- Filed
- September 11, 2026, 08:00 UTC
- Actor
- Islamic Culture and Communications Organization (ICCO), Islamic Propaganda Office of Khorasan Razavi (Mashhad cognitive-warfare command room), and Bina Cultural Observatory (Islamic Propaganda Organization), operating on behalf of Iranian state propaganda structures including IRGC-aligned channels
- Target
- Iranian domestic audiences, diaspora communities, Arabic/Urdu/Malay/Spanish/English-language publics, and Western information environments whose perceptions of Iran, the IRGC, the US-Israel conflict, and religious minorities the campaigns sought to shape
- Source
- Unidentified Source blurred: contractors, cutouts, buried disclosure
- Confidence
- high Multiple independent open sources, low disagreement about the facts
- Techniques
- Narrative launderingSynthetic mediaManufactured consensusAstroturfingTestimonial
- Where
- Iran, United States, Israel, Middle East
- Channels
- Anthropic Claude (Haiku/Sonnet/Opus) for planning, doctrine, persona generation and content drafting
- Iranian platforms (Eitaa, Bale, Rubika) and paid amplification on 100+ IRGC-aligned channels
- X/Twitter, Instagram, Telegram, TikTok, YouTube
- ICCO cultural-attaché network
- false attribution to Western think tanks (CSIS, Brookings, RAND)
Summary
Anthropic’s 10 September 2026 threat-intelligence report documents three Iranian state-aligned accounts (GTG-34001) that used Claude between late 2025 and August 2026 to construct influence operations. The accounts were tied to the Islamic Culture and Communications Organization (ICCO) under the Ministry of Culture and Islamic Guidance, the Islamic Propaganda Office of Khorasan Razavi operating a Mashhad seminary cognitive-warfare command room, and the Islamic Propaganda Organization’s Bina Cultural Observatory. Operators generated doctrine manuals, persona systems, target databases, ministerial portfolios, and multi-language content while engineering attribution laundering so state narratives appeared as independent or Western-sourced commentary. During the 2026 US-Israel-Iran conflict window the Bina-linked actor produced messaging in the voice of an IRGC spokesperson and falsely attributed claims to CSIS, Brookings, and RAND. Accounts used VPNs and foreign numbers to bypass Iran blocks; Anthropic banned them and shared indicators.
Analysis
Primary source is Anthropic’s ‘Detecting and Countering Misuse of AI: September 2026’ report (published 10 September 2026), case GTG-34001. Anthropic’s Threat Intelligence team identified three accounts whose operators explicitly named their institutions, locations and roles in conversation; institutionally branded document footers and open-source corroboration of named individuals confirmed the links. Access was obtained via VPNs and foreign phone numbers because Claude is blocked inside Iran. The operators described their work as ‘soft war’ or ‘cognitive warfare’ and tied it to the official doctrine of Jihad al-Tabyin (explanatory jihad). Claude was used as an administrative and production layer: doctrine manuals, persona systems, target databases, ministerial nine-part international portfolios, and even funeral-planning documents for the Supreme Leader. Content was generated in Farsi, Arabic, Urdu, Malay, Spanish and English with plans for twenty languages. Attribution laundering was deliberate—state bulletins were rewritten to appear as independent citizen or foreign-journalist commentary; hashtag campaigns were designed to look organic. One Bina-linked actor generated official-voice IRGC spokesperson messaging and, during the 2026 conflict window, inserted false citations to CSIS, Brookings and RAND so that Iranian claims would travel with Western institutional prestige.
Mechanism: narrative-laundering is load-bearing. The operational goal is to move the same IRGC-aligned frames through surfaces the audience trusts more than overt Iranian state media. Synthetic-media supplies the volume and multi-language capacity that a small staffed office could not sustain. Astroturf and manufactured-consensus appear in the persona systems and the multi-province ‘Manjanegh’ content factory that repackaged security-service reporting under dozens of activist personas without institutional labels, then amplified them via paid campaigns on more than 100 channels. Testimonial is present in the false Western-think-tank attributions. The color is gray: ultimate Iranian state linkage is recoverable from Anthropic’s telemetry and open-source corroboration, yet the content surfaces that reach audiences omit that provenance.
This qualifies as propaganda and an influence operation because origin is concealed, institutional form (independent commentary, Western research) is performed, and the design goal is durable shaping of foreign and domestic information environments rather than transparent advocacy under an Iranian government byline. Technique scoring remains actor-agnostic: identical AI-assisted persona factories, attribution stripping, and prestige-laundering via false citations appear across multiple state and commercial campaigns documented in the same Anthropic report and in prior FRAME briefs.
Literacy counter: when multi-language content on contested geopolitics suddenly appears under activist or independent-journalist personas, or when Iranian claims arrive carrying citations to Western institutes, check for institutional branding, named staff, physical addresses, and any AI-production tells. Prefer primary Iranian government statements, named scholars with verifiable affiliations, and independent local reporting. Demand that provenance tags travel with every extracted paragraph or social post. Apply the identical laundering and synthetic-media test to every faction’s AI-augmented influence pipelines—the method does not change with the flag.
Tells
- AI-generated multi-language content that strips institutional attribution and presents state bulletins as independent or foreign-journalist voices
- False citations to Western think tanks (CSIS, Brookings, RAND) attached to Iranian claims
- Persona systems and activist-looking accounts that amplify IRGC-aligned frames without disclosing links
- Use of VPNs and foreign phone numbers to access blocked AI services from inside Iran
- Explicit internal language of ‘cognitive warfare’, ‘soft war’ or Jihad al-Tabyin in planning documents
Evidence
- Anthropic: Detecting and Countering Misuse of AI – September 2026 (GTG-34001 section)
- Anthropic PDF report download (primary document)
- Iran International: Iran state-aligned accounts used Claude to push IRGC narratives (10 Sep 2026)
- Ctech: The chatbot in the middle of the Israel-Iran shadow war (10 Sep 2026)