/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Microsoft and OpenAI say hackers, including Russian, North Korean, Iranian, and Chinese-backed groups, are already using LLMs to refine and improve cyberattacks

Microsoft and OpenAI are revealing today that hackers are already using large language models like ChatGPT to refine and improve their existing cyberattacks.

The Verge Tom Warren

Context & Ripple Effects

Earlier research had already identified criminals experimenting with ChatGPT for hacking tools and malware code, but this report extends the concern to state-linked groups using models to improve established operations. Later coverage of OpenAI's disruption of 10 malicious operations shows that abuse enforcement became an ongoing operational task, not a one-off disclosure.

The story matters because it places general-purpose model access inside the cyber conflict loop: attackers can use the same broadly available systems that defenders and researchers increasingly employ in an AI-driven cyber cat-and-mouse game.

First-order effects

  • Microsoft and OpenAI must treat misuse detection, account enforcement, and reporting on state-linked activity as immediate parts of operating LLM services.
  • Defenders facing Russian-, North Korean-, Iranian-, and Chinese-backed groups must account for AI assistance in the refinement of phishing, malware, and other existing attack workflows.

Second-order effects

  • Other model providers face pressure to build comparable abuse-monitoring and disruption capabilities, especially as later reporting links Western models to expanded Iranian cyber activity and its phishing and malware work.
  • Security teams and vendors will have to adapt detection and training to attacks whose language, research, or code can be iterated more quickly, intensifying the attacker-defender cycle.

Third-order effects

  • If this pattern persists, frontier-model governance will increasingly be judged on whether providers can preserve legitimate access while constraining state-linked cyber misuse.
  • Cybersecurity may become a core dimension of AI platform competition and policy, with model providers expected to demonstrate durable monitoring and response rather than rely solely on model safeguards.

The trend: This is an early data point in the shift from AI as a standalone productivity tool to AI as contested dual-use infrastructure in cyber operations.

Discussion

  • @sixdub Justin on x
    In collaboration, OpenAI and Microsoft Threat Intel conducted analysis on how state-aligned actors are using publicly available LLMs. Assessment is that they are exploring the capability — primarily using for productivity, and early-stage capability. https://www.microsoft.com/...
  • @hackinglz Justin Elze on x
    Harnessing the power of LLMs these threat actors were able to reduce the use of the recon command “whoami.exe” by 2%! https://www.microsoft.com/...
  • @msftsecintel @msftsecintel on x
    Microsoft, in collaboration with OpenAI, is publishing research on emerging threats in the age of AI, focusing on identified activity associated with known threat actors Forest Blizzard, Emerald Sleet, Crimson Sandstorm, and others. Learn more: https://www.microsoft.com/...