# OpenAI disrupts Russian 'Dark Clark' fake-think-tank and Iranian fake-journalist AI-enabled influence operations

> OpenAI disclosed takedowns of two AI-enabled false-front influence operations. A Russian-origin cluster ('Dark Clark') ran a fake Latin American think tank, the Social Research Center, fronted by an AI persona 'Mia Clark', to target Latin American politics and damage Ukraine's reputation, including fake audio in Ecuador and Bolivia. An Iranian-linked, for-hire-style campaign used at least seven fake journalist personas to place almost 100 articles across about a dozen outlets on the U.S.-Iran war.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3055
- **ID:** TL-2026-3055
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** MONITORING
- **Actor:** Dark Clark (Russia, Iran)
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-10-08 OpenAI published 'Disrupting AI-enabled false front operations' describing two covert influence operations (IO) that used ChatGPT and other AI tools to build false-front identities: a fake think tank and fake journalists. OpenAI rated the Russian operation 5 and the Iranian operation 4 on its 6-point Breakout Scale (most campaigns it sees rate 1 or 2). CyberScoop reports it as the first time OpenAI has reported a high-impact influence campaign.

Russian-origin operation 'Dark Clark': The cluster is named for 'Mia Clark', a fabricated AI persona presented as leader of the Social Research Center (SRC), a purported Latin American think tank. Its focus was Latin American politics and culture, mainly harming Ukraine's reputation, with engagement on political issues in Argentina and Bolivia (secondary coverage also lists Ecuador, Peru and Poland and reports more than 60 original articles). OpenAI assessed that the Russian group controlled the SRC, citing ChatGPT-generated internal reports on staff wage scales and hiring and firing, and said the SRC's Latin American staff were not aware they worked for a Russian group. OpenAI called it the most complex front-identity attempt it has disrupted in two and a half years. In March a TikTok video falsely claiming the Ecuadorian government used shell companies to recruit citizens to fight for Ukraine was fact-checked by Lupa Media, and the operation also spread fake audio of the Ukrainian consul in Ecuador insulting Ecuadorians. During May anti-government protests in Bolivia it released fake audio of a state water company employee claiming a state of emergency and water cuts for La Paz; the Bolivian government denied it on Facebook. Operators also queried the model about Politology, described as a successor to the Wagner Group, far more than any other Russian organization. No specific Russian government or intelligence agency was named.

Iranian operation: Using many of the same AI tools, the operation pitched and placed articles on the U.S.-Iran war under at least seven fake journalist personas. OpenAI identified almost 100 articles published or syndicated under those bylines across about a dozen small-to-medium international-affairs, geopolitics and Middle East outlets, and the operation also generated social media comments. Secondary coverage rates article placement Category 4 and social media impact Category 2. Most stories drew little social engagement. OpenAI said the activity resembled a commercial actor running a for-hire campaign and did not attribute it to a specific actor or group. Both operations reportedly overstated their own effectiveness in internal reports. The number of banned accounts was not stated. No CVEs, malware or network IOCs were published; indicators are persona and organization names. Some persona names come from secondary coverage of the OpenAI report because the primary page was not retrievable.

## MITRE ATT&CK

- T1585.001 Social Media Accounts
- T1588.007 Artificial Intelligence
- T1583.006 Web Services
- T1684.001 Impersonation
- T1565.001 Stored Data Manipulation

## Sources

- [OpenAI says Iran, Russia used AI journalists, think tanks to influence Western media (CyberScoop)](https://cyberscoop.com/openai-disrupts-russia-iran-ai-influence-operations/)
- [Disrupting AI-enabled false front operations (OpenAI)](https://openai.com/index/disrupting-ai-enabled-false-front-operations/)
- [Disrupting AI-enabled 'false front' operations (daily.dev summary)](https://daily.dev/posts/disrupting-ai-enabled-false-front-operations-jybjurgnx)
- [Ecuadorian government official post on X denying the claim](https://x.com/GildaAlcivarOk/status/2067034085021676030)
- [Bolivian government Facebook denial of the fake water-cut audio](https://www.facebook.com/photo.php?fbid=1426877002799780&set=pb.100064324827050.-2207520000&type=3)
- [OpenAI bans accounts linked to covert Iranian influence operation (CyberScoop, 2024 precedent)](https://cyberscoop.com/openai-bans-accounts-linked-to-covert-iranian-influence-operation/)
- [OpenAI shut down an Iranian influence op that used ChatGPT to generate bogus news articles (Engadget, 2024 precedent)](https://www.engadget.com/cybersecurity/openai-shut-down-an-iranian-influence-op-that-used-chatgpt-to-generate-bogus-news-articles-202526662.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3055
