WorkThe story, in brief

STORM-0817: Iran-linked malware and scraping activity

OpenAI banned Iran-linked accounts using ChatGPT to debug malware and scrape platforms — a real test of AI safety enforcement.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

State-sponsored actors are actively misusing frontier AI tools for offensive operations (malware development, data scraping). This demonstrates both the dual-use risk practitioners need to account for and OpenAI's enforcement capability — a policy/security story affecting how enterprises think about AI access controls and threat surfaces.

The key facts

12 to know
  1. STORM-0817: Iran-linked threat actor group

  2. Used OpenAI tools to debug Android malware

  3. Used ChatGPT for social platform scraping

  4. Used AI to translate malicious tooling

  5. OpenAI banned the accounts and disrupted the activity

  6. October 2024 disclosure

  7. OpenAI banned STORM-0817 (Iran-linked threat actor)

  8. Activity included: malware debugging, social-platform scraping, tooling translation

  9. Android malware development was primary use case

  10. First documented state-actor abuse of frontier models at operational scale

  11. Enforcement action by OpenAI; coordinated with law enforcement/intelligence

  12. Published Oct 1, 2024 — timing suggests attribution/investigation completion

Go to the source

OpenAI Blogopenai.com

Publisher excerpt: OpenAI banned Iran-linked STORM-0817 accounts using AI to debug Android malware, scrape social platforms, and translate tooling.
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work