shiichan

Who's Behind the Fake Journalists? OpenAI Disrupts ChatGPT-Powered Influence Operation "VAGue Focus"

Hi, it's Shiichan! Today I've got a bit of a dramatic one: an OpenAI report on a covert influence network it caught misusing ChatGPT.

OpenAI News openai.com

What was announced?

OpenAI's News reported that it banned a small network of accounts that had been misusing ChatGPT. The accounts prompted the models in Chinese and were mostly active during mainland Chinese business hours.

They used ChatGPT to generate social media posts, analyze datasets, and translate emails and messages from Chinese to English that resembled attempts at social engineering. The generated text purported to come from employees of three geopolitically focused entities: "Focus Lens News," "BrightWave Media Europe," and "Visionary Advisory Group" (VAG). The threat actors themselves described these entities as fronts for intelligence collection and analysis, which is why OpenAI named the operation "VAGue Focus" after them.

Why it matters

Most influence operations we've seen so far mainly flood social media with articles and comments to try to sway public opinion. This one is a bit different: the actors impersonated journalists and analysts to make direct contact, dangling paid interviews and offers to buy classified documents. That's less about broadcasting content and more about using AI's translation and writing skills to support social engineering and intelligence gathering aimed at real people.

What changes

With the accounts banned, this network can no longer generate new content through ChatGPT. But it doesn't look like the operation was landing many punches to begin with.

The social media accounts tied to this activity didn't pick up much genuine engagement. The one account with a real following, Focus Lens News on X, had 17,000 followers, but the account was originally created under a different name back in November 2014, posted for just three days, and then went silent until mid-2024. That pattern is typical of a compromised account that's been repurposed, so OpenAI cautions against reading too much into that follower count.

Using the Breakout Scale, a framework for measuring how far influence operations spread, OpenAI assessed the public-facing part of this operation as being at the low end of Category 2: active across multiple platforms, but with little evidence that real people picked up or widely shared the content. There wasn't enough evidence to assess the impact of the operation's social engineering and other covert activity.

Dive Deep

The network ran four main workstreams.

  • Fake persona posts and bios: Generating social media posts and biographies for online personas posing as journalists and geopolitical analysts, distributed through X accounts impersonating them
  • Correspondence to a US Senator: Polishing and translating letters addressed to a US Senator about the nomination of an Administration official (OpenAI couldn't confirm whether any of it was actually sent)
  • Basic cyberattack tool questions: Asking basic questions about computer network attack and exploitation tools, to which ChatGPT only gave general explanations — a sign of relatively low technical sophistication compared to the more advanced cyber actors elsewhere in the report
  • Outreach message translation: Translating Chinese messages designed to engage with and extract information from unknown people, some posted as public replies to journalists and researchers, others resembling direct messages that didn't turn up in online searches

One of the network's targets, Visionary Advisory Group (VAG), presented itself on its website as a Turkey-based geopolitical consulting firm. Instructions translated through ChatGPT included offers of $2,000 an hour for interviews about US economic and financial policy, as well as offers to pay for classified documents. Interestingly, VAG's website has Turkish and English versions, and the Chinese characters for "contact us" (聯絡) were still visible in the English version's menu — the only Chinese text found anywhere on the domain. Small slip-ups like that are what end up giving these operations away.

Some of the network's promotional material also claimed the operation used machine learning, natural language processing, and automated data scraping to identify influential voices and topics on social media — a claim OpenAI says it couldn't independently verify.

Wrap-up

  • OpenAI banned a small network of accounts, dubbed "VAGue Focus," that misused ChatGPT in Chinese
  • It was used to generate posts for fake journalist and analyst personas, translate correspondence to a US Senator, and translate outreach messages meant to extract information
  • One target, VAG Group, offered $2,000 an hour for interviews and offered to buy classified documents
  • The one X account with a large following showed signs of being a compromised, repurposed account, and real spread was limited
  • OpenAI rated the operation at the low end of Category 2 on the Breakout Scale, though there wasn't enough evidence to assess the impact of its social engineering activity

If you're curious about AI-powered influence operations and social engineering tactics, this report is worth a read!