Meta disrupted an Iran-linked influence operation that used artificial intelligence to impersonate American activists and flood Instagram with anti-Republican memes, the company disclosed August 27 in its semiannual threat report. The network; 35 accounts across Facebook and Instagram, posed as U.S.-based students, graphic designers, and activists in Washington D.C., San Diego, and Atlanta while accumulating approximately 79,400 Instagram followers.
Operators used AI to generate memes targeting Republican politicians, promote messaging on the Israel-Palestine conflict, and push content on immigration—all while routing their traffic exclusively through U.S. and Canadian proxy servers to mask their Iranian origins. The operation represents a sophisticated escalation: combining AI-generated content with carefully constructed American personas and aggressive outreach to journalists and politicians.
The Fake Americans
The Iran-based operators created detailed fictitious identities—activists campaigning for social justice, students engaged in campus politics, graphic designers producing political art. Each persona claimed residence in major American cities and maintained what appeared to be authentic civic meme accounts. The accounts tagged real journalists and politicians in their posts and directly messaged high-profile political figures and news outlets seeking content collaborations.
None of those outreach attempts succeeded, according to Meta, but the effort demonstrates the operation’s ambition to bridge from covert activity into mainstream American political discourse. The network’s follower count — 79,400 accounts — gave it what Meta assessed as “moderate” reach with “meaningful but limited” engagement, higher than the typically low engagement of most state-backed influence campaigns.
AI as Operational Accelerant
Artificial intelligence has become routine in influence operations Meta investigates, appearing in “virtually every influence network” the company disrupts, according to the threat report. The Iranian operation used AI to mass-produce political memes expressing anti-Republican views while maintaining the visual consistency needed to sustain fake American identities.
Meta’s H2 2026 Adversarial Threat Report documents how AI lowers the skill threshold for cyber operations: actors who previously lacked technical sophistication can now generate convincing content at scale. The report notes that AI appears concentrated at earlier stages of the cyber kill chain, capability development rather than deployment, suggesting Iran-based actors used generative tools to build content libraries before launching the operation.
Sophisticated Evasion
The operators routed all traffic through proxy and hosting services located in the United States and Canada, a technique designed to evade platform detection systems that flag foreign IPs. The operational security represents a departure from cruder Iranian efforts. In August 2024, Meta disrupted a separate operation by APT42 — an Iranian cyber espionage group also known as UNC788 and Mint Sandstorm — which targeted Biden and Trump administration officials, diplomats, and journalists through basic phishing on WhatsApp.
That operation posed as technical support for AOL, Google, Yahoo, and Microsoft. The latest network shows Iranian operators graduating from simple credential theft to sustained influence campaigns with AI-generated content and multi-platform coordination.
Iran’s Influence Operation Track Record
Iran has been the most frequent country of origin for Middle East influence operations documented in academic datasets, accounting for 20 of 46 social media takedowns analyzed by researchers. In previous operations, the Islamic Revolutionary Guard Corps has run extensive networks, including 14,200 posts using fake Irish and Scottish profiles to target European audiences.
In March 2026, Meta disrupted another Iranian network of approximately 300 accounts that used “sophisticated fake personas,” including a political scientist, women’s rights activist, and satirical cartoonist, to build relationships with U.S. users before introducing political messaging. That operation also employed multiple AI-generated profile photos to enhance credibility. Europol this year targeted what it described as the IRGC’s “propaganda ecosystem” across the EU.
The Parallel Meme War
While Iranian operatives ran covert influence operations impersonating Americans, Tehran’s embassies openly flooded social media with AI-generated “slopaganda” memes mocking President Trump during the 2026 Iran war.
The two-track approach — overt propaganda paired with covert operations — shows Iran’s cyber strategy operating at multiple levels simultaneously. Iranian state media has used hundreds of fake accounts since at least 2011 to spread pro-Iranian messaging, according to previous Meta disruptions.
What Meta Shared
Meta provided information about the network to U.S. law enforcement. The company’s disclosure comes from its H2 2026 Adversarial Threat Report released August 27, which documents threats across coordinated inauthentic behavior, fraud and scams, terrorist organizations, surveillance-for-hire, and AI security.
The report notes that at least 135 countries have been targeted by influence operations Meta has tracked, with networks originating from 81 countries. Iran remains a persistent actor.








