
OpenAI News
· 1 min read
Cyber Operation: Russian-speaking malware tooling
This case study was originally published in OpenAI’s October 2025(opens in a new window) report.
Actor
We banned ChatGPT accounts that were attempting to use the model to help develop and refine malware, including a remote-access trojan, credential stealers, and features to evade detection. These accounts appear to be affiliated with Russian-speaking criminal groups, as we observed them posting evidence of their activities in a Telegram channel dedicated to those actors. Based on our investigation, we assess that this activity was connected to a Russian-language operator managing multiple accounts and leveraging proxy and ephemeral hosting infrastructure.
Behavior
This threat actor used multiple ChatGPT accounts primarily to prototype and troubleshoot technical components that enable post-exploitation and credential theft, well known activities for this type of threat actor. The model refused direct requests to generate malicious content, so typical operator use of the model involved eliciting building-block code, such as converting compiled executables into shellcode, designing in-memory loaders, or parsing browser credentials, which the threat actor then likely assembled into malicious workflows.
The threat actor also used our models to generate code for obfuscation and “crypter” patterns, such as inserting padding instructions and junk sequences, clipboard-monitoring, and simple exfiltration helpers, such as a Telegram bot uploader and archive-and-ship scripts. These outputs are not inherently malicious, unless used in such a way by a threat actor outside of our platform.
Completions
Representative examples of these activities can be mapped to the LLM ATT&CK framework as follows:
Original source
This story was published by OpenAI News. SyncAI.news shows a preview; the complete article is on the publisher's site.
Read the full story on openai.com


