OpenAI Disrupts Operation VAGue Focus Influence Activity

OpenAI has disrupted "Operation VAGue Focus," a network of ChatGPT accounts used to generate social media content, translate messages, and conduct social engineering attempts. The operation utilized AI to create personas posing as European or Turkish professionals to collect intelligence and influence online discourse.

Threat Actor Profile and Attribution

OpenAI identified a small network of ChatGPT accounts that operated primarily during mainland Chinese business hours and prompted the models in Chinese. These actors used the models to create front organizations to facilitate intelligence collection and analysis.

Three primary entities were used as covers for these activities:

  • Focus Lens News: Described as an independent European-based analysis and reporting entity.
  • BrightWave Media Europe: A geopolitically focused front.
  • Visionary Advisory Group (VAG): A geopolitical consulting service purportedly located in Turkey.

Operational Workstreams

Operation VAGue Focus utilized ChatGPT across four primary functional areas to support its covert activities:

1. Covert Influence and Persona Creation

Actors used the models to generate social media posts and biographies for online personas. These personas posed as journalists and geopolitical analysts on X (formerly Twitter) to distribute content and establish credibility.

2. Political Correspondence

The accounts were used to polish and translate correspondence addressed to a US Senator regarding the nomination of an Administration official. OpenAI noted that it cannot independently confirm if this correspondence was actually sent.

3. Cyber Tool Inquiry

The actors queried the models for basic information regarding computer network attack and exploitation tools. OpenAI reports that the models provided only general explanations, and the actors' questions lacked sophistication, suggesting a low level of technical expertise in cyber operations.

4. Social Engineering and Intelligence Extraction

ChatGPT was used to translate messages from Chinese to English designed to engage and extract information from unknown targets. These included:

  • Public replies to researchers and journalists on social media.
  • Direct messages intended for private outreach.
  • Offers of compensation (up to $2,000 per hour) for interviews regarding U.S. economic and financial policies.
  • Offers to pay for classified documents.

Technical Indicators and Intelligence Collection

The operation's intelligence collection efforts focused on posing as professionals in Europe or Turkey. While the Visionary Advisory Group (VAG) website featured Turkish and English versions, a technical slip revealed the actor's origin: the Chinese characters for "contact us" (聯絡) appeared in the English version's menu, marking the only Chinese text on the entire domain.

Additionally, the actors claimed the operation used machine learning, natural language processing, and automated data scraping to identify influential social media voices and topics, though OpenAI could not independently verify these claims.

Assessment of Impact

OpenAI assesses the public-facing portion of this operation as having low impact. Using the Brookings Institution's Breakout Scale for influence operations, the activity is categorized as Category 2 (Low End), meaning that while activity occurred across multiple platforms, there was little evidence that real people widely shared or engaged with the content.

Most affiliated social media accounts failed to gain significant authentic engagement. One account associated with Focus Lens News had 17,000 followers, but OpenAI noted this account was likely compromised and repurposed, as it had been created in 2014, remained silent for a decade, and only became active again in mid-2024.

Sources