Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

APT Hackers Abuse ChatGPT to Develop Advanced Malware and Phishing Campaigns

Security researchers at Volexity have identified that China-aligned threat actors are utilizing artificial intelligence platforms, such as ChatGPT, to enhance their cyberattack capabilities.

Security researchers at Volexity have identified that China-aligned threat actors are utilizing artificial intelligence platforms, such as ChatGPT, to enhance their cyberattack capabilities.

AI-Enhanced Phishing Operations Target Global Organizations

The group, identified as UTA0388, has conducted spear phishing campaigns since June 2025. These campaigns employ AI to develop malware and craft multilingual phishing emails targeting organizations in North America, Asia, and Europe.

UTA0388's operations demonstrate an advanced use of Large Language Models to automate malicious activities. The threat actors create fabricated personas and fictional research organizations to socially engineer targets into downloading malicious payloads.

The campaigns are distinguished by the volume and linguistic diversity of attacks, with emails crafted in English, Chinese, Japanese, French, and German.

Volexity observed over 50 unique phishing emails that appeared fluent across multiple languages. However, despite linguistic fluency, the emails often lacked coherence, containing incongruent combinations such as English-speaking targets receiving emails with Mandarin subject lines and German message bodies.

The group, identified as UTA0388, has conducted spear phishing campaigns since June 2025.
Eric Wallace · Thehackingpost

The threat actors employed "rapport-building phishing," where initial contact appeared benign, only delivering malicious content after targets engaged in conversation over multiple email exchanges. This approach minimizes infrastructure exposure while building trust with potential victims before deploying malicious payloads.

Technical analysis reveals five distinct variants of UTA0388's custom malware, named GOVERSHELL, each representing significant rewrites rather than iterative improvements typical of human development patterns. This suggests potential AI assistance in generating different communication methods and capabilities across malware iterations.

GOVERSHELL variants employed various command-and-control mechanisms, from fake TLS communications to WebSocket connections, with each iteration introducing new features and completely rewritten network stacks. The malware achieves persistence through scheduled tasks and uses search order hijacking techniques to load malicious DLL files alongside legitimate executables.

Advertisement

Technical artifacts discovered in malware samples include developer paths containing Simplified Chinese characters and metadata indicating creation using python-docx, a Python library commonly used by LLMs for document generation tasks.

OpenAI published a report in October 2025 confirming that UTA0388 leveraged their ChatGPT platform for spear phishing and malware development operations. Evidence of AI usage includes fabricated organizational details with predictable patterns and bizarre content in malware archives.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories