Threat reportThreat IntelligenceTL-2026-3055

OpenAI disrupts Russian 'Dark Clark' fake-think-tank and Iranian fake-journalist AI-enabled influence operations

mediumMONITORING

OpenAI disrupts Russian 'Dark Clark' fake-think-tank and (TL-2026-3055), also tracked as Dark Clark, is a medium-severity tracked intrusion set, first published 2026-10-08. It is attributed to Dark Clark (Russia, Iran) with low confidence, affects Various Online news and international-affairs outlets; social, maps to 5 MITRE ATT&CK techniques (T1565.001, T1583.006, T1585.001), and is covered by 9 detection rules and 13 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
5MITRE ATT&CK
Actors
1Dark Clark
Detection rules
9SPL · KQL · Sigma
IOCs
13Indicators of compromise

Key facts for TL-2026-3055

Threat ID
TL-2026-3055
Also known as
Dark Clark, Bogus Bylines
Severity
MEDIUM
Status
MONITORING
Category
THREAT_INTEL
First published
Last reviewed
Attribution
Dark Clark
Attribution confidence
LOW
Nation-state nexus
Russia, Iran
Motivation
UNKNOWN
Target sectors
news - media, government administration, think tanks, civil society
Target regions
Latin America, argentina, bolivia, ecuador, united states of america, Middle East
Detection rules
9
Indicators of compromise
13

Malware and tooling in OpenAI disrupts Russian 'Dark Clark' fake-think-tank and

Malware and tooling: ChatGPT

How OpenAI disrupts Russian 'Dark Clark' fake-think-tank and works

OpenAI disclosed takedowns of two AI-enabled false-front influence operations. A Russian-origin cluster ('Dark Clark') ran a fake Latin American think tank, the Social Research Center, fronted by an AI persona 'Mia Clark', to target Latin American politics and damage Ukraine's reputation, including fake audio in Ecuador and Bolivia. An Iranian-linked, for-hire-style campaign used at least seven fake journalist personas to place almost 100 articles across about a dozen outlets on the U.S.-Iran war.

On 2026-10-08 OpenAI published 'Disrupting AI-enabled false front operations' describing two covert influence operations (IO) that used ChatGPT and other AI tools to build false-front identities: a fake think tank and fake journalists. OpenAI rated the Russian operation 5 and the Iranian operation 4 on its 6-point Breakout Scale (most campaigns it sees rate 1 or 2). CyberScoop reports it as the first time OpenAI has reported a high-impact influence campaign.

Russian-origin operation 'Dark Clark': The cluster is named for 'Mia Clark', a fabricated AI persona presented as leader of the Social Research Center (SRC), a purported Latin American think tank. Its focus was Latin American politics and culture, mainly harming Ukraine's reputation, with engagement on political issues in Argentina and Bolivia (secondary coverage also lists Ecuador, Peru and Poland and reports more than 60 original articles). OpenAI assessed that the Russian group controlled the SRC, citing ChatGPT-generated internal reports on staff wage scales and hiring and firing, and said the SRC's Latin American staff were not aware they worked for a Russian group. OpenAI called it the most complex front-identity attempt it has disrupted in two and a half years. In March a TikTok video falsely claiming the Ecuadorian government used shell companies to recruit citizens to fight for Ukraine was fact-checked by Lupa Media, and the operation also spread fake audio of the Ukrainian consul in Ecuador insulting Ecuadorians. During May anti-government protests in Bolivia it released fake audio of a state water company employee claiming a state of emergency and water cuts for La Paz; the Bolivian government denied it on Facebook. Operators also queried the model about Politology, described as a successor to the Wagner Group, far more than any other Russian organization. No specific Russian government or intelligence agency was named.

Iranian operation: Using many of the same AI tools, the operation pitched and placed articles on the U.S.-Iran war under at least seven fake journalist personas. OpenAI identified almost 100 articles published or syndicated under those bylines across about a dozen small-to-medium international-affairs, geopolitics and Middle East outlets, and the operation also generated social media comments. Secondary coverage rates article placement Category 4 and social media impact Category 2. Most stories drew little social engagement. OpenAI said the activity resembled a commercial actor running a for-hire campaign and did not attribute it to a specific actor or group. Both operations reportedly overstated their own effectiveness in internal reports. The number of banned accounts was not stated. No CVEs, malware or network IOCs were published; indicators are persona and organization names. Some persona names come from secondary coverage of the OpenAI report because the primary page was not retrievable.

MITRE ATT&CK techniques used in TL-2026-3055

Impact

T1565.001 Stored Data Manipulation

Resource Development

T1583.006 Web Services; T1585.001 Social Media Accounts; T1588.007 Artificial Intelligence

Stealth

T1684.001 Impersonation

Affected products and versions in OpenAI disrupts Russian 'Dark Clark' fake-think-tank and

  • Various — Online news and international-affairs outlets; social platforms (TikTok, Facebook, X)

Remediation for OpenAI disrupts Russian 'Dark Clark' fake-think-tank and

Immediate actions

  • Treat the named personas and the Social Research Center as untrusted sources; check whether they appear in your media-monitoring or sourcing lists
  • Verify audio and video of officials and utility employees through the originating government or company channel before amplifying

Workarounds

  • Require editorial verification of unsolicited op-ed pitches from unknown contributors

Longer-term hardening

  • Add provenance checks for think-tank and freelance-journalist submissions (identity verification, byline history, outlet cross-checks)
  • Track AI-enabled influence operation reporting and share persona indicators with fact-checking networks

Timeline of OpenAI disrupts Russian 'Dark Clark' fake-think-tank and

  • Operation also spreads fake audio of the Ukrainian consul in Ecuador insulting Ecuadorians (timing not stated; placed here with the Ecuador activity)
  • A TikTok video falsely claiming the Ecuadorian government used shell companies to recruit citizens to fight for Ukraine is fact-checked by Lupa Media (month precision; exact day not stated)
  • Bolivian government publicly denies the fake audio on Facebook (month precision)
  • During anti-government protests, fake audio of a state water company employee claims a state of emergency and water cuts for La Paz (month precision)
  • CyberScoop reports the takedowns, noting OpenAI's first report of a high-impact influence campaign
  • OpenAI publishes its report on the disrupted Russian 'Dark Clark' (Breakout Scale 5) and Iranian fake-journalist (Breakout Scale 4) operations

Sources cited for OpenAI disrupts Russian 'Dark Clark' fake-think-tank and

Detection coverage for TL-2026-3055

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3055 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
13 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats