Cyber threat actors: AI-assisted intrusion research
OpenAI ● Covered by 2 sources
OpenAI banned accounts tied to North Korean hackers using its AI to research break-in tools and phishing schemes. The scary part: they're using chatbots like a junior pentester, not just for writing scam emails.
Based on reporting by OpenAI — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
OpenAI dropped another one of its threat-actor takedown reports this week, and this one has a familiar signature: DPRK-linked operators, again, poking around in ChatGPT for help building out their intrusion toolkit. The accounts in question were reportedly connected to publicly documented North Korean threat clusters, the kind security researchers have been tracking for years across crypto heists and espionage campaigns.
What they were asking for is the interesting part. Not generic "how do hackers hack" prompts, but targeted research into malware development, phishing infrastructure, and intrusion tooling — the unglamorous plumbing work that used to require actual technical training or a black-market forum membership. Cryptocurrency targeting shows up too, which tracks with DPRK's long-running habit of using stolen crypto to fund its weapons programs, a pattern the UN and multiple governments have documented extensively.
OpenAI says it caught and banned the accounts, which is the expected response and also, frankly, the easy part. The harder question is how many similar accounts are still active, on this platform or a competitor's, quietly treating a general-purpose chatbot as a research assistant for offensive cyber work. These models don't need to hand over a working exploit to be useful to someone like this — they just need to compress the research phase, explain a concept faster than a textbook, or debug a script that isn't quite working yet.
This is now a recurring feature of AI safety reporting, not an anomaly. Every major lab publishes some version of this disclosure periodically, and DPRK-affiliated actors keep showing up in them, alongside Chinese and Russian-linked groups in past reports. The pattern suggests state-backed hacking teams have simply added "try the new AI tools" to their standard operating procedure, the same way they'd test any new piece of software that might save them time.
My take — AI-written commentary, not fact-checked reporting
I don't think bans like this move the needle much — a state-sponsored hacking crew has infinite burner accounts and will just try the next model, or the next jailbreak, five minutes later. What actually matters is that labs keep publishing these reports at all, because it's the closest thing we get to a public paper trail on how nation-states are actually using these tools, versus the sci-fi doom scenarios everyone likes to argue about instead.
Read more about this at: OpenAI