Threat actors use ChatGPT to write malware

Oct. 14, 2024, 10:47 a.m.

Description

OpenAI has disrupted over 20 malicious cyber operations abusing ChatGPT for various purposes, including malware development and spear-phishing attacks. The company confirmed cases involving Chinese and Iranian threat actors. SweetSpecter, a Chinese group, targeted OpenAI employees with phishing emails and used ChatGPT for reconnaissance and social engineering. CyberAv3ngers, an Iranian group, utilized the AI tool for developing scripts, planning post-compromise activities, and exploiting vulnerabilities. Another Iranian group, Storm-0817, employed ChatGPT to create Android malware and supporting infrastructure. These cases demonstrate that generative AI tools can enhance offensive cyber operations, particularly for low-skilled actors, across all stages of an attack.

Date

  • Created: Oct. 14, 2024, 10:23 a.m.
  • Published: Oct. 14, 2024, 10:23 a.m.
  • Modified: Oct. 14, 2024, 10:47 a.m.

Indicators

  • stickhero.pro

Attack Patterns

  • SugarGh0st RAT
  • SweetSpecter, CyberAv3ngers, Storm-0817

Additional Informations

  • Technology
  • Energy
  • Government
  • Iran, Islamic Republic of
  • Jordan
  • China
  • Pakistan