Experts say ChatGPT, Gemini, and other Western AI models are turbocharging Iran's cyber operations, helping it develop malware and launch phishing attacks
Western AI models are turbocharging Tehran's cyber operations, helping it develop malware and launch attacks
Context & Ripple Effects
Related coverage traces a progression from early criminal experimentation with ChatGPT-generated hacking tools in 2023 to disclosures that state-linked groups from Iran, China, Russia, and North Korea were using LLMs to improve cyber activity in 2024. By early 2025, US officials and Google researchers described AI use across a wider set of countries and targets.
This report lands alongside coverage of Iran intensifying its hacking activity to create disruption, collect intelligence, and identify targets. It makes the issue less about isolated account abuse and more about readily available Western models lowering the effort required to support an active state cyber campaign.
First-order effects
- Iranian operators can use general-purpose models to speed up malware development and produce phishing content, increasing the operational throughput of existing cyber teams.
- ChatGPT, Gemini, and other Western-model providers face more pressure to detect and disrupt malicious use, following prior removals of Iranian accounts tied to an influence operation.
Second-order effects
- Defenders must contend with more polished and potentially more varied phishing lures and malware-support activity, raising the value of behavior-based detection rather than relying only on known malicious templates.
- AI providers’ abuse controls become a competitive and governance issue: the same broad accessibility that expands model reach also increases exposure to state-linked misuse and demands for stronger safeguards.
Third-order effects
- If state-backed groups can repeatedly turn public AI tools into cyber-force multipliers, model safety will increasingly be judged by measurable resistance to misuse, not only by capability and consumer adoption.
- The pattern points toward an enduring offense-defense cycle in which providers, governments, and security teams continually adapt controls as widely available models reduce the skill and time barriers for parts of cyber operations.
The trend: General-purpose AI is becoming dual-use infrastructure: its rapid mainstream deployment is also lowering friction for cyber-enabled state activity and forcing security controls to mature alongside adoption.