Timeline

Microsoft and OpenAI disrupt state-affiliated hacking groups misusing LLMs

The groups used LLMs mainly for reconnaissance, translation, debugging and phishing-content drafting rather than novel attack techniques; the identified accounts were terminated.

  • Security & misuse
  • Major

Microsoft and OpenAI published joint research identifying five state-affiliated hacking groups that had used OpenAI’s services, and said the associated accounts had been terminated: Russia’s Forest Blizzard (linked to GRU Unit 26165), North Korea’s Emerald Sleet, Iran’s Crimson Sandstorm (linked to the IRGC), and China’s Charcoal Typhoon and Salmon Typhoon.

The uses described were mundane rather than novel. Forest Blizzard used LLMs to research satellite and radar technologies relevant to operations in Ukraine and for basic scripting help. Emerald Sleet used them to research North Korea-focused think tanks and experts, understand publicly disclosed vulnerabilities, and draft phishing content. Crimson Sandstorm used them for .NET development support, generating social-engineering emails, and researching ways to evade detection. Charcoal Typhoon used them to research cybersecurity tools and companies, debug code, and generate content for phishing campaigns; Salmon Typhoon’s use was more exploratory, touching geopolitics research and cryptographic technology. Both companies were explicit that they had not observed the groups develop “particularly novel or unique” AI-enabled attack techniques — the models were functioning as a productivity aid for otherwise conventional tradecraft, not as a new offensive capability in themselves.

The disclosure was notable less for the severity of what was found than for its structure: a frontier AI lab and its cloud partner sharing threat intelligence and coordinating account takedowns against nation-state actors, in public, before any major AI-enabled attack had been documented. It set a template — matching a taxonomy of known threat-actor names to observed LLM usage patterns — that OpenAI, Google DeepMind and other labs followed in subsequent threat-intelligence reports through 2024 and 2025, each finding broadly similar patterns of state actors using general-purpose models to accelerate existing techniques rather than to originate new ones.