Plot Twist: OpenAI Uncovers a Hidden Link Between Iran's STORM-2035 and IUVM
Hi, it's Shiichan! Today I want to share a bit of detective work from one of OpenAI's misuse reports.
OpenAI NewsWhat was announced?
OpenAI's News published a new report on Iran-based influence operations. It found that one of the banned ChatGPT accounts had actually generated content for two networks that had previously been reported as separate operations: STORM-2035 and IUVM.
Why it matters
STORM-2035 and IUVM had each been reported on their own before, but nobody had found evidence linking the two together. This time, the way a single account was used revealed a possible connection between them. It's a good example of how carefully tracing how AI tools get used can surface relationships that earlier investigations missed.
What changes
By banning the accounts tied to this activity, OpenAI cut off both operations' ability to keep generating new content with ChatGPT. The discovery itself also matters: security researchers can now treat STORM-2035 and IUVM as networks that overlap rather than fully separate operations. That gives investigators a new lead to check whenever a new account or site tied to either one turns up.
Dive Deep
Here's how the banned accounts were being used:
- Account 1: generated long-form articles published on al-sarira[.]com, a site publicly linked to STORM-2035
- Accounts 2 and 3: generated tweets posted by al-Sarira's X account and two other X accounts
- Account 4: generated a small number of Spanish-language articles for a site called lalinearoja[.]net
- Account 5 (the most notable finding): generated French-language text published on critiquepolitique[.]com, a STORM-2035-linked site, while the same account also generated English-language articles published on iuvmpress[.]co, a site linked to IUVM
Interestingly, the operator doesn't seem to have published the ChatGPT-generated text as-is — they appear to have rewritten it before posting. When OpenAI used its own models to check the semantic similarity between the generated and published versions, the analysis concluded the published text was highly likely a rewrite. That suggests the operator may have used multiple rounds of rewriting to try to evade detection.
The content itself was pro-Palestinian, pro-Hamas, and pro-Iran, and critical of Israel and the United States. During the collapse of the Assad regime in Syria, the operation also produced content defending Assad and denying reports of his unpopularity. Notably, many of the banned accounts used ChatGPT more often for building English- and Spanish-teaching materials than for influence content — worth mentioning because past Iranian threat activity has been publicly linked to people with a background in teaching English as a foreign language.
As for actual reach, it stayed pretty small:
- As of January 16, 2025, the al-Sarira X account had 157 followers while following 895 accounts
- Individual tweets typically got single-digit engagement, if any
OpenAI used the Breakout Scale — a 1-to-6 scale for measuring the impact of influence operations — to rate this activity at the low end of Category 2: active across multiple platforms, but with no evidence that real people picked up or widely shared the content.
Wrap-up
- OpenAI banned ChatGPT accounts linked to the Iran-based influence operations STORM-2035 and IUVM
- Two operations previously reported as separate turned out to share at least one operator, based on how a single account was used
- Content spanned long-form articles, tweets, and Spanish- and French-language posts across multiple languages, sites, and social accounts
- The operator appears to have rewritten AI-generated text before publishing it, likely to evade detection
- Real-world reach and engagement stayed low, rated at the low end of Category 2 on OpenAI's Breakout Scale
If you're interested in how AI gets misused for influence operations, and how researchers piece together cross-platform activity, this report is worth a read!