engblogs

summaries of the latest blog articles from your favorite tech companies.
OpenAIOpenAI

Operation “VAGue Focus”: Social engineering and influence activity

Case study detailing OpenAI's takedown of the 'VAGue Focus' network that used ChatGPT to generate social media posts, translate emails, and coordinate covert influence and intelligence-gathering across European and Turkish fronts.

6/1/2025
OpenAIOpenAI

Operation “ScopeCreep”: Russian-speaking malware development

A technical examination of Operation ScopeCreep, detailing how a Russian-speaking actor used AI-assisted development to build Windows malware, distribute a trojanized loader, and employ multi-stage execution, evasion, and C2, leading to rapid detection and takedown.

6/1/2025
OpenAIOpenAI

Vixen and Keyhole Panda: China-linked cyber operations

Technical case study analyzing China-linked threat actors Vixen Panda and Keyhole Panda, their use of AI-assisted research, scripting, and infrastructure operations, and OpenAI's response to curb abuse of models for reconnaissance, exploitation, and automation.

6/1/2025
OpenAIOpenAI

Operation “VAGue Focus”: Social engineering and influence activity

Case study of Operation VAGue Focus revealing how a small network used ChatGPT to generate social media posts and translated messages to conduct covert influence and intelligence-collection activities under sham European/Turkish media brands.

6/1/2025
OpenAIOpenAI

Deceptive Employment Scheme: IT worker activity

A technical deep-dive into AI-powered deceptive employment campaigns that target IT and software roles, detailing automated résumé generation, persona fabrication, remote-work setup tools, and DPRK-linked operators leveraging AI across the recruitment and credentialing process.

6/1/2025
OpenAIOpenAI

Operation “ScopeCreep”: Russian-speaking malware development

A technical case study of ScopeCreep, a Russian-speaking malware operation that used AI-assisted development to build a stealthy, multi-stage loader, evade detection, and exfiltrate data via a covert C2 channel.

6/1/2025
OpenAIOpenAI

Vixen and Keyhole Panda: China-linked cyber operations

PRC-linked threat actors Vixen Panda and Keyhole Panda leveraged AI to assist vulnerability research, scripting, and infrastructure setup, with LLM ATT&CK mappings and security policy implications.

6/1/2025
OpenAIOpenAI

Operation “Helgoland Bite”: German-language influence activity

Helgoland Bite demonstrates a coordinated, Russian-linked AI-generated German-language influence operation distributed across Telegram and X, tied to the Pravda network and the covert Portal Kombat ecosystem, including translation work and posting-time coordination to support AfD.

6/1/2025
OpenAIOpenAI

Deceptive Employment Scheme: IT worker activity

Technical case study on AI-driven deceptive employment campaigns that automate resumes, fabricate personas, and recruit for remote jobs, revealing DPRK-linked actors, contractor networks, and techniques to bypass geolocation and endpoint security controls.

6/1/2025
OpenAIOpenAI

Operation “High Five”: Philippines political comments

Technical case study detailing how ChatGPT was used to analyze Philippine political discourse, generate bulk short comments for TikTok and Facebook, and craft PR pitches as part of a covert political-influence operation.

6/1/2025
OpenAIOpenAI

Operation “ScopeCreep”: Russian-speaking malware development

An in-depth case study of Operation ScopeCreep showing how a Russian-speaking threat actor leveraged AI-assisted development to craft stealthy Windows malware with multi-stage delivery, obfuscation (Themida), privilege escalation, and covert C2 communications.

6/1/2025
OpenAIOpenAI

Operation “Uncle Spam”: US polarization influence activity

Analyzing Operation Uncle Spam—a China-origin influence operation that used AI-generated content and fake personas to polarize US political discourse and harvest profile data from platforms like X and Bluesky.

6/1/2025