Microsoft and OpenAI indicate that Chinese, Russian, North Korean, and Iranian groups have used the LLM for phishing and intelligence operations.

On February 14, 2024, Microsoft and OpenAI published a report revealing that State-sponsored Chinese, Russian, North Korean and Iranian cybercriminals used ChatGPT for nefarious purposes. The two main uses are intelligence and phishing tools.

In Russia, the infamous Fancy Bear group, which has ties to Russian intelligence, is thought to have asked ChatGPT to research “satellite communication protocols, radar imaging tech and specific technical settings.” In China, the State group Charcoal Typhoon used the LLM to investigate cybersecurity firms and tools.

As far as phishing goes, the North Koreans of Emerald Sleet, Iranians of Crimson Sandstorm and Chinese of Salmon Typhoon, used ChatGPT to create counterfeit documents and letters. In particular, Crimson Sandstorm created spearphishing emails “impersonating an international development agency and another agency attempting to lure famous feminists to a fake website.”

Malicious actors will sometimes try to take advantage of our tools to hurt others, including when it comes to cyber operations,” recognize Microsoft and OpenAI in their report. The two partners closed the accounts involved, and maintain they have taken measures to detect State-sponsored cybercriminals in the future.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.