OpenAI Bans Chinese APT Groups Using ChatGPT for Pentagon Recon and Password Brute-Forcing
Curated by the Inblix editorial team
OpenAI has terminated a cluster of ChatGPT accounts linked to two notorious Chinese state-sponsored hacking groups, KEYHOLE PANDA (APT5) and VIXEN PANDA (APT15), after catching them using the models to script password attacks against FTP servers and research US special operations networks. The activity, disclosed in OpenAI’s June 2025 threat report, offers a rare technical window into how advanced persistent threat actors are integrating LLMs into their operational workflows—though the company is quick to dampen any alarm about supercharged capabilities.
The banned accounts engaged with models in both Chinese and English, splitting their work into two distinct lanes. One lane focused squarely on offensive reconnaissance: the actors solicited help modifying reNgine web application scanners, scripting Selenium automation to bypass logins and capture authorization tokens, and building a tool to brute-force username and password combos on FTP servers. They also researched how to chain LLMs into autonomous penetration testing loops, feeding Nmap scan output back into the model to generate successive attack commands.
The second lane was more mundane infrastructure support—the kind of sysadmin grunt work any dev team needs. The operatives asked for advice on configuring firewalls and nameservers, building offline software packages, deploying Docker containers, and even standing up local LLM instances of DeepSeek. This dual-use pattern, blending quiet IT prep with sharp-edged research into US Special Operations Command, satellite ground station locations, and government ID cards, is exactly what makes attribution messy but intelligence-rich.
Here’s the kicker that should cool the hottest takes: OpenAI found zero evidence that model access gave these actors anything they couldn’t have grabbed from public resources. That’s a crucial detail that pushes back on the narrative of AI as some kind of cyber superweapon. The real story might be more boring—and more interesting. These groups aren’t discovering novel exploits via ChatGPT; they’re just offloading the tedious scripting and translation tasks that slow down a campaign. The value is in the acceleration of the known, not the discovery of the unknown. For defenders, the implication is clear: the speed of operations is the new battleground, not necessarily the sophistication.
💡 Key Takeaways
- OpenAI confirmed the banned accounts belong to KEYHOLE PANDA and VIXEN PANDA, two groups publicly attributed to China’s Ministry of State Security.
- The threat actors used ChatGPT primarily for scripting repetitive attack tools and conducting open-source research on US military networks, not for developing novel exploits.
- OpenAI asserts that all obtained information and capabilities were available through public resources, suggesting the primary AI advantage is operational speed rather than unique offensive power.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.