HeadlinesBriefing favicon HeadlinesBriefing.com

AI-Assisted Cyber Intrusion Research by DPRK Actors

OpenAI Blog •
×

OpenAI has banned accounts linked to DPRK-affiliated threat actors suspected of using AI for cyber intrusion research. These actors, potentially associated with groups like VELVET CHOLLIMA and STARDUST CHOLLIMA, employed OpenAI's models for tasks including coding assistance, debugging, and researching security-related open-source code. Their activities focused on developing tools for Remote Desktop Protocol (RDP) brute-force attacks and utilizing open-source Remote Administration Tools (RATs).

The actors also sought information on debugging auto-start extensibility points for Mac OS, revealing staging URLs for previously undetected binaries. OpenAI submitted these URLs to security vendors, ensuring the binaries are now reliably detected. The research encompassed LLM-assisted development for RDP clients, crafting phishing emails for cryptocurrency investors, and researching RATs for post-compromise activities.

While the actors primarily leveraged existing open-source information and the AI models did not provide novel capabilities, OpenAI has banned the associated accounts. The payloads discovered were shared with the security community to disrupt ongoing operations and protect potential victims.