Microsoft reported in February 2024 that state-linked hacking groups from Iran, North Korea, Russia, and China had begun using generative AI, including large language models (LLMs) from Microsoft and its partner OpenAI, to support offensive cyber operations. According to the company, these actors used AI tools for tasks such as reconnaissance, technical research, scripting, and drafting more convincing phishing and social-engineering content, but the activities observed were described as “early-stage” and “incremental” rather than fundamentally new attack techniques. Microsoft and OpenAI said they detected, investigated, and then disabled the accounts and assets associated with the identified threat groups. The findings, published alongside a broader Microsoft threat report, highlight how major geopolitical adversaries are experimenting with generative AI to enhance existing cyber-espionage and influence capabilities. Examples included North Korea’s Kimsuky using LLMs to research foreign think tanks and generate spear-phishing content, Iran’s Revolutionary Guard using AI to craft lures and troubleshoot malware or intrusion techniques, Russia’s GRU-linked operators querying satellite and radar technologies relevant to the war in Ukraine, and Chinese groups such as Aquatic Panda and Maverick Panda probing how LLMs might augment technical operations and geopolitical analysis. While Microsoft and OpenAI stressed that current models provide only limited additional capability beyond non-AI tools for malicious cybersecurity tasks, the company warned that generative AI is poised to amplify social engineering, deepfakes, and disinformation, raising concerns for democratic processes and global cyber risk in the coming years.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on AI

Comments