AI Pulse by Inblix

OpenAI Busted North Korean Hackers Using ChatGPT to Debug MacOS Malware

OpenAI Blog · Feb 1, 2025 · 2 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: OpenAI Busted North Korean Hackers Using ChatGPT to Debug MacOS Malware

OpenAI has banned a cluster of accounts linked to North Korean state-sponsored hacking groups caught using ChatGPT to research and develop cyber intrusion tools. The activity, flagged by a trusted industry partner and detailed in a February 2025 report, points to operatives from the notorious VELVET CHOLLIMA and STARDUST CHOLLIMA units — groups better known to security pros as Kimsuky and APT38.

The threat actors weren’t just kicking the tires. They used OpenAI’s models for targeted coding assistance, debugging malicious scripts, and researching open-source remote administration tools (RATs). One particularly sloppy operational security mistake proved invaluable: while debugging a MacOS auto-start persistence mechanism, the hackers revealed staging URLs for compiled binaries that were completely unknown to security vendors at the time. OpenAI immediately submitted those URLs to an online scanning service, and the payloads are now reliably detected by multiple antivirus engines — directly disrupting a live operation.

The activity spanned a blend of financially motivated and espionage-related tasks. The accounts sought help crafting phishing emails aimed at cryptocurrency investors, developing a C#-based RDP client for brute-force attacks, and obfuscating PowerShell scripts to evade detection. This dual-use pattern — chasing crypto wallets while building intrusion infrastructure — is textbook DPRK tradecraft, where cyber units fund the regime through heists like the $600 million Axie Infinity hack while also stealing intelligence.

Here’s the context that should temper any AI panic: OpenAI’s report makes clear that the models didn’t give these actors any novel capabilities. The generations either mirrored publicly available information or were outright refusals to respond. What the actors did gain was efficiency — a force multiplier for middling programmers, not a zero-day factory. The real story isn’t that LLMs create super-hackers; it’s that they accelerate the boring parts of cybercrime, like writing boilerplate phishing templates and troubleshooting buggy scripts, just like they do for legitimate developers.

💡 Key Takeaways

  1. A live DPRK malware operation was disrupted after hackers accidentally exposed staging URLs for unknown MacOS binaries while using ChatGPT to debug their code.
  2. The threat actors mapped cleanly onto the MITRE ATT&CK LLM extensions, using AI specifically for reconnaissance, payload crafting, social engineering, and anomaly detection evasion.
  3. OpenAI assessed that its models provided no novel offensive capabilities — the value for adversaries was purely in efficiency gains for routine development tasks.

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

Learn more

Glossary terms

← Back to all articles