OpenAI busts China's 'Spamouflage' op using its own AI to debug smear sites
Curated by the Inblix editorial team
OpenAI has pulled back the curtain on a China-linked influence operation that was using its models not just to churn out propaganda, but for the grimier work of debugging websites designed to dox critics. The network, widely known as “Spamouflage” and previously tied by the FBI to a unit within China’s Ministry of Public Security, had its accounts banned. It’s a fascinating look at how a massive state-run influence machine is experimenting with AI—and where it still falls flat.
The operation’s use of ChatGPT was oddly practical. In 2023, actors used it to debug code for a WordPress site called revealscum.com, a platform that published the personal information of Chinese diaspora members it branded as “traitors.” They also leaned on the models for open-source research, asking for summaries of social media posts by government critics and researching how to apply for developer accounts. The content itself, OpenAI notes, wasn’t generated entirely by AI; the network produced a high volume of manually written, often unidiomatic English posts alongside the machine-made material.
What did the AI actually write? A mix of predictable talking points. The operation generated articles accusing Japan of marine pollution from the Fukushima wastewater release, a long-running theme in Chinese information operations, and posted them to platforms like Medium and Blogspot. In April 2024, it ran a coordinated English-language smear campaign against Chinese dissident Cai Xia, with one X account posting an initial comment and a cluster of others replying in a hollow echo chamber—OpenAI saw zero real users engaging with the thread.
Here’s the kicker: despite being one of the most intensively researched influence operations since 2019, Spamouflage’s AI-augmented push still failed to gain traction. OpenAI’s impact assessment is brutal. Using the Breakout Scale, the company found that none of the identified blogs or social media accounts gained meaningful engagement from authentic audiences. In some cases, the only views came from OpenAI’s own investigators. It’s a stark reminder that generating text is easy; generating influence is a different beast entirely. The discovery of positive posts about a Chinese Public Security Minister’s trip to Uzbekistan—a new theme for the group—does suggest the operation is taking orders to diversify, even if no one’s listening.
💡 Key Takeaways
- Spamouflage used OpenAI's models to debug the code for a doxxing website targeting Chinese diaspora critics, not just for generating social media spam.
- Despite integrating AI, the operation's posts saw virtually zero authentic engagement, with most views coming only from OpenAI's investigative team.
- The network mixed AI-generated content with a higher volume of manually written, often unidiomatic posts, treating the models as just one tool in its kit.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.