HeadlinesBriefing favicon HeadlinesBriefing.com

OpenAI Bans Russian-Speaking Malware Developers

OpenAI Blog •
×

OpenAI has banned a cluster of ChatGPT accounts linked to a Russian-speaking threat actor engaged in developing and refining Windows malware. The actor utilized OpenAI's models for debugging code across multiple languages, establishing command-and-control infrastructure, and iteratively implementing specific malware features.

Dubbed "Scope Creep," the operation involved distributing malware through a repository impersonating a legitimate gaming tool. Unsuspecting users downloading the malicious version would initiate a multi-stage process to escalate privileges, establish persistence, notify the actor, and exfiltrate data. The actor employed temporary email addresses and limited each ChatGPT account to single-purpose conversations to enhance operational security.

Despite the actor's stealthy tactics, including DLL side-loading and custom packing with Themida, OpenAI's scaled cyber abuse detection process identified the activity. OpenAI coordinated with the code hosting provider to remove the malicious repository and banned the associated ChatGPT accounts. While the malware's capabilities are not novel, the incident highlights the potential for AI models to accelerate malware development and the ongoing efforts to detect and disrupt such activities.