Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.
Social Engineering Examples·2 sources
On February 14, 2024, Microsoft Threat Intelligence and OpenAI jointly published research disclosing that several state-affiliated threat actors had been using large language models (LLMs), including OpenAI's GPT-4-family services, to support cyber-operations-adjacent activity. Among the five actors named, Forest Blizzard, Microsoft's designation for the Russian GRU-linked group also known as APT28, Fancy Bear, and (previously) STRONTIUM, was found to have used the LLM for open-source research into satellite communication protocols, radar imaging technologies, and specific technical parameters, plus scripting assistance (file manipulation, data selection, regular expressions, multiprocessing) to help automate technical tasks.
Microsoft termed this pattern "LLM-informed reconnaissance" and "LLM-enhanced scripting techniques." Both companies stated the observed use was consistent with adversaries treating AI as an incremental productivity tool rather than a source of novel attack capability, and that no particularly novel or unique AI-enabled attack technique had been observed.
OpenAI terminated the accounts tied to Forest Blizzard (alongside four other state-affiliated actors), and Microsoft stated it had disabled all accounts and assets associated with the group.
Forest Blizzard (Microsoft's designation for the GRU-linked actor also tracked as APT28/Fancy Bear, and formerly as STRONTIUM) accessed OpenAI's LLM services (ChatGPT/GPT-4-family models) using accounts that Microsoft and OpenAI's joint threat-intelligence collaboration subsequently attributed to the group. The actor used the LLM in two documented ways: first, as an open-source research assistant to investigate satellite communication protocols, radar imaging technologies, and specific technical parameters, subject matter directly relevant to conventional military operations in the context of Russia's war in Ukraine; second, as a coding aid, where the LLM provided "LLM-enhanced scripting techniques" covering file manipulation, data selection, regular expressions, and multiprocessing, meaning help writing or refining scripts to automate technical tasks.
Microsoft explicitly characterized this as "LLM-informed reconnaissance," using the model to accelerate and structure research the actor could otherwise have done manually via search engines and public documentation, rather than any novel LLM-enabled attack technique. Microsoft's Threat Intelligence team (which tracks more than 300 threat actors, including roughly 160 nation-state groups) and OpenAI cross-referenced known threat-actor indicators/infrastructure with account activity to attribute the usage to Forest Blizzard, then acted under a jointly announced set of principles: disable the offending accounts, terminate service access, and publicly disclose the detected misuse together with mitigation steps.
There was no human-facing lure; this incident is AI-service misuse/recon automation rather than social engineering of a victim. The "tell" that exposed it was on the defender side: Microsoft Threat Intelligence (which tracks 300+ threat actors, including ~160 nation-state groups, via known infrastructure, tooling, and behavioral indicators) and OpenAI's account-abuse monitoring correlated LLM-account query activity, open-source research requests centered on satellite communication protocols, radar imaging technology, and specific technical parameters, plus scripting-assistance requests involving file manipulation, regex, and multiprocessing, with known Forest Blizzard tradecraft and infrastructure, enabling attribution and account takedown before any confirmed downstream compromise was reported.
OpenAI terminated the accounts associated with Forest Blizzard as part of a coordinated takedown that also hit four other state-affiliated actors (North Korea's Emerald Sleet, Iran's Crimson Sandstorm, and China's Charcoal Typhoon and Salmon Typhoon). Microsoft stated that "all accounts and assets associated with Forest Blizzard have been disabled." Neither company identified a specific victim organization or confirmed that the LLM-assisted research led to a successful intrusion or compromise; Microsoft characterized the observed behavior overall as consistent with attackers "using AI as another productivity tool" rather than evidence of new, AI-enabled attack capability.
No breach, data theft, or financial loss was attributed to this specific activity.
This was one of the first major, jointly attributed public disclosures by a leading AI vendor (OpenAI) and a leading security vendor (Microsoft) confirming that a well-known nation-state APT group, GRU-linked APT28/Fancy Bear, with a long history of election interference and military-intelligence-driven cyber operations, was directly using commercial generative-AI chatbot services for OSINT-style reconnaissance and technical scripting support.
It matters less for scale of damage (none was disclosed) than as an early, concrete case study establishing that state threat actors treat mainstream LLMs as a research and productivity accelerator for sensitive technical domains (here, satellite/radar systems tied to a live military conflict), and it set a public template, the "principled approach" of detect, disable, notify peer vendors, and disclose, that other AI providers have since followed for similar nation-state AI-abuse findings.
Both companies described a "principled approach": (1) identify and act against malicious use of Microsoft/OpenAI AI APIs/services by tracked APTs, APMs, or cybercrime syndicates, disabling accounts, terminating services, limiting resource access; (2) notify other AI service providers when a threat actor is detected using their AI systems, sharing data so they can independently verify and act; (3) collaborate with other stakeholders (industry/government) to exchange threat-actor AI-use intelligence; (4) transparency, publicly disclose detected AI misuse and actions taken.
Concretely for this case: OpenAI terminated the accounts associated with Forest Blizzard (and four other state-affiliated actors, Emerald Sleet/North Korea, Crimson Sandstorm/Iran, Charcoal Typhoon and Salmon Typhoon/China); Microsoft stated "all accounts and assets associated with Forest Blizzard have been disabled." Broader recommended defenses for the sector: monitor for anomalous LLM-account query patterns tied to sensitive technical domains (satellite/radar/military-adjacent research), cross-vendor AI-abuse intelligence sharing, and treating LLM outputs used in adversary tooling as a new but currently incremental (not novel-technique-enabling) layer of existing OSINT/recon tradecraft.
Social Engineering Examples. “Forest Blizzard (APT28/Fancy Bear) Uses GPT-4 for Satellite Comms and Radar Tech Reconnaissance”. Accessed 19 September 2026. https://socialengineeringexamples.com/forest-blizzard-apt28-llm-recon-2024
Forest Blizzard (Russia's GRU Unit 26165, also tracked as APT28/Fancy Bear) is documented by Microsoft as pursuing intelligence needs tied to Russia's war in Ukraine; satellite communication protocols and radar imaging technology were pursued as research topics with direct relevance to conventional military operations.
A nation-state actor's choice of research topic is driven by its government's strategic and military priorities, not by anything a vendor or defender controls; there is no practical control at this stage, so the realistic intervention point is the next stage, where the actor's activity first touches a monitorable commercial platform.
Consistent with the group's established tradecraft of using accessible, low-cost infrastructure, the actor obtained access to OpenAI's GPT-4-family services (ChatGPT/API) through accounts that Microsoft and OpenAI's joint threat-intelligence review later attributed to Forest Blizzard.
AI service providers can apply account-abuse and threat-actor-attribution monitoring, cross-referencing known infrastructure, indicators, and behavioral patterns tracked by threat intelligence teams, to flag suspect accounts; this is how Microsoft Threat Intelligence and OpenAI's collaboration attributed the accounts to Forest Blizzard.
The actor queried the LLM for open-source research on satellite communication protocols, radar imaging technologies, and specific technical parameters, using the model to accelerate and structure research it could otherwise have pursued manually through search engines and public documentation.
Providers can monitor for anomalous LLM-account query patterns clustered around sensitive technical domains, such as satellite, radar, or other military-adjacent research, and correlate them against known threat-actor tradecraft, enabling earlier detection before any downstream use of the research.
Separately, the actor used the LLM as a coding aid, requesting help with file manipulation, data selection, regular expressions, and multiprocessing to automate or optimize technical tasks supporting its broader operations.
The same account-level monitoring can flag scripting-assistance requests when combined with the reconnaissance pattern above, and providers can act on confirmed abuse by disabling accounts, terminating services, or limiting resource access, consistent with the "principled approach" both companies described.
The actor incorporated the LLM-derived research findings and scripting assistance into its own tradecraft and tooling as a productivity accelerant, per Microsoft and OpenAI's assessment, until the accounts were identified and disabled; no confirmed downstream intrusion or compromise was tied to this specific LLM activity.
Once abuse is confirmed, the realistic control is takedown plus disclosure: terminate the account's access and share indicators with peer AI vendors and the public, as Microsoft and OpenAI did in their joint February 14, 2024 disclosure, so other providers can check for and cut off the same actor on their own platforms.
Browse by what this case has in common with others in the library.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…
Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power.
A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted…
Impersonators posing as two School District of Philadelphia vendors switched payments to ACH and diverted nearly $700,000 into fraud accounts.
The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters…
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…
Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power.
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…
Lazarus operators spear-phished a senior Sky Mavis engineer through a fake LinkedIn recruiting process and a spyware-laced job-offer PDF.
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…
In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and…
Lazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms.