BETA nonprofit public democratic european moderated

Search

#TargetProfiling

IRAN: MEK/NCRI – when AI impersonated a real activist in live conversations For years, synthetic media has largely meant fabricated images, cloned voices and manipulated video. A case uncovered by Anthropic in September 2026 suggests a more consequential development: artificial intelligence being used not merely to imitate how a person looks or sounds, but to behave as that person in an ongoing conversation. Anthropic says it dismantled a distributed influence operation targeting Iranians inside the country and abroad that it linked to the People’s Mojahedin Organization of Iran, or PMOI/MEK, and its political front, the National Council of Resistance of Iran. The operators used a shared AI-agent platform to support impersonation, audience profiling, coordinated social-media activity, synthetic personas and the laundering of organisational content through apparently independent accounts. At least four people involved in the operation worked for official NCRI media outlets, according to Anthropic. The company also found references to committee approval processes and MEK leadership, but said it could not independently determine the precise level of central control. Cloning a person from 8,400 Telegram posts The most striking part of the operation involved a real activist whose Telegram identity was copied. According to Anthropic, the operators instructed Claude in Persian that it was now that person, then provided approximately 8,400 of the activist’s Telegram posts so the system could learn and reproduce his writing style. The AI-assisted account was subsequently used to conduct live political conversations with the activist’s existing contacts. Anthropic says that, to its knowledge, the people receiving those messages did not know they were interacting with an account being operated with AI assistance. This is materially different from a conventional chatbot or a static deepfake. The system was not simply producing a forged statement attributed to someone else. It was using a large archive of that person’s authentic language as behavioural training material, then applying the resulting imitation interactively. In practical terms, the deception moved from synthetic content to synthetic identity. Anthropic did not publish the identity of the impersonated activist, nor details of his contacts, and the public report does not establish what specific information the conversations produced. What it does establish is that the impersonation was operational rather than experimental: the cloned account was used in real exchanges with real people. From social-media monitoring to psychographic dossiers The impersonation sat inside a much broader targeting system. Anthropic says the network scraped more than 500 social-media channels and categorised individuals by location, age, profession, political orientation and arrest history. It then analysed approximately 51,944 archived messages from conversations to construct detailed psychographic dossiers on dozens of people inside Iran. The system was therefore not limited to broadcasting propaganda. It was also designed to understand specific audiences and individuals. Profiles could be used to decide what kind of message was most likely to resonate with a particular person, which political identity they appeared closest to and how they should be approached. Anthropic describes this as a structured targeting funnel rather than ad hoc social-media activity. That distinction is important in the Iranian context. Political activists, dissidents and opposition contacts inside Iran can face arrest and severe punishment. The report does not show that the dossiers directly led to arrests or other harm, but collecting and organising information such as arrest history and political affiliation adds a surveillance dimension to what would otherwise be described as an influence operation. A shared AI system for an influence network Anthropic found that the actors used a shared Claude-based platform named “Viktor”, with separate workspaces and persistent memory. Those memory files contained approved sources, prohibited words, account-management instructions and methods intended to reduce the risk of detection. One operator loaded MEK founding doctrine into the system as what the report called “strategic base data”, allowing others to reuse it across their work. This persistent-memory structure meant the AI did not have to be briefed from scratch for every task. Once doctrine, stylistic rules and operational constraints had been stored, the system could repeatedly produce material consistent with the network’s objectives. Anthropic says the same general playbook appeared across different workspaces despite the operators not sharing obvious account infrastructure. The network also used automated pipelines to coordinate Instagram posting schedules and tailor messages to different audiences. Some accounts initially avoided mentioning the Mojahedin at all, allowing material aligned with MEK/NCRI narratives to appear as neutral or independent political commentary. Content was distributed through the organisation’s own media ecosystem as well as accounts presented as ordinary news or activist profiles. Anthropic assessed the campaign as Category Two on its Breakout Scale: active on multiple platforms with distribution through NCRI-linked media properties and amplifier accounts, but without evidence of broad authentic penetration. Synthetic citizens and disguised organisational media The same infrastructure generated AI avatars presented as ordinary Iranians, complete with Persian audio, to promote Maryam Rajavi’s political programme. Anthropic says the synthetic nature of these personas was intentionally concealed. Operators also rewrote and redistributed content originating from MEK-affiliated media while stripping identifying features or presenting it through apparently independent accounts. The network’s political messaging targeted the Iranian government but also rival opposition currents, including monarchists and supporters of the Pahlavi camp. Anthropic documented fabricated video material attacking a member of the Pahlavi family and the use of the slogan “Neither Shah Nor Sheikh”, consistent with the NCRI’s broader competition with other opposition movements. That rivalry provides relevant context. Reuters describes the MEK as one of Iran’s principal organised opposition movements in exile and the dominant force behind the NCRI, led by Maryam Rajavi. Its relationship with other opposition currents is often contentious, while the extent of its support inside Iran remains uncertain. What can be attributed – and what cannot Anthropic’s attribution is unusually specific but still needs to be stated carefully. The company says its investigation linked the operation to MEK/NCRI and established that at least four participants worked for official NCRI media organisations. It also found a common operational playbook, committee review structures and repeated references to MEK leadership. On that basis, Anthropic said central tasking was likely. It nevertheless stopped short of saying it had proven that NCRI’s senior leadership directly ordered or managed every component of the operation. That caveat matters. The strongest public evidence supports describing GTG-84006 as a MEK/NCRI-aligned influence operation involving personnel from official NCRI media, rather than asserting that every action was directly commanded by the organisation’s top leadership. The broader significance of the case lies elsewhere. Earlier generations of synthetic media attempted to fabricate evidence: a photograph, a voice recording or a video. Here, AI was used to maintain an identity over time, remember doctrine, analyse targets and speak directly to real people while appearing to be someone they already trusted. The deepfake was no longer merely an artefact. It had become a participant in the conversation. Sources Anthropic — Countering misuse of AI: September 2026 https://www.anthropic.com/threat-intelligence-report-september-2026 AI Misuse Case Library — GTG-84006 activist impersonation case https://www.misuseofai.com/en/cases/gtg-84006-activist-impersonation/ Reuters — Who makes up Iran’s fragmented opposition? https://www.reuters.com/business/media-telecom/who-makes-up-irans-fragmented-opposition-2025-06-18/ Reuters — Iran’s divided opposition senses its moment https://www.reuters.com/world/middle-east/irans-divided-opposition-senses-its-moment-activists-remain-wary-protests-2025-06-19/ Reuters — NCRI and Maryam Rajavi https://www.reuters.com/world/middle-east/dissident-leader-abroad-urges-iranians-bring-down-khamenei-2025-06-24/ Keywords #DISINFORMED #Episode12 #Iran #MEK #PMOI #NCRI #IranianOpposition #Disinformation #InfluenceOperations #InformationWarfare #ArtificialIntelligence #AI #GenerativeAI #ClaudeAI #Anthropic #AIDeception #AIImpersonation #IdentityImpersonation #SyntheticIdentity #InteractiveDeepfake #DigitalImpersonation #PersonaCloning #BehaviouralCloning #Telegram #PsychographicProfiling #TargetProfiling #AudienceTargeting #SocialMediaManipulation #Astroturfing #SyntheticPersonas #NarrativeLaundering #CoordinatedInfluence #PoliticalInfluence #DigitalInfluence #OppositionPolitics #IranPolitics #OSINT #WRLD

Countering misuse of AI: September 2026 / Anthropic