Experts say US models like ChatGPT and Gemini have turbocharged Iran's cyber operations, helping it develop malware, craft phishing messages, and scale attacks
Context & Ripple Effects
Related coverage traces a progression from early reports of criminals testing ChatGPT for hacking tools and scam chatbots to disclosures that state-linked groups, including Iranian actors, were using large language models to improve cyber operations. OpenAI had already removed Iranian accounts tied to an election-focused influence effort, indicating providers were confronting misuse beyond ordinary consumer use.
The new report matters because it frames that misuse as operational scaling: widely available Western models can assist both malware development and phishing work. It also arrives while ChatGPT and Gemini are expanding their reach, widening the pool of legitimate users and the moderation surface providers must manage.
First-order effects
- Iranian cyber operators can use general-purpose models to accelerate drafting, coding, and phishing-content tasks, reducing friction in parts of an attack workflow.
- ChatGPT, Gemini, and other Western-model providers face more immediate pressure to detect and disrupt malicious use without broadly blocking legitimate technical and security-related requests.
Second-order effects
- Defenders must assume more polished and more readily localized phishing and malware-adjacent material, increasing the value of verification, behavioral detection, and rapid abuse reporting over simple text-quality cues.
- Competition among leading model providers will increasingly include abuse-prevention capabilities: account controls, monitoring, red-teaming, and incident disclosure become product and trust differentiators alongside model adoption.
Third-order effects
- If state-linked actors can repeatedly convert consumer AI access into cyber-operational leverage, frontier-model governance will become more tightly coupled to national-security and cybersecurity policy rather than treated solely as a content-moderation issue.
- The enduring tension is likely to be dual-use access: providers will need to preserve broadly useful coding and language functions while making repeatable hostile workflows harder to scale; the corpus does not establish that current controls can reliably do so.
The trend: Generative AI is becoming a dual-use layer in cyber operations, shifting the security contest toward preventing scalable misuse of widely distributed general-purpose models.