Chinese Threat Actor Targets OpenAI With Spear-Phishing Attacks
OpenAI has disclosed that its employees were targeted by spear-phishing attacks launched by a suspected Chinese state-sponsored threat actor.
The phishing attempts were unsuccessful. Notably, the threat actor also abused OpenAI’s own products to assist in the campaign.
“We identified and banned accounts, which based on an assessment from a credible source likely belonged to a suspected China-based adversary, that were attempting to use our models to support their offensive cyber operations while simultaneously conducting spear phishing attacks against our employees and governments around the world,” OpenAI says.
“Publicly tracked as SweetSpecter, this adversary emerged in 2023. We understand this is the first time their targeting has publicly been identified to include a U.S.-based AI company, with their previous activity reported as having focused on political entities in the Middle East, Africa, and Asia.”
The threat actor sent phishing emails to corporate and personal email addresses of OpenAI employees, asking for help with ChatGPT errors. The emails contained attachments designed to install malware.
“In these emails, SweetSpecter posed as a ChatGPT user asking for support from the targeted employees,” the company says. “The emails included a malicious attachment called ‘some problems.zip’, containing an LNK file. This file contained code that would, if opened, present a DOCX file to the user that listed various apparent error and service messages from ChatGPT.
In the background, however, Windows malware known as SugarGh0st RAT would be decrypted and executed. The malware is designed to give SweetSpecter control over the compromised machine and allow them to do things like execute arbitrary commands, take screenshots, and exfiltrate data.”
New-school security awareness training can give your organization an essential layer of defense against phishing attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
OpenAI has the story.
Free BreachSim Tool
How easy is it for bad actors to penetrate your system and exfiltrate your data? Pinpoint vulnerabilities, take action and build stronger cyber defenses with KnowBe4’s Breach Simulator “BreachSim.” Based on techniques outlined in the MITRE Att&CK framework, BreachSim launches 12+ simulated scenarios to uncover the stark reality of what happens when employees unknowingly fall for an attack.
How BreachSim works:
- 100% harmless simulation of real breach and data exfiltration attacks
- Provides secure .txt, .doc, and .bmp test files for the simulation
- Tests 12+ realistic data exfiltration scenarios following the MITRE Att&CK framework
- Just download the installer, upload the secure test files, and run
Results in a few minutes!
PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/breached-password-test-partner?partnerid=001a000001lWEoJAAW