China's SweetSpecter used ChatGPT to craft malware before targeting OpenAI staff
Curated by the Inblix editorial team
OpenAI has confirmed it banned a cluster of accounts linked to SweetSpecter, a suspected China-based cyber adversary that turned the company’s own product against it. The group used ChatGPT to research vulnerabilities, write scripts, and support spear-phishing campaigns—all while simultaneously targeting OpenAI employees with malware.
The attack chain, detected in May 2024 after a tip from a credible partner, shows a brazen operational loop. SweetSpecter sent emails to both corporate and personal accounts of OpenAI staff, posing as a ChatGPT user requesting support. The messages carried a malicious attachment, “some problems.zip,” which hid a Windows malware variant called SugarGh0st RAT. Once opened, it would display a decoy DOCX file full of fake ChatGPT error messages while silently giving the attacker full remote control: executing commands, capturing screenshots, and siphoning data. OpenAI’s security controls prevented those emails from ever reaching corporate inboxes.
What makes this more than just another phishing attempt is the simultaneous on-platform activity. OpenAI’s investigation mapped the banned accounts’ behavior to the LLM-themed tactics Microsoft proposed for the MITRE ATT&CK framework earlier this year. The operators weren’t just probing defenses from the outside; they were inside the platform, using the models to accelerate reconnaissance and scripting tasks that feed directly into offensive operations.
Here’s the reality check, though: OpenAI’s assessment is that the models didn’t give SweetSpecter any novel capabilities they couldn’t have gotten from public resources. That tracks with what we saw in the company’s first threat report. The AI didn’t teach them new tricks—it just made their existing ones faster. The real story here isn’t supercharged AI hacking. It’s the operational audacity of using a company’s own infrastructure to build weapons while simultaneously trying to breach its employees, and the quiet effectiveness of threat-intelligence sharing that caught it before any damage was done.
💡 Key Takeaways
- SweetSpecter used ChatGPT for vulnerability research and scripting while simultaneously sending malware-laced phishing emails to OpenAI's own employees.
- OpenAI's existing security controls blocked the malicious emails from reaching corporate inboxes, and the models did not grant the adversary novel offensive capabilities.
- This marks the first time SweetSpecter's targeting has publicly included a U.S.-based AI company, expanding beyond its previous focus on political entities in the Middle East, Africa, and Asia.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.