OpenAI busts Iranian hackers using ChatGPT to build Android spyware and scrape journalists
Curated by the Inblix editorial team
OpenAI has publicly tied an Iran-linked threat actor, codenamed STORM-0817, to the use of its AI models for a range of malicious cyber activities, marking the first time this specific group has been called out for leveraging generative AI. The company disrupted a network of accounts and detailed the findings in a case study from its October 2024 report, offering a rare peek into the gritty, unglamorous ways adversaries are actually trying to weaponize tools like ChatGPT—not for sci-fi plots, but for the tedious, error-prone grunt work of coding and debugging.
The group used OpenAI’s models primarily to troubleshoot and develop a relatively basic piece of Android surveillanceware. The malware, hidden inside packages named com.example.myttt and com.mihanwebmaster.ashpazi, was designed to vacuum up a standard list of personal data: contacts, call logs, photos, browsing history, and even files from secure messaging apps like WhatsApp. The prompts also revealed work on the corresponding command-and-control server, a WAMP setup tied to the domain stickhero[.]pro, which OpenAI’s investigation suggests was still under active development and not yet fully operational. It’s a reminder that for all the hype around AI-generated super-malware, the current reality is often adversaries using it to fix broken code and build the scaffolding for otherwise mundane threats.
Beyond the malware, STORM-0817’s activity showed a clear intelligence-gathering bent. They sought help writing a Python-based Instagram scraper to pull follower details, and OpenAI noted the tool was tested on an Iranian journalist critical of the government—a textbook surveillance target. In a separate but aligned effort, the group used ChatGPT to translate LinkedIn profiles of individuals and academics linked to Pakistan’s National Center for Cyber Security and the Air University’s cybercrime lab, an institution that supports Pakistan’s military branches. This dual focus neatly captures the group’s operational mandate: technical espionage support that spans both domestic repression and foreign intelligence collection.
OpenAI’s ultimate assessment is sobering and consistent with its past findings on groups like SweetSpecter. The company stated its models offered only “limited, incremental capabilities” for malicious tasks beyond what’s already achievable with publicly available, non-AI tools. The real value for defenders is the unique insight OpenAI gained into an adversary’s development pipeline—seeing the infrastructure, capabilities, and targets before they became fully operational. That kind of visibility is far more valuable than any marginal boost the AI gave the attackers themselves. All identified accounts were disabled and indicators of compromise shared with industry partners.
💡 Key Takeaways
- The AI's primary value for the attackers was in debugging broken code and building basic server infrastructure, not in creating advanced or novel malware.
- The group tested its Instagram scraper on a specific Iranian journalist critical of the government, highlighting a direct link between AI-assisted reconnaissance and real-world surveillance targets.
- OpenAI's visibility into the attacker's prompts revealed pre-operational infrastructure and targeting, offering a rare intelligence advantage that the AI itself didn't provide to the adversary.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.