Operation “ScopeCreep”: Russian-speaking malware development
OpenAI disrupted a Russian malware ring using ChatGPT to build cyber tools — and it's forcing the industry to reckon with how fast attack tooling evolves.

Why it matters
AI platforms are now active battlegrounds in cyber conflict. This case shows both OpenAI's enforcement capability and the emerging cat-and-mouse game: malicious actors are adapting faster than detection, and practitioners need to understand AI's role in the threat landscape.
The key facts
10 to knowOpenAI disrupted Russian-speaking malware development operation ('ScopeCreep')
Actors used ChatGPT to build malware, refine loaders, and troubleshoot cyber tooling
Russian-language accounts targeted for platform enforcement
Represents AI-enabled cyber threat category now material to security practitioners
Signals expanding cat-and-mouse dynamic: malicious use detection vs. evolving attack adaptation
OpenAI disrupted Russian-speaking accounts using ChatGPT/API for malware development
Campaign included refining loaders and troubleshooting cyber tooling
Enforcement: account bans and API access revocation
Disclosed via OpenAI's official disruption report (work.openai.com)
Framed as AI security/policy enforcement, not a technical vulnerability
Go to the source
OpenAI Blogopenai.com
Publisher excerpt: OpenAI banned Russian-language accounts using AI to build malware, refine loaders, and troubleshoot cyber tooling.
