APT Hackers Abuse ChatGPT to Develop Advanced Malware and Phishing Campaigns
Security researchers at Volexity have identified that China-aligned threat actors are utilizing artificial intelligence platforms, such as ChatGPT, to enhance their cyberattack capabilities.
Security researchers at Volexity have identified that China-aligned threat actors are utilizing artificial intelligence platforms, such as ChatGPT, to enhance their cyberattack capabilities.
AI-Enhanced Phishing Operations Target Global Organizations
The group, identified as UTA0388, has conducted spear phishing campaigns since June 2025. These campaigns employ AI to develop malware and craft multilingual phishing emails targeting organizations in North America, Asia, and Europe.
UTA0388's operations demonstrate an advanced use of Large Language Models to automate malicious activities. The threat actors create fabricated personas and fictional research organizations to socially engineer targets into downloading malicious payloads.
The campaigns are distinguished by the volume and linguistic diversity of attacks, with emails crafted in English, Chinese, Japanese, French, and German.
Volexity observed over 50 unique phishing emails that appeared fluent across multiple languages. However, despite linguistic fluency, the emails often lacked coherence, containing incongruent combinations such as English-speaking targets receiving emails with Mandarin subject lines and German message bodies.
The group, identified as UTA0388, has conducted spear phishing campaigns since June 2025.
The threat actors employed "rapport-building phishing," where initial contact appeared benign, only delivering malicious content after targets engaged in conversation over multiple email exchanges. This approach minimizes infrastructure exposure while building trust with potential victims before deploying malicious payloads.
Technical analysis reveals five distinct variants of UTA0388's custom malware, named GOVERSHELL, each representing significant rewrites rather than iterative improvements typical of human development patterns. This suggests potential AI assistance in generating different communication methods and capabilities across malware iterations.
GOVERSHELL variants employed various command-and-control mechanisms, from fake TLS communications to WebSocket connections, with each iteration introducing new features and completely rewritten network stacks. The malware achieves persistence through scheduled tasks and uses search order hijacking techniques to load malicious DLL files alongside legitimate executables.
Technical artifacts discovered in malware samples include developer paths containing Simplified Chinese characters and metadata indicating creation using python-docx, a Python library commonly used by LLMs for document generation tasks.
OpenAI published a report in October 2025 confirming that UTA0388 leveraged their ChatGPT platform for spear phishing and malware development operations. Evidence of AI usage includes fabricated organizational details with predictable patterns and bizarre content in malware archives.
Based on reporting by GBHackers.
