HeadlinesBriefing favicon HeadlinesBriefing.com

OpenAI Bans Accounts Linked to Phishing Operations

OpenAI Blog •
×

OpenAI has banned a cluster of ChatGPT accounts that exhibited activity overlapping with threat groups UNK_DROPPITCH and UTA0388. These actors demonstrated hallmarks consistent with cyber operations serving PRC intelligence requirements, including Chinese language use and targeting of Taiwan's semiconductor sector, U.S. academia, and ethnic groups critical of the CCP.

The threat actors primarily utilized ChatGPT to enhance existing workflows, focusing on generating phishing content in multiple languages and assisting with tool development and malware debugging. Their activities included crafting phishing emails with specific personas and regional nuances, and developing code snippets for tasks like process enumeration and C2 traffic encryption, albeit with unsophisticated implementation such as using a simple static key for AES.

Across multiple sessions, they developed basic command-and-control prototypes and explored automation for mass phishing. OpenAI disabled these accounts and shared indicators with industry partners, noting that the actors sought efficiency and localization rather than novel offensive capabilities. The model outputs did not introduce new offensive techniques beyond well-documented public methods.