AI Pulse by Inblix

OpenAI Bans Chinese Hackers Using ChatGPT to Phish Taiwan's Semiconductor Sector

OpenAI Blog · Oct 1, 2025 · 2 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: OpenAI Bans Chinese Hackers Using ChatGPT to Phish Taiwan's Semiconductor Sector

OpenAI banned a cluster of ChatGPT accounts linked to Chinese threat actors who used the platform to refine phishing lures and debug malware, the company revealed in its latest threat intelligence report. The activity overlaps with groups tracked as UNK_DROPPITCH by Proofpoint and UTA0388 by Volexity. In at least one case, an email address used to register a ChatGPT account was also tied directly to sending phishing messages. The operation squarely aligned with PRC intelligence collection priorities, targeting Taiwan’s semiconductor industry, U.S. academic institutions, think tanks, and diaspora groups critical of the Chinese Communist Party.

The threat actors weren’t developing zero-days or novel attack chains. They came for efficiency. Their primary use of ChatGPT was generating content for highly tailored phishing campaigns in simplified Chinese, traditional Chinese, English, and Japanese. The playbook was formulaic: craft a polite email from a fake academic or industry persona, then request micro-edits to adjust tone or insert specific institutional details. Despite this painstaking localization effort, they often left giveaway mistakes in signature blocks—a telling sign of a technically competent but unsophisticated operator.

On the malware side, the group used ChatGPT to accelerate routine scripting tasks. They requested code snippets for encrypted C2 traffic using AES-GCM, process enumeration in Go and PowerShell, and simple obfuscation tricks like renaming functions or hiding strings. The development work showed a clear ceiling. They discussed the nuances of AES for securing communications but then hardcoded a simple static key. Some of their Go-based activities overlapped with public reporting on malware tracked as GOVERSHELL and HealthKick, suggesting the models were being used to support their primary malware development, not replace it.

Perhaps most interesting is what they were planning next. The operators researched using DeepSeek to automate mass phishing at scale—scraping web content to automatically generate target lists and personalized email content. OpenAI says it cannot confirm if that automation ever went live or which model was ultimately used. The picture that emerges is one of incremental gain. These actors valued speed and localization above all else, using AI not to break new ground but to sand down the rough edges of existing workflows.

💡 Key Takeaways

  1. The banned accounts overlapped with known Chinese threat groups and targeted Taiwan's semiconductor sector using AI-generated phishing lures in four languages.
  2. Operators used ChatGPT as a productivity tool for scripting and debugging, not for developing novel capabilities, with their code showing a mix of technical knowledge and basic errors like static encryption keys.
  3. The actors researched using DeepSeek to automate mass phishing at scale by scraping web content for personalized targeting, indicating a push toward AI-driven reconnaissance.

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

Learn more

Glossary terms

← Back to all articles