Anthropic’s Threat Intelligence report, titled “Detecting and countering misuse of AI: September 2026”, details the malicious activities, threat actor behaviors, and AI exploits discovered and disrupted by their Threat Intelligence team between December 2025 and August 2026. The report builds upon previous disclosures from 2025 by shifting its focus toward the evolution of adversarial AI dependency, autonomous agent workflows, and the concept of “uplift” (how much faster, deeper, and wider attacks become when powered by generative AI). According to the report, Anthropic disrupted a distributed MEK/NCRI-aligned influence operation that used a shared AI agent to impersonate real people and recruit inside Iran. Read this part of the report:
GTG-84006: Disrupting a distributed MEK/NCRI-aligned influence operation that used a shared AI agent to impersonate real people and recruit inside Iran
We identified and removed a distributed influence operation that targeted Iranian audiences inside the country and abroad. To deceive users, the operation impersonated a real-world activist by tasking the shared AI agent to clone the activist’s personal Telegram account, then instructing it in Persian that it was now that person. The actor directed Claude to read roughly 8,400 of his Telegram posts to copy his writing style, and then used it to run live political conversations with his contacts. To our knowledge, these contacts did not know they were speaking with an AI-assisted account.
Although the actors did not share account infrastructure or show visible signs of coordination, our investigations linked this activity to People’s Mojahedin Organization of Iran (PMOI/MEK), and its political front, the National Council of Resistance of Iran (NCRI).
Our investigation showed that at least four individuals running this campaign work for official NCRI media outlets. The operation relied on staffed NCRI/MEK media properties across multiple platforms, including broadcast television, satellite and shortwave radio, Instagram, Telegram, and X/Twitter. While the presence of committee approval loops and notes about MEK leadership suggest central tasking is likely, we are not able to verify the level of centralized control.
Using the Breakout Scale, we would assess this operation as Category Two (multiple platforms, with distribution through the network’s own NCRI media properties and amplifier accounts.)
Key findings
The operation successfully scraped over 500 social media channels to build detailed profiles of individuals inside Iran. They then grouped these targets by city, age, occupation, political alignment, and arrest history likely to help them tailor their messages to the specific audiences.
The network analyzed roughly 51,944 archived messages from these conversations to build detailed psychographic dossiers on dozens of specific individuals in Iran. To spread their message further, the impersonation accounts also sent a fabricated breaking news headline to more than 30 contacts simultaneously.
To promote NCRI president Maryam Rajavi’s ten-point plan, the network created AI-generated avatars for each article. The actors animated these avatars, gave them Persian audio, and styled them to look like average Iranians, while intentionally hiding the fact that they were AI-generated.
The people behind the campaign used an automated pipeline to run networks of Instagram accounts that coordinated their posting schedules. They adjusted the content to fit different target audiences. To hide their true motives, initial posts intentionally avoided naming the Mojahedin, making the group’s propaganda look like unaffiliated, neutral news.
The operation focused its messaging on the Iranian government, monarchist groups, and the Pahlavi camp. The actors spread a fabricated video attacking a member of the Pahlavi family and used the “Neither Shah Nor Sheikh” framing against the targets. This content was designed to strengthen the MEK’s position in the Iranian opposition.
Attack lifecycle and AI usage
The network relied on Claude to support all phases of its influence operation. The actors managed these tasks using a shared AI agent platform, where each workspace maintained its own long-term memory files. Over time they updated these files with specific instructions, such as lists of banned words, approved sources, account management rules, and ways to avoid detection. This allowed the agent to keep producing content without a human user directing each session. One actor loaded MEK founding doctrine into the model’s memory as “strategic base data” for others within the operation to reuse.
The human management behind this operation was highly structured. This included an approval loop by a dedicated committee and a formal review process from content correctors to managers. Throughout their communication, the actors repeatedly used the phrase “per our contract” and made regular references to the MEK leadership. We found that the same operational playbook was applied uniformly across all workspaces.
A majority of the output was Persian-first as it swapped the organic 2022 protest slogan “Woman, Life, Freedom” for the MEK variant “Woman, Resistance, Freedom”.

Different aspects of the influence operation of the MEK using AI

One of the MEK’s distributed network bound by a shared Claude-based agent platform (named “Viktor”), spanning live impersonation, surveillance inside Iran
Disruption and mitigations
We found this activity as part of our internal investigations and banned the accounts. At this point, we are not able to independently confirm how much authentic engagement was drawn by the network’s amplification accounts.

IoCs with network handles, associated websites and dissemination accounts behind the MEK’s activity
Anthropic’s Threat Intelligence team
Read the full report at: https://www.anthropic.com/threat-intelligence-report-september-2026



