OpenAI Disrupts State-Affiliated Threat Actors Using AI
OpenAI has terminated the accounts of five state-affiliated threat actors who attempted to use its AI services for malicious cyber activities. These findings indicate that while state actors are attempting to leverage AI, current models provide only limited, incremental capabilities for cybersecurity tasks compared to existing non-AI powered tools.
Disruption of State-Affiliated Actors
OpenAI and Microsoft Threat Intelligence identified and disrupted five specific state-affiliated actors. The affected accounts were terminated across the following groups:
- China: Charcoal Typhoon and Salmon Typhoon
- Iran: Crimson Sandstorm
- North Korea: Emerald Sleet
- Russia: Forest Blizzard
These actors primarily utilized OpenAI services for basic tasks such as querying open-source information, translation, finding coding errors, and executing basic coding tasks.
Specific Actor Activities
Each group utilized the AI tools for different strategic objectives:
- Charcoal Typhoon: Focused on researching companies and cybersecurity tools, debugging code, generating scripts, and creating content for phishing campaigns.
- Salmon Typhoon: Used services to translate technical papers, retrieve public information on intelligence agencies and regional threat actors, assist with coding, and research methods for hiding processes on a system.
- Crimson Sandstorm: Utilized the platform for app and web development scripting support, generating spear-phishing content, and researching malware detection evasion.
- Emerald Sleet: Identified defense experts and organizations in the Asia-Pacific region, researched public vulnerabilities, performed basic scripting, and drafted phishing content.
- Forest Blizzard: Primarily conducted open-source research into radar imaging technology and satellite communication protocols, alongside scripting support.
AI Capabilities in Cybersecurity Tasks
Findings from this disruption align with previous red team assessments conducted by OpenAI and external experts. These assessments concluded that GPT-4 offers only limited, incremental capabilities for malicious cybersecurity tasks beyond what is already achievable with publicly available, non-AI powered tools.
OpenAI's Multi-Pronged Safety Strategy
To combat the evolving threat of state-affiliated misuse, OpenAI employs a four-part safety framework:
Monitoring and Disruption
OpenAI utilizes dedicated Intelligence and Investigations, Safety, Security, and Integrity teams to identify sophisticated threat actors. These teams use OpenAI's own models to analyze adversary interactions and assess intentions. Detected actors face account disabling, service termination, or resource limitations.
Ecosystem Collaboration
OpenAI collaborates with industry partners and stakeholders to exchange information regarding the detected use of AI by state-affiliated actors. This effort is part of a voluntary commitment to promote the safe and transparent development of AI technology.
Iterative Safety Mitigations
Real-world misuse data is used to inform the iterative development of safety safeguards. By analyzing how sophisticated actors attempt to abuse the system, OpenAI identifies patterns that may become widespread, allowing for the continuous evolution of model safeguards.
Public Transparency
OpenAI maintains a policy of informing the public and stakeholders about the nature and extent of detected malicious state-affiliated activity when warranted. The goal is to foster collective defense and increase awareness among all stakeholders.