HeadlinesBriefing favicon HeadlinesBriefing.com

OpenAI Blocks Malicious ChatGPT Accounts

OpenAI Blog •
×

OpenAI has identified and banned a cluster of ChatGPT accounts operated in Korean that were attempting to use its models for malware and command-and-control (C2) development. The observed activity overlaps with a Trellix report detailing spear-phishing campaigns against South Korean diplomatic missions, the deployment of Xeno RAT malware, and GitHub-based C2. While the use of Korean, time zones, and operational themes suggest North Korean (DPRK) actors, OpenAI cannot independently confirm attribution and blocks access from North Korea.

The banned accounts primarily interacted in Korean, focusing on specific use cases like converting Chrome extensions to Safari, configuring Windows Server VPNs, or developing macOS Finder extensions. Interactions involved Windows API hooking, browser credential access (DPAPI), and CAPTCHA clones. Draft phishing emails in Korean, themed around cryptocurrency and financial institutions, were also observed, alongside experimentation with cloud storage services and GitHub functions.

While OpenAI found no evidence that malicious binaries described by Trellix were generated by its models, the actors generated outputs supporting implant and RAT-adjacent development, credential theft routines, phishing lures, macOS development scaffolding, and cryptocurrency operations. Many of these requests fell into the dual-use category, having legitimate applications but repurposed by threat actors. OpenAI disabled all associated accounts and shared indicators with partners, noting that model access did not enable novel capabilities beyond existing public tools.