OpenAI Banned ChatGPT Accounts Used by Chinese and North Korean Hackers to Develop Malware
OpenAI has implemented account bans on various ChatGPT accounts associated with Chinese state-affiliated hacking groups. These accounts were used to enhance malware capabilities and generate phishing content.
OpenAI has implemented account bans on various ChatGPT accounts associated with Chinese state-affiliated hacking groups. These accounts were used to enhance malware capabilities and generate phishing content.
The report from October 2025 highlights the disruption of multiple networks as part of OpenAI's efforts to prevent misuse of its AI technologies by unauthorized entities.
Since February 2024, OpenAI has disrupted over 40 networks for policy violations. The company notes that threat actors are integrating AI to boost operational efficiency rather than developing new offensive capabilities.
China-Linked Actors Enhance Cyber Operations
A significant case study in the report details a group identified as "Cyber Operation Phish and Scripts." Managed by Chinese-speaking individuals, this group utilized AI to support malware development and phishing activities.
OpenAI's investigation revealed that the group's operations aligned with the intelligence objectives of the People's Republic of China (PRC) and overlapped with known threat groups, UNKDROPPITCH and UTA0388.
Malware Development : The group employed AI to develop and debug tools, with overlaps in implementation with malware like GOVERSHELL and HealthKick. There was also exploration into further automation using AI models such as DeepSeek. Phishing Content Generation : The group created phishing emails in multiple languages, targeting Taiwan's semiconductor sector, U.S. academia, and critics of the Chinese government.
OpenAI has implemented account bans on various ChatGPT accounts associated with Chinese state-affiliated hacking groups.
OpenAI reported that the actors used the AI models to enhance efficiency in existing operations rather than generating new types of threats.
The report also describes the disruption of other accounts linked to Chinese government entities using AI for surveillance tool development.
One user attempted to draft a proposal for a "High-Risk Uyghur-Related Inflow Warning Model," intended to analyze travel and police records.
Another attempt involved creating a "social media probe" to scan platforms for content labeled as extremist, while other accounts researched critics of the Chinese government.
OpenAI has deactivated all accounts related to these activities and shared compromise indicators with industry partners to support cybersecurity efforts.
The report notes that AI models often functioned as safety barriers, declining requests to generate harmful code or exploits, limiting actors to generating non-malicious code snippets.
OpenAI's findings suggest that while state-sponsored actors are exploring AI, its primary use is to enhance existing operations.
The company remains committed to detecting and disrupting misuse to prevent its tools from aiding malicious cyber activities.
Based on reporting by Cyber Security News.
