HeadlinesBriefing favicon HeadlinesBriefing.com

Iran-linked CyberAv3ngers used OpenAI models

OpenAI Blog •
×

OpenAI has banned accounts linked to CyberAv3ngers, a threat actor reportedly affiliated with Iran’s IRGC. These accounts utilized OpenAI's models for activities such as researching vulnerabilities, debugging code, and seeking scripting advice.

CyberAv3ngers are known for disruptive attacks on industrial control systems (ICS) and programmable logic controllers (PLCs) in water, manufacturing, and energy sectors, often targeting infrastructure in Israel, the United States, or Ireland. Recent incidents include compromises at the Municipal Water Authority of Aliquippa in Pennsylvania in November 2023 and a disruption of water services in County Mayo, Ireland in December 2023.

The group leveraged weak passwords and known PLC vulnerabilities, alongside open-source tools for scanning and exploitation. Their activity on ChatGPT largely involved reconnaissance, seeking information on companies, services, and vulnerabilities. They also requested assistance in creating and refining bash and python scripts, some of which utilized publicly available pentesting tools.

Furthermore, CyberAv3ngers inquired about obfuscating malicious code, using post-compromise security tools, and information on various vulnerabilities. While previous reporting focused on ICS/PLC targeting, these prompts revealed potential interest in other technologies. OpenAI stated that these interactions did not provide CyberAv3ngers with novel capabilities beyond what is achievable with publicly available, non-AI tools.