OpenAI and Microsoft Shut Down State-Linked Hacking Groups Using AI Tools
OpenAI terminates accounts of five state-affiliated threat groups from Russia, China, North Korea, and Iran that use large language models for early-stage hacking tasks. Analysts warn this activity serves as a precursor for malicious actors to scale cyberattacks using generative AI.
OpenAI and Microsoft disrupt five state-affiliated threat groups linked to Russia, China, North Korea, and Iran that use large language models to prepare for malicious hacking campaigns. OpenAI terminates the accounts of these actors, who leverage the AI technology for precursor tasks such as open source queries, translation, code debugging, and basic coding. Microsoft threat researchers collaborate in this effort to identify and stop these emerging cyber threats.
Cybersecurity analysts warn that this uncovered activity confirms widespread concerns about the potential abuse of generative AI by malicious groups. Experts note that generative AI essentially puts attackers on steroids by allowing them to scale and accelerate their operations far beyond the current capabilities of network defenders. The rapid adoption of these tools enables threat actors to spread their attacks much more quickly across multiple targets.
Despite these alarming trends, OpenAI cautions that prior red-team assessments show GPT-4 provides malicious attackers with only limited, incremental improvements over traditional, publicly available non-AI tools. Microsoft confirms that it has not yet observed any uniquely novel attack methods or significant campaigns relying on large language models. However, Microsoft continues to actively track this evolving activity and pledges to promptly alert the public regarding any future misuse of the technology.