OpenAI Cracks Down on Malicious Use of ChatGPT by Cyber Threat Actors

OpenAI has announced the termination of several ChatGPT accounts linked to Russian-speaking cybercriminals and Chinese nation-state hacking groups. These accounts were reportedly used to aid in malware development, automate social media activities, and research U.S. satellite communications technologies.

“The [Russian-speaking] actor used our models to assist with developing and refining Windows malware, debugging code across multiple languages, and setting up their command-and-control infrastructure,” OpenAI stated in its threat intelligence report. The actor was noted for their knowledge of Windows internals and operational security behaviors.

ScopeCreep: A New Malware Campaign

The Go-based malware campaign, codenamed ScopeCreep by OpenAI, was not found to be widespread. The threat actor used temporary email accounts to sign up for ChatGPT, engaging in a single conversation per account to incrementally improve their malicious software before abandoning the account.

The attackers distributed the AI-assisted malware through a code repository posing as a legitimate video game crosshair overlay tool named Crosshair X. Users downloading the trojanized software had their systems infected by a malware loader, which fetched additional payloads from an external server.

The malware was designed to:
– Escalate privileges using ShellExecuteW
– Evade detection by excluding itself from Windows Defender
– Suppress console windows and insert timing delays

ScopeCreep employed tactics such as Base64-encoding to obfuscate payloads, DLL side-loading techniques, and SOCKS5 proxies to hide source IP addresses. The malware aimed to harvest credentials, tokens, and cookies stored in web browsers and sent alerts to a Telegram channel when new victims were compromised.

Chinese Nation-State Hacking Groups

OpenAI also disabled accounts linked to two Chinese hacking groups, APT5 and APT15, known for engaging in open-source research and infrastructure setup. These groups used the AI models to troubleshoot configurations, modify software, and research implementation details.

Activities included:
– Building software packages for offline deployment
– Configuring firewalls and name servers
– Web and Android app development

The China-linked clusters weaponized ChatGPT to develop a brute-force script for FTP servers, research automation of penetration testing using large-language models (LLMs), and manage Android devices for social media automation.

Other Observed Malicious Activities

OpenAI identified various other malicious activities utilizing ChatGPT:

– A North Korea IT worker scheme : Used OpenAI’s models for deceptive employment campaigns.
– Sneer Review (China-origin) : Generated social media posts on geopolitical topics in multiple languages for platforms like Facebook and TikTok.
– Operation High Five (Philippines-origin) : Created political content for Facebook and TikTok.
– Operation VAGue Focus (China-origin) : Generated posts posing as journalists and geopolitical analysts.
– Operation Helgoland Bite (Russia-origin) : Created content about the German 2025 election for Telegram and X.
– Operation Uncle Spam (China-origin) : Produced polarized social media content for U.S. political discourse.
– Storm-2035 (Iranian influence operation) : Generated comments supporting various geopolitical causes.
– Operation Wrong Number (Cambodian-origin) : Created recruitment messages for task scams.

These operations often involved charging recruits high fees and using a portion of those funds to maintain existing ’employees.’ “This structure is characteristic of task scams,” noted OpenAI’s Ben Nimmo and his team.

For more updates, follow aitechtrend.com.

Note: This article is inspired by content from https://thehackernews.com/2025/06/openai-bans-chatgpt-accounts-used-by.html. It has been rephrased for originality. Images are credited to the original source.

Subscribe to our Newsletter