with persuasive fakes were not borne out in the documented record. Overstating the threat feeds the liar's dividend by teaching people that nothing can be trusted.
  • »The record dates quickly. Models, tools and tactics in this area change within months, so any summary, including this one, should be read with its review date in mind.

Still contested

  • This page needs re-review every few months. It reflects reports available on 21 September 2026; the companies publish new threat reports several times a year, and a single later case of an AI-enabled operation that did break out would change the assessment.
  • Whether "no breakout" means "no effect". The Breakout Scale measures observable spread across platforms and communities, not persuasion. Low public engagement does not rule out effects on the small number of people who saw the content, though no report presents evidence of such effects.
  • How representative the detected cases are. Critics note a survivorship problem: the operations in these reports are the ones clumsy enough to be caught on monitored commercial services. Capable actors may use self-hosted open models that no vendor can observe.
  • Who was behind Zero Zeno. OpenAI and Meta attribute it to the firm STOIC and go no further. The New York Times reported in June 2024 that Israel's Ministry of Diaspora Affairs funded it; the ministry denied this. No platform report confirms or refutes government sponsorship.
  • Whether the productivity gains will compound. The reports describe 2024-era use as incremental. Later research on AI persuasion (for example Hackenburg and colleagues in Science, December 2025) finds that models tuned for persuasion are measurably more persuasive and less accurate, which suggests the ceiling may be higher than the 2024 cases reached. That is a finding about capability in experiments, not about observed operations.
  • Whether vendor self-reporting is adequate oversight. There is no independent audit of what the companies detect or miss, and the reports are selective about which cases are described.

Sources

  1. OpenAI, Disrupting deceptive uses of AI by covert influence operations, with the report "AI and Covert Influence Operations: Latest Trends" (30 May 2024)
    The five named operations and their attribution wording, the uses made of the models, the attacker and defender trends, operator errors, per-operation engagement figures, the Breakout Scale ratings, and the credit given to earlier researchers.
  2. Meta, Adversarial Threat Report, First Quarter 2024 (May 2024)
    The Israel-origin network and its link to STOIC, account and follower counts, impersonated identities, likely AI-generated comments, purchased engagement, the role of DFRLab reporting, and Meta's statement that it had not seen GenAI-driven tactics that impede its ability to disrupt networks, including continued use of GAN profile photos.
  3. Microsoft Threat Analysis Center, Same targets, new playbooks: East Asia threat actors employ unique methods (April 2024)
    Storm-1376 (Spamouflage) use of AI-generated audio, memes and video around Taiwan's January 2024 election, and its scale across websites and languages.
  4. Microsoft On the Issues, China tests US voter fault lines and ramps AI content to boost its geopolitical interests (4 April 2024)
    Microsoft's summary of the same findings, including that this was the first nation-state use of AI content it had seen aimed at a foreign election.
  5. OpenAI, Influence and cyber operations: an update (October 2024)
    More than 20 operations disrupted in 2024, the election-related cases, and the finding that none attracted viral engagement or built sustained audiences through use of the models.
  6. OpenAI, Disrupting malicious uses of AI: June 2025
    Later named cases including Sneer Review, High Five and STORM-2035, showing the pattern continuing into 2025.
  7. Google Threat Intelligence Group, Adversarial Misuse of Generative AI (29 January 2025)
    Use of Gemini by Iranian, Chinese and Russian information-operations actors for research, content generation, translation and localisation, and the conclusion that generative AI lets actors move faster and at higher volume without breakthrough capabilities.
  8. Ben Nimmo, The Breakout Scale: Measuring the impact of influence operations (Brookings Institution, September 2020)
    The six-category scale OpenAI used to rate impact, and what Categories 1 and 2 mean.
  9. U.S. Department of Justice, Justice Department Leads Efforts to Disrupt Covert Russian Government-Operated Social Media Bot Farm (9 July 2024)
    The Meliorator bot farm as a contemporaneous government-documented case of AI-generated personas.
  10. NPR, How Israel tried to use AI to covertly sway Americans about Gaza (9 July 2024)
    Independent reporting on the STOIC campaign, the New York Times account of Ministry of Diaspora Affairs funding, and the ministry's denial.
Last reviewed Suggest a correction