Threat reportThreat IntelligenceTL-2026-3055
OpenAI disrupts Russian 'Dark Clark' fake-think-tank and Iranian fake-journalist AI-enabled influence operations
OpenAI disrupts Russian 'Dark Clark' fake-think-tank and (TL-2026-3055), also tracked as Dark Clark, is a medium-severity tracked intrusion set, first published 2026-10-08. It is attributed to Dark Clark (Russia, Iran) with low confidence, affects Various Online news and international-affairs outlets; social, maps to 5 MITRE ATT&CK techniques (T1565.001, T1583.006, T1585.001), and is covered by 9 detection rules and 13 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 5MITRE ATT&CK
- Actors
- 1Dark Clark
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 13Indicators of compromise
Key facts for TL-2026-3055
- Threat ID
- TL-2026-3055
- Also known as
- Dark Clark, Bogus Bylines
- Severity
- MEDIUM
- Status
- MONITORING
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution
- Dark Clark
- Attribution confidence
- LOW
- Nation-state nexus
- Russia, Iran
- Motivation
- UNKNOWN
- Target sectors
- news - media, government administration, think tanks, civil society
- Target regions
- Latin America, argentina, bolivia, ecuador, united states of america, Middle East
- Detection rules
- 9
- Indicators of compromise
- 13
Malware and tooling in OpenAI disrupts Russian 'Dark Clark' fake-think-tank and
Malware and tooling: ChatGPT
How OpenAI disrupts Russian 'Dark Clark' fake-think-tank and works
OpenAI disclosed takedowns of two AI-enabled false-front influence operations. A Russian-origin cluster ('Dark Clark') ran a fake Latin American think tank, the Social Research Center, fronted by an AI persona 'Mia Clark', to target Latin American politics and damage Ukraine's reputation, including fake audio in Ecuador and Bolivia. An Iranian-linked, for-hire-style campaign used at least seven fake journalist personas to place almost 100 articles across about a dozen outlets on the U.S.-Iran war.
On 2026-10-08 OpenAI published 'Disrupting AI-enabled false front operations' describing two covert influence operations (IO) that used ChatGPT and other AI tools to build false-front identities: a fake think tank and fake journalists. OpenAI rated the Russian operation 5 and the Iranian operation 4 on its 6-point Breakout Scale (most campaigns it sees rate 1 or 2). CyberScoop reports it as the first time OpenAI has reported a high-impact influence campaign.
Russian-origin operation 'Dark Clark': The cluster is named for 'Mia Clark', a fabricated AI persona presented as leader of the Social Research Center (SRC), a purported Latin American think tank. Its focus was Latin American politics and culture, mainly harming Ukraine's reputation, with engagement on political issues in Argentina and Bolivia (secondary coverage also lists Ecuador, Peru and Poland and reports more than 60 original articles). OpenAI assessed that the Russian group controlled the SRC, citing ChatGPT-generated internal reports on staff wage scales and hiring and firing, and said the SRC's Latin American staff were not aware they worked for a Russian group. OpenAI called it the most complex front-identity attempt it has disrupted in two and a half years. In March a TikTok video falsely claiming the Ecuadorian government used shell companies to recruit citizens to fight for Ukraine was fact-checked by Lupa Media, and the operation also spread fake audio of the Ukrainian consul in Ecuador insulting Ecuadorians. During May anti-government protests in Bolivia it released fake audio of a state water company employee claiming a state of emergency and water cuts for La Paz; the Bolivian government denied it on Facebook. Operators also queried the model about Politology, described as a successor to the Wagner Group, far more than any other Russian organization. No specific Russian government or intelligence agency was named.
Iranian operation: Using many of the same AI tools, the operation pitched and placed articles on the U.S.-Iran war under at least seven fake journalist personas. OpenAI identified almost 100 articles published or syndicated under those bylines across about a dozen small-to-medium international-affairs, geopolitics and Middle East outlets, and the operation also generated social media comments. Secondary coverage rates article placement Category 4 and social media impact Category 2. Most stories drew little social engagement. OpenAI said the activity resembled a commercial actor running a for-hire campaign and did not attribute it to a specific actor or group. Both operations reportedly overstated their own effectiveness in internal reports. The number of banned accounts was not stated. No CVEs, malware or network IOCs were published; indicators are persona and organization names. Some persona names come from secondary coverage of the OpenAI report because the primary page was not retrievable.
MITRE ATT&CK techniques used in TL-2026-3055
Impact
T1565.001 Stored Data Manipulation
Resource Development
T1583.006 Web Services; T1585.001 Social Media Accounts; T1588.007 Artificial Intelligence
Stealth
Affected products and versions in OpenAI disrupts Russian 'Dark Clark' fake-think-tank and
- Various — Online news and international-affairs outlets; social platforms (TikTok, Facebook, X)
Remediation for OpenAI disrupts Russian 'Dark Clark' fake-think-tank and
Immediate actions
- Treat the named personas and the Social Research Center as untrusted sources; check whether they appear in your media-monitoring or sourcing lists
- Verify audio and video of officials and utility employees through the originating government or company channel before amplifying
Workarounds
- Require editorial verification of unsolicited op-ed pitches from unknown contributors
Longer-term hardening
- Add provenance checks for think-tank and freelance-journalist submissions (identity verification, byline history, outlet cross-checks)
- Track AI-enabled influence operation reporting and share persona indicators with fact-checking networks
Timeline of OpenAI disrupts Russian 'Dark Clark' fake-think-tank and
- Operation also spreads fake audio of the Ukrainian consul in Ecuador insulting Ecuadorians (timing not stated; placed here with the Ecuador activity)
- A TikTok video falsely claiming the Ecuadorian government used shell companies to recruit citizens to fight for Ukraine is fact-checked by Lupa Media (month precision; exact day not stated)
- Bolivian government publicly denies the fake audio on Facebook (month precision)
- During anti-government protests, fake audio of a state water company employee claims a state of emergency and water cuts for La Paz (month precision)
- CyberScoop reports the takedowns, noting OpenAI's first report of a high-impact influence campaign
- OpenAI publishes its report on the disrupted Russian 'Dark Clark' (Breakout Scale 5) and Iranian fake-journalist (Breakout Scale 4) operations
Sources cited for OpenAI disrupts Russian 'Dark Clark' fake-think-tank and
- OpenAI says Iran, Russia used AI journalists, think tanks to influence Western media (CyberScoop)
- Disrupting AI-enabled false front operations (OpenAI)
- Disrupting AI-enabled 'false front' operations (daily.dev summary)
- Ecuadorian government official post on X denying the claim
- Bolivian government Facebook denial of the fake water-cut audio
- OpenAI bans accounts linked to covert Iranian influence operation (CyberScoop, 2024 precedent)
- OpenAI shut down an Iranian influence op that used ChatGPT to generate bogus news articles (Engadget, 2024 precedent)
Detection coverage for TL-2026-3055
As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3055 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.