Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar imaging technology and to get scripting help, prompting Microsoft and OpenAI to jointly disclose the abuse and disable the group's accounts on 2024-02-14.
Reviewed by the Social Engineering Examples team.
On February 14, 2024, Microsoft Threat Intelligence and OpenAI jointly published research disclosing that several state-affiliated threat actors had been using large language models (LLMs), including OpenAI's GPT-4-family services, to support cyber-operations-adjacent activity. Among the five actors named, Forest Blizzard, Microsoft's designation for the Russian GRU-linked group also known as APT28, Fancy Bear, and (previously) STRONTIUM, was found to have used the LLM for open-source research into satellite communication protocols, radar imaging technologies, and specific technical parameters, plus scripting assistance (file manipulation, data selection, regular expressions, multiprocessing) to help automate technical tasks. Microsoft termed this pattern "LLM-informed reconnaissance" and "LLM-enhanced scripting techniques." Both companies stated the observed use was consistent with adversaries treating AI as an incremental productivity tool rather than a source of novel attack capability, and that no particularly novel or unique AI-enabled attack technique had been observed. OpenAI terminated the accounts tied to Forest Blizzard (alongside four other state-affiliated actors), and Microsoft stated it had disabled all accounts and assets associated with the group.
Forest Blizzard (Microsoft's designation for the GRU-linked actor also tracked as APT28/Fancy Bear, and formerly as STRONTIUM) accessed OpenAI's LLM services (ChatGPT/GPT-4-family models) using accounts that Microsoft and OpenAI's joint threat-intelligence collaboration subsequently attributed to the group. The actor used the LLM in two documented ways: first, as an open-source research assistant to investigate satellite communication protocols, radar imaging technologies, and specific technical parameters, subject matter directly relevant to conventional military operations in the context of Russia's war in Ukraine; second, as a coding aid, where the LLM provided "LLM-enhanced scripting techniques" covering file manipulation, data selection, regular expressions, and multiprocessing, meaning help writing or refining scripts to automate technical tasks. Microsoft explicitly characterized this as "LLM-informed reconnaissance," using the model to accelerate and structure research the actor could otherwise have done manually via search engines and public documentation, rather than any novel LLM-enabled attack technique. Microsoft's Threat Intelligence team (which tracks more than 300 threat actors, including roughly 160 nation-state groups) and OpenAI cross-referenced known threat-actor indicators/infrastructure with account activity to attribute the usage to Forest Blizzard, then acted under a jointly announced set of principles: disable the offending accounts, terminate service access, and publicly disclose the detected misuse together with mitigation steps.
There was no human-facing lure; this incident is AI-service misuse/recon automation rather than social engineering of a victim. The "tell" that exposed it was on the defender side: Microsoft Threat Intelligence (which tracks 300+ threat actors, including ~160 nation-state groups, via known infrastructure, tooling, and behavioral indicators) and OpenAI's account-abuse monitoring correlated LLM-account query activity, open-source research requests centered on satellite communication protocols, radar imaging technology, and specific technical parameters, plus scripting-assistance requests involving file manipulation, regex, and multiprocessing, with known Forest Blizzard tradecraft and infrastructure, enabling attribution and account takedown before any confirmed downstream compromise was reported.
OpenAI terminated the accounts associated with Forest Blizzard as part of a coordinated takedown that also hit four other state-affiliated actors (North Korea's Emerald Sleet, Iran's Crimson Sandstorm, and China's Charcoal Typhoon and Salmon Typhoon). Microsoft stated that "all accounts and assets associated with Forest Blizzard have been disabled." Neither company identified a specific victim organization or confirmed that the LLM-assisted research led to a successful intrusion or compromise; Microsoft characterized the observed behavior overall as consistent with attackers "using AI as another productivity tool" rather than evidence of new, AI-enabled attack capability. No breach, data theft, or financial loss was attributed to this specific activity.
This was one of the first major, jointly attributed public disclosures by a leading AI vendor (OpenAI) and a leading security vendor (Microsoft) confirming that a well-known nation-state APT group, GRU-linked APT28/Fancy Bear, with a long history of election interference and military-intelligence-driven cyber operations, was directly using commercial generative-AI chatbot services for OSINT-style reconnaissance and technical scripting support. It matters less for scale of damage (none was disclosed) than as an early, concrete case study establishing that state threat actors treat mainstream LLMs as a research and productivity accelerator for sensitive technical domains (here, satellite/radar systems tied to a live military conflict), and it set a public template, the "principled approach" of detect, disable, notify peer vendors, and disclose, that other AI providers have since followed for similar nation-state AI-abuse findings.
Both companies described a "principled approach": (1) identify and act against malicious use of Microsoft/OpenAI AI APIs/services by tracked APTs, APMs, or cybercrime syndicates, disabling accounts, terminating services, limiting resource access; (2) notify other AI service providers when a threat actor is detected using their AI systems, sharing data so they can independently verify and act; (3) collaborate with other stakeholders (industry/government) to exchange threat-actor AI-use intelligence; (4) transparency, publicly disclose detected AI misuse and actions taken. Concretely for this case: OpenAI terminated the accounts associated with Forest Blizzard (and four other state-affiliated actors, Emerald Sleet/North Korea, Crimson Sandstorm/Iran, Charcoal Typhoon and Salmon Typhoon/China); Microsoft stated "all accounts and assets associated with Forest Blizzard have been disabled." Broader recommended defenses for the sector: monitor for anomalous LLM-account query patterns tied to sensitive technical domains (satellite/radar/military-adjacent research), cross-vendor AI-abuse intelligence sharing, and treating LLM outputs used in adversary tooling as a new but currently incremental (not novel-technique-enabling) layer of existing OSINT/recon tradecraft.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…
Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup, caught two separate job candidates using real-time AI deepfake video filters to…