July 31, 2026, (Inside AI) — OpenAI has banned accounts linked to North Korean threat actors who used its AI models to research cyber intrusion tools, phishing, malware, and cryptocurrency theft. The company disclosed the action in a case study originally published in February 2025, revealing that the accounts were detected after a tip from a trusted industry partner.
The banned accounts were associated with two known DPRK-affiliated groups: VELVET CHOLLIMA (also known as Kimsuky or Emerald Sleet) and STARDUST CHOLLIMA (also known as APT38 or Sapphire Sleet). These groups are notorious for blending espionage with financially motivated cybercrime, a hallmark of North Korean operations.
The actors used OpenAI’s tools primarily for coding assistance, debugging, and researching open-source security tools. Their activities included development support for Remote Desktop Protocol (RDP) brute force attacks and guidance on using open-source Remote Administration Tools (RATs).
During one debugging session for MacOS auto-start extensibility points (ASEPs), the actor inadvertently exposed staging URLs for binaries that were unknown to security vendors at the time. OpenAI submitted these URLs to an online scanning service, enabling vendors to detect the malware and protect potential victims.
OpenAI stated that the prompts and queries were largely based on existing public information, and the model outputs either provided no novel capabilities or were refusals. The company shared payloads with the security community to further disrupt the operations.
Mapping AI-Assisted Intrusion to the MITRE ATT&CK Framework #
The activity was mapped to proposed LLM-themed extensions of the MITRE ATT&CK Framework, a widely used knowledge base of adversary tactics. This mapping helps defenders understand how AI can be weaponized at various stages of an attack lifecycle, from reconnaissance to execution.
For instance, the actors leveraged AI for vulnerability research and script generation, which aligns with techniques like “AI-Assisted Exploit Development.” However, OpenAI emphasized that the models did not enable any breakthrough capabilities, underscoring the current limitations of AI in offensive operations. This incident is not isolated. In early 2024, Microsoft and OpenAI reported that state-backed hackers, including groups from Russia and China, were using large language models to refine phishing emails and troubleshoot code. A 2024 study by Recorded Future found that while LLMs lower the barrier for basic attacks, they have not yet enabled sophisticated autonomous hacking.
The Broader Trend of AI Weaponization by State Actors #
North Korea’s cyber program has increasingly relied on cryptocurrency theft to fund its weapons programs, with groups like APT38 stealing billions. The use of AI tools represents a natural evolution, allowing even low-skilled operators to accelerate research and development.
OpenAI’s proactive banning and information sharing align with its policies against malicious use, but the case highlights the challenge of preventing dual-use AI. As models become more capable, distinguishing legitimate security research from malicious intent becomes harder.
The company has not disclosed the number of banned accounts or the specific models accessed. It reiterated that it continuously monitors for abuse and collaborates with partners to identify threats.
While the exposed payloads are now detected by multiple vendors, the incident serves as a reminder that AI platforms are increasingly part of the cyber threat landscape. For defenders, integrating AI-specific indicators into threat intelligence is becoming essential.