HeadlinesBriefing favicon HeadlinesBriefing.com

China-linked hackers used AI for cyber ops

OpenAI Blog •
×

OpenAI has banned accounts linked to China-based threat actors who leveraged AI tools for various cyber operations. These actors, communicating in both Chinese and English, utilized OpenAI's models to aid in vulnerability research, script modification, system configuration troubleshooting, and software development. Their activities included attempts to bypass security measures, automate social media tasks on Android devices, and gather information on U.S. federal defense industry and military networks.

Observed technical activities involved modifying scripts for tools like reNgine and Selenium, and advice on Linux system administration, software development (web, Android, C, Golang), and infrastructure setup such as VPNs, Docker, and local LLM deployments. The threat actors sought assistance with password bruteforcing, port scanning software, AI-driven penetration testing, and social media automation.

Further research focused on U.S. Special Operations Command, satellite communications, government technology, and networking equipment. OpenAI mapped these activities to the LLM ATT&CK framework, including LLM Assisted Vulnerability Research and LLM Enhanced Scripting Techniques. While OpenAI disabled the associated accounts and shared indicators, they found no evidence that their models provided novel capabilities beyond publicly available resources.