OpenAI Bans Korean-Language Accounts Building Malware and Phishing Lures
Curated by the Inblix editorial team
OpenAI has banned a cluster of ChatGPT accounts operated by Korean-language users who were systematically using its models for malware development, phishing, and command-and-control (C2) infrastructure work. The activity, detailed in a new case study, overlaps with a Trellix report on spear-phishing campaigns targeting South Korean diplomatic missions and the deployment of XenoRAT malware. While OpenAI stopped short of independent attribution, the Korean language use, UTC+8/UTC+9 time zone activity, and operational themes align with the security community’s understanding of North Korean (DPRK) actors.
These weren’t amateurs fumbling around. Each account showed a structured, narrow focus, from converting Chrome extensions for the Apple App Store to configuring Windows Server VPNs. One account wouldn’t dabble in multiple areas; it was a cell-like division of labor. The models were prompted for help with Windows API hooking, in-memory execution, and debugging scripts designed to steal browser encryption keys and passwords through DPAPI workflows. The operators also drafted Korean-language phishing emails themed around cryptocurrency and government services, and built look-alike login pages by proxying reCAPTCHA.
OpenAI frames much of this as a “gray zone” of dual-use activity. Asking a model how to handle reflective DLL loading or browser credential access is not inherently malicious—it’s standard fare for software debugging and legitimate development. But that technical signal flips when tied to a threat actor repurposing it for an implant. The group also experimented with cloud-storage services like pCloud and file.io, and GitHub functions for raw content retrieval, likely staging payloads through legitimate developer platforms.
Here’s the reality check that separates this from the AI-doomsday hype. OpenAI found no evidence that its models generated the actual malicious binaries used in the Trellix campaigns, and access didn’t grant any novel capabilities beyond what’s publicly available. What the models provided was a force multiplier for speed and troubleshooting—an on-demand assistant for writing credential-theft scripts or scaffolding macOS Finder extensions. The accounts are now disabled and indicators shared with partners, but the operation highlights a persistent challenge: the same features that make these tools indispensable for developers make them irresistible for threat actors working the same technical plumbing.
💡 Key Takeaways
- The threat actors used a cell-like structure where individual ChatGPT accounts focused on single, specialized tasks like converting browser extensions or configuring VPNs.
- OpenAI confirmed the models were used to troubleshoot DPAPI credential-theft scripts and build phishing infrastructure, but not to generate the final malicious binaries.
- Despite the operational security overlap with known North Korean activity, OpenAI did not independently attribute the campaign, noting it already blocks access from North Korea.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.