Illustration: an interwar radio-and-newsreel intelligence collage with a 1930s map of Europe and propaganda poster proofs.

Iran-linked agents used Chinese open-source models to stand up American-looking accounts so rented personas would read as U.S. political speech.

Illustration, not an archive object

Filed
September 18, 2026, 18:10 UTC
Actor
Iran-based operators of a Coordinated Inauthentic Behavior network targeting U.S. audiences, documented by Meta in August 2026 and described on 18 September 2026 by unnamed U.S. officials speaking to The New York Times as a state-backed autonomous-agent campaign using Chinese open-source models
Target
U.S. platform users, journalists, and midterm audiences asked to treat American-looking meme accounts as homegrown political speech rather than as an undeclared foreign production line
Source
Unidentified Source blurred: contractors, cutouts, buried disclosure
Confidence
high Multiple independent open sources, low disagreement about the facts
Techniques
AstroturfingSynthetic mediaManufactured consensusCard stackingDisclosure theater
Where
Iran, United States
Channels
  • Instagram, Facebook, X, and TikTok inauthentic accounts
  • Chinese open-source models driving autonomous software agents
  • New York Times, Sheera Frenkel, Eli Tan, and Dustin Volz, 18 September 2026
  • Ynet restatement of the same Times file, 18 September 2026
  • Meta H2 2026 Adversarial Threat Report, published 27 August 2026
  • Axios exclusive on the Meta Iran disruption, 27 August 2026

Summary

On 18 September 2026 The New York Times, restated the same day by Ynet, reported that Iran, China, and two Israeli private firms had begun combining downloadable Chinese open-source models with autonomous software agents that opened and posted from fake accounts on Instagram, Facebook, X, and TikTok. U.S. officials who were not authorized to speak publicly told the paper the Iranian and Chinese clusters were state-backed. Ynet's restatement said the Iranian network posed as ordinary Americans in major cities, tagged politicians and journalists, circulated anti-Republican and Israel-Palestine memes, and gathered nearly 80,000 followers in the first half of 2026. Those follower and account counts match Meta's 27 August 2026 H2 Adversarial Threat Report, which removed four Facebook and 31 Instagram accounts originating in Iran, recorded about 79,400 Instagram followers, and said some content was AI-generated. Score the Meta takedown, the 79,400 figure, and the dated NYT/Ynet method description as high. Score a named IRGC or ICCO tasking order for the agent layer, and any proof the farm moved a U.S. race, as not shown.

Analysis

The last two active briefs covered a West African commercial follow-farm aimed at Sweden and an Israeli anti-Qatar WhatsApp cell. Rotation this cycle is an Iran-attributed account farm on U.S. platforms, not another mercenary graph and not another ministry-adjacent volunteer desk.

Two records have to stay separate. Meta's H2 2026 Adversarial Threat Report, issued 27 August 2026 and previewed that day by Axios, is the primary on inventory: four Facebook accounts and 31 Instagram accounts originating in Iran, about 79,400 Instagram followers, U.S. and Canadian proxy infrastructure, personas posed as American activists and students in cities such as Washington, San Diego, and Atlanta, themes of anti-Republican memes, Israel-Palestine, and immigration, and a line that some content was AI-generated. The New York Times on 18 September 2026, restated by Ynet the same day, is the primary on method: unnamed U.S. officials and security researchers said Iran, China, and groups in Israel had begun pairing Chinese open-source models with autonomous agents that could open accounts and coordinate posts with little ongoing human handling. Ynet's Iran paragraph maps onto Meta's counts: nearly 80,000 followers, first half of 2026, ordinary-American costume, politician and journalist tags. Score those dated counts, the platform list, and the official-sourced agent description as high. Score a named ministry letterhead on the four-plus-thirty-one logins, a public model card for the agents, and any causal claim that the farm moved a U.S. primary or the November midterms as not shown.

The Times also described two Israeli private-company campaigns, one of them named by Ynet as Tel Aviv firm IntelEye, founded by former NSO employees, which Ynet said bought about 10,000 accounts, ran about 1,000, used DeepSeek, and posted both for and against Benjamin Netanyahu around Israel's election. Co-founder Maor Sellek told the Times the work was defensive research and testing. That cluster is a same-method object, not this brief's actor. Last cycle already covered an Israeli influence cell. Do not collapse IntelEye, the Meta Iran CIB, and the thinly described Chinese experiment into one operator.

Mechanism is astroturf first. Accounts that claim to be students in Atlanta are rented grassroots. Synthetic-media is the production line: models write the bios and memes; agents operate the software. Manufactured-consensus is the costume of many independent Americans arriving at the same tags. Card-stacking is the theme list Meta published: anti-Republican, Israel-Palestine, immigration in; contrary Iranian domestic constraint and named-agency disclosure out. Disclosure-theater is the American city in the bio while the attribution Meta published is actors in Iran using North American proxies.

This is propaganda on the method test where origin is an undeclared Iran-based network, form is vernacular U.S. political speech, and the design goal is to move identification so a foreign desk reads as a neighbor. Gray color does not cancel the method. Iranians arguing about Gaza or U.S. immigration under their own names is not the violation. Standing up American-looking meme accounts, then letting software post as if those people lived in San Diego, is the influence layer. A same-method test applies in reverse. A Virginia contractor that used an open-source model and a fleet of agents to pose as Tehran students, tagged Iranian officials, and sold the resulting comment stack as domestic dissent would be this brief with the cities swapped.

Literacy counter: keep three objects apart. One: the 27 August Meta inventory, the 79,400 follower count, the four-and-thirty-one account counts, the Axios persona list, and the 18 September Times/Ynet agent-and-model description. Those are records. Two: the midterm-threat sentence and the first-of-their-kind label. Those are frames. Three: the instruction that object one proves every anti-Republican meme on Instagram is IRGC product, or that object two proves AI agents are only a lab demo. If the payload is two or three, the stack is still doing method work. If the payload is one, open the Meta H2 report, the Axios 27 August item, and the Times and Ynet 18 September pieces on the same screen.

Tells

Evidence

  1. New York Times, 18 Sep 2026: Frenkel, Tan, Volz on Iran, China, and Israeli-firm autonomous-agent campaigns
  2. Ynet, 18 Sep 2026: restates Times file; Iran ~80,000 followers; IntelEye DeepSeek contrast; Meta spokesman line
  3. Meta H2 2026 Adversarial Threat Report: 4 Facebook and 31 Instagram accounts from Iran, about 79,400 followers
  4. Meta Integrity Reports hub, updated 27 Aug 2026: same Iran CIB counts and AI-content line
  5. Axios, 27 Aug 2026: Meta exclusive on Iran-linked AI meme accounts posing as U.S. activists and students

Related briefs