OpenAI says it has blocked ChatGPT accounts , which were used by North Korean hackers to research future targets and discover ways to breach networks.

“ We have banned accounts that exhibit activity potentially related to threat actors from the Democratic People’s Republic of Korea (DPRK) ,” the company said in a report
“Some of these accounts were involved in activity involving TTPs associated with a threat group known as VELVET CHOLLIMA (AKA Kimsuky, Emerald Sleet), while other accounts were potentially associated with the STARDUST CHOLLIMA (AKA APT38, Sapphire)“.
See also: DeceptiveDevelopment: North Korean hackers target freelance developers
The most recently banned accounts were identified by the company with the help of an industry partner. North Korean hackers appear to have been using ChatGPT to find tools they can use in cyberattacks, as well as to find information on cryptocurrency-related topics. North Korean hackers are often involved in crypto theft attacks.
According to OpenAI, malicious actors also used ChatGPT for coding assistance, including help on how to use open -source Remote Administration Tools (RATs), as well as help with debugging, research and development for open-source and publicly available security tools, etc.
Additionally, OpenAI threat analysts discovered that North Korean hackers exposed URLs for malicious binaries that were unknown to security vendors at the time.
These staging URLs and the associated compiled executables were submitted to an online scanning service for easy sharing with the wider security community. As a result, some vendors can now reliably detect malicious binaries, protecting potential victims from future attacks.
See also: North Korean hackers behind the Phemex breach?

OpenAI also observed the following malicious activities by North Korean hackers on ChatGPT:
- Questions about vulnerabilities in various applications
- Developing and troubleshooting a C#-based RDP client for activation
- Search for code to bypass security warnings for unauthorized RDP
- Search for multiple PowerShell scripts for RDP connections, sending/receiving files, executing code from memory, and obfuscating HTML content
- Creating phishing emails and alerts to deceive users
- Searching for methods to conduct targeted phishing and social engineering
- Discussion on creating and deploying obfuscated payloads for execution
OpenAI also banned accounts likely linked to North Korean IT workerswho are trying to get jobs at Western companies with the aim of exploiting them.
“They used our models to perform work-related tasks, such as writing code, troubleshooting problems, and messaging with colleagues,” OpenAI explained. “They also used our models to devise cover stories to explain unusual behaviors such as avoiding video calls, accessing corporate systems from unauthorized countries, or working irregular hours.”
See also: Phishing attacks exploit ChatGPT subscriptions
North Korean hackers: A major threat
North Korean hackers pose a threat to global security through a series of cyberattacks targeting critical systems and networks. These attacks can cause significant disruption and undermine trust in digital systems.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, North Korean hackers have demonstrated their ability to infiltrate financial systems, such as banks and cryptocurrencies, causing economic instability.
Finally, they can use their skills to steal sensitive information, such as military secrets or intellectual property, thus causing security issues and political tensions.
Source: www.bleepingcomputer.com
