OpenAIOperation “VAGue Focus”: Social engineering and influence activity
Case study detailing OpenAI's takedown of the 'VAGue Focus' network that used ChatGPT to generate social media posts, translate emails, and coordinate covert influence and intelligence-gathering across European and Turkish fronts.
OpenAIOperation “ScopeCreep”: Russian-speaking malware development
A technical examination of Operation ScopeCreep, detailing how a Russian-speaking actor used AI-assisted development to build Windows malware, distribute a trojanized loader, and employ multi-stage execution, evasion, and C2, leading to rapid detection and takedown.
OpenAIVixen and Keyhole Panda: China-linked cyber operations
Technical case study analyzing China-linked threat actors Vixen Panda and Keyhole Panda, their use of AI-assisted research, scripting, and infrastructure operations, and OpenAI's response to curb abuse of models for reconnaissance, exploitation, and automation.
OpenAIOperation “VAGue Focus”: Social engineering and influence activity
Case study of Operation VAGue Focus revealing how a small network used ChatGPT to generate social media posts and translated messages to conduct covert influence and intelligence-collection activities under sham European/Turkish media brands.
OpenAIDeceptive Employment Scheme: IT worker activity
A technical deep-dive into AI-powered deceptive employment campaigns that target IT and software roles, detailing automated résumé generation, persona fabrication, remote-work setup tools, and DPRK-linked operators leveraging AI across the recruitment and credentialing process.
OpenAIOperation “ScopeCreep”: Russian-speaking malware development
A technical case study of ScopeCreep, a Russian-speaking malware operation that used AI-assisted development to build a stealthy, multi-stage loader, evade detection, and exfiltrate data via a covert C2 channel.
OpenAIVixen and Keyhole Panda: China-linked cyber operations
PRC-linked threat actors Vixen Panda and Keyhole Panda leveraged AI to assist vulnerability research, scripting, and infrastructure setup, with LLM ATT&CK mappings and security policy implications.
OpenAIOperation “Helgoland Bite”: German-language influence activity
Helgoland Bite demonstrates a coordinated, Russian-linked AI-generated German-language influence operation distributed across Telegram and X, tied to the Pravda network and the covert Portal Kombat ecosystem, including translation work and posting-time coordination to support AfD.
OpenAIDeceptive Employment Scheme: IT worker activity
Technical case study on AI-driven deceptive employment campaigns that automate resumes, fabricate personas, and recruit for remote jobs, revealing DPRK-linked actors, contractor networks, and techniques to bypass geolocation and endpoint security controls.
OpenAIOperation “High Five”: Philippines political comments
Technical case study detailing how ChatGPT was used to analyze Philippine political discourse, generate bulk short comments for TikTok and Facebook, and craft PR pitches as part of a covert political-influence operation.
OpenAIOperation “ScopeCreep”: Russian-speaking malware development
An in-depth case study of Operation ScopeCreep showing how a Russian-speaking threat actor leveraged AI-assisted development to craft stealthy Windows malware with multi-stage delivery, obfuscation (Themida), privilege escalation, and covert C2 communications.
OpenAIOperation “Uncle Spam”: US polarization influence activity
Analyzing Operation Uncle Spam—a China-origin influence operation that used AI-generated content and fake personas to polarize US political discourse and harvest profile data from platforms like X and Bluesky.