OpenAI has announced the termination of several ChatGPT accounts linked to Russian-speaking cybercriminals and Chinese nation-state hacking groups. These accounts were reportedly used to aid in malware development, automate social media activities, and research U.S. satellite communications technologies.
“The [Russian-speaking] actor used our models to assist with developing and refining Windows malware, debugging code across multiple languages, and setting up their command-and-control infrastructure,” OpenAI stated in its threat intelligence report. The actor was noted for their knowledge of Windows internals and operational security behaviors.
ScopeCreep: A New Malware Campaign
The Go-based malware campaign, codenamed ScopeCreep by OpenAI, was not found to be widespread. The threat actor used temporary email accounts to sign up for ChatGPT, engaging in a single conversation per account to incrementally improve their malicious software before abandoning the account.
The attackers distributed the AI-assisted malware through a code repository posing as a legitimate video game crosshair overlay tool named Crosshair X. Users downloading the trojanized software had their systems infected by a malware loader, which fetched additional payloads from an external server.
The malware was designed to:
– Escalate privileges using ShellExecuteW
– Evade detection by excluding itself from Windows Defender
– Suppress console windows and insert timing delays
ScopeCreep employed tactics such as Base64-encoding to obfuscate payloads, DLL side-loading techniques, and SOCKS5 proxies to hide source IP addresses. The malware aimed to harvest credentials, tokens, and cookies stored in web browsers and sent alerts to a Telegram channel when new victims were compromised.
Chinese Nation-State Hacking Groups
OpenAI also disabled accounts linked to two Chinese hacking groups, APT5 and APT15, known for engaging in open-source research and infrastructure setup. These groups used the AI models to troubleshoot configurations, modify software, and research implementation details.
Activities included:
– Building software packages for offline deployment
– Configuring firewalls and name servers
– Web and Android app development
The China-linked clusters weaponized ChatGPT to develop a brute-force script for FTP servers, research automation of penetration testing using large-language models (LLMs), and manage Android devices for social media automation.
Other Observed Malicious Activities
OpenAI identified various other malicious activities utilizing ChatGPT:
– A North Korea IT worker scheme : Used OpenAI’s models for deceptive employment campaigns.
– Sneer Review (China-origin) : Generated social media posts on geopolitical topics in multiple languages for platforms like Facebook and TikTok.
– Operation High Five (Philippines-origin) : Created political content for Facebook and TikTok.
– Operation VAGue Focus (China-origin) : Generated posts posing as journalists and geopolitical analysts.
– Operation Helgoland Bite (Russia-origin) : Created content about the German 2025 election for Telegram and X.
– Operation Uncle Spam (China-origin) : Produced polarized social media content for U.S. political discourse.
– Storm-2035 (Iranian influence operation) : Generated comments supporting various geopolitical causes.
– Operation Wrong Number (Cambodian-origin) : Created recruitment messages for task scams.
These operations often involved charging recruits high fees and using a portion of those funds to maintain existing ’employees.’ “This structure is characteristic of task scams,” noted OpenAI’s Ben Nimmo and his team.
For more updates, follow aitechtrend.com.
Note: This article is inspired by content from https://thehackernews.com/2025/06/openai-bans-chatgpt-accounts-used-by.html. It has been rephrased for originality. Images are credited to the original source.
