Disrupting malicious uses of AI by state-affiliated threat actors

OpenAI Blog News

Summary

OpenAI and Microsoft disrupted five state-affiliated threat actors (from China, Iran, North Korea, and Russia) who were misusing AI services for phishing campaigns, code analysis, and information gathering. The actors were identified and their accounts terminated, with findings showing limited incremental capabilities of GPT-4 for malicious cybersecurity tasks beyond existing tools.

No content available
Original Article
View Cached Full Text

Cached at: 04/20/26, 02:48 PM

# Disrupting malicious uses of AI by state-affiliated threat actors Source: [https://openai.com/index/disrupting-malicious-uses-of-ai-by-state-affiliated-threat-actors/](https://openai.com/index/disrupting-malicious-uses-of-ai-by-state-affiliated-threat-actors/) Based on collaboration and information sharing with Microsoft, we disrupted five state\-affiliated malicious actors: two China\-affiliated threat actors known as Charcoal Typhoon and Salmon Typhoon; the Iran\-affiliated threat actor known as Crimson Sandstorm; the North Korea\-affiliated actor known as Emerald Sleet; and the Russia\-affiliated actor known as Forest Blizzard\. The identified OpenAI accounts associated with these actors were terminated\. These actors generally sought to use OpenAI services for querying open\-source information, translating, finding coding errors, and running basic coding tasks\. Specifically: - Charcoal Typhoon used our services to research various companies and cybersecurity tools, debug code and generate scripts, and create content likely for use in phishing campaigns\. - Salmon Typhoon used our services to translate technical papers, retrieve publicly available information on multiple intelligence agencies and regional threat actors, assist with coding, and research common ways processes could be hidden on a system\. - Crimson Sandstorm used our services for scripting support related to app and web development, generating content likely for spear\-phishing campaigns, and researching common ways malware could evade detection\. - Emerald Sleet used our services to identify experts and organizations focused on defense issues in the Asia\-Pacific region, understand publicly available vulnerabilities, help with basic scripting tasks, and draft content that could be used in phishing campaigns\. - Forest Blizzard used our services primarily for open\-source research into satellite communication protocols and radar imaging technology, as well as for support with scripting tasks\. Additional technical details on the nature of the threat actors and their activities can be found in the[Microsoft blog post⁠\(opens in a new window\)](https://aka.ms/emerging-AI-threats)published today\. The activities of these actors are consistent with previous[red team assessments⁠\(opens in a new window\)](https://cdn.openai.com/papers/gpt-4.pdf)we conducted in partnership with external cybersecurity experts, which found that GPT‑4 offers only limited, incremental capabilities for malicious cybersecurity tasks beyond what is already achievable with publicly available, non\-AI powered tools\_\.\_

Similar Articles

Disrupting malicious uses of AI

OpenAI Blog

OpenAI publishes an annual report on disrupting malicious uses of AI, detailing its efforts to prevent state-affiliated actors and other bad actors from misusing AI tools for purposes including authoritarian control, child exploitation, influence operations, and cyber attacks.

Disrupting malicious uses of AI: October 2025

OpenAI Blog

OpenAI released its October 2025 report on disrupting malicious uses of AI, detailing over 40 disrupted networks violating usage policies including state-affiliated threats, scams, and influence operations since February 2024.

Disrupting deceptive uses of AI by covert influence operations

OpenAI Blog

OpenAI reports disrupting five covert influence operations attempting to misuse its AI models for deceptive campaigns, with findings showing that safety-designed models prevented threat actors from generating desired content. The company is publishing trend analysis and collaborating with industry, civil society, and government to combat AI-enabled information manipulation.

An update on disrupting deceptive uses of AI

OpenAI Blog

OpenAI publishes a threat intelligence report detailing efforts to disrupt over 20 deceptive AI operations globally, with a focus on state-linked actors and influence campaigns particularly concerning given global elections.

Disrupting malicious uses of AI | February 2026

OpenAI Blog

OpenAI released a February 2026 threat report detailing case studies on detecting and preventing malicious uses of AI, highlighting how threat actors combine AI models with traditional tools and abuse multiple platforms and models in coordinated campaigns.