OpenAI bans accounts using ChatGPT for phishing and scripting support tied to PRC intelligence requirements
Cyber Operation: Phishing and scripting support
OpenAI's October threat report details banned ChatGPT accounts whose activity overlapped with publicly tracked groups UNK_DROPPITCH and UTA0388. The actors used the model to draft phishing emails in Chinese, English, and Japanese, and to assist Go and PowerShell malware development—including encrypted C2 and process enumeration. The model introduced no novel offensive capabilities; the operators sought incremental speed and localization, yet left giveaway errors like implausible contact details in email signatures. They also explored DeepSeek for automating mass phishing, though OpenAI cannot confirm whether that work proceeded.
Why it matters: OpenAI's official threat report names specific actor overlaps (UNK_DROPPITCH, UTA0388) and concrete TTPs. Strong cross-source signal, but it's threat intel rather than AI capability news—direct value for product/research readers is limited, so it lands right at the featured th...