OpenAI banned a cluster of Russia-linked ChatGPT accounts that used VPNs to evade access restrictions while supporting a covert influence operation posing as the Israel-based International Burke Institute (IBI). The accounts used the model primarily to draft English-language promotional posts and replies and remove linguistic signs of Russian authorship, then distributed content through Substack, Telegram, X, Facebook, and LinkedIn.
IBI used a credible-looking website, a pro-Russian “Sovereignty Index,” and apparently copied or misattributed academic material to manufacture authority while portraying Russia favorably and criticizing Western countries. OpenAI assessed the campaign’s direct reach as low—despite affiliated Telegram channels having roughly 10,000 to 20,000 followers—but warned that its reusable infrastructure could enable a more scalable influence operation.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
OpenAI banned a cluster of ChatGPT accounts linked to a Russia-based covert influence operation promoting IBI. The operators used VPNs to evade Russian access restrictions and used ChatGPT primarily to create English-language promotional posts and comments while concealing linguistic signs of Russian authorship.
The website for the purported International Burke Institute (IBI), ibi[.]institute, was registered. The operation later used the site to present copied or misattributed academic material and pro-Russian narratives.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
9 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcetechrepublic.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcetomshardware.com
Open sourcethehackernews.com
Open sourceopenai.com
Open sourcecdn.openai.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.