Microsoft and OpenAI Expose State-Backed Hackers Using AI for Cyberattacks
Microsoft and OpenAI reveal that state-sponsored hacking groups from Russia, North Korea, Iran, and China are actively utilizing large language models to enhance their cyberattack campaigns. The companies are responding by blocking malicious accounts and establishing new security principles.
Microsoft and OpenAI reveal that several state-backed hacking groups actively use large language models to support their cyberattack campaigns. The companies publish their findings in detailed blog posts and introduce a set of principles to tackle the malicious use of artificial intelligence. These best practices include identifying and blocking the accounts that hackers create to access LLM-powered chatbots.
The research highlights a Russian group known as Forest Blizzard that heavily targets defense, energy, and transportation organizations connected to the war in Ukraine. This group utilizes OpenAI services to research satellite communication protocols, radar imaging technology, and basic scripting tasks. A North Korean group called Emerald Sleet also relies on AI to find experts on North Korea, generate content for spear-phishing campaigns, and research scripting techniques.
An Iranian hacking group tracked as Crimson Sandstorm uses OpenAI services to develop malicious .NET code and research methods for disabling antivirus applications. Additionally, Microsoft shares intelligence on Chinese state-affiliated hacking groups that target various industries, including the defense sector. By exposing these activities, Microsoft and OpenAI aim to understand and mitigate the emerging threats posed by AI-assisted cyber warfare.