August 15, 2026 01:48 am (IST)
Follow us:
facebook-white sharing button
twitter-white sharing button
instagram-white sharing button
youtube-white sharing button
Ajit Doval breaks silence on Operation Sindoor in Discovery’s explosive new docuseries | Rahul Gandhi's 'mock hug' taunt sparks row; Centre stresses 'mutual respect' with Italy | Delhi on high alert: Bomb threat to High Court, airport and multiple locations ahead of I-Day | ‘Who are they to interfere?’: CJI Surya Kant slams Bar Council of India over NALSAR students’ enrolment row | 'Shows how low Congress has sunk': BJP slams Rahul Gandhi over Modi foreign policy jibe | From guns to glamour: Former women Maoists walk the ramp in Chhattisgarh | Netaji row: Suvendu Adhikari govt strips BJP MP Anant Maharaj of state honour | Sukhbir Badal attacked by Nihang Sikh with kirpan at Maharashtra gurdwara; assailant detained | ‘If you cannot do it, we will pass an order’: Supreme Court’s final warning to Centre on food labels | ‘Time to move on’: Bombay HC sends strong message in Vijay Mallya-bank dispute
Photo Courtesy: Pixabay

Microsoft says hackers from Russia, China, Iran, DPRK exploiting AI tools

| @indiablooms | Feb 15, 2024, at 07:13 am

Washington: Microsoft said on Wednesday that hacker groups allegedly linked to Russia, China, Iran and North Korea are exploiting its OpenAI tools to enhance their cyberoperations.

All four countries deny involvement in cyber attacks.

"In collaboration with OpenAI, we are sharing threat intelligence showing detected state-affiliated adversaries—tracked as Forest Blizzard, Emerald Sleet, Crimson Sandstorm, Charcoal Typhoon, and Salmon Typhoon— using LLMs [large language models] to augment cyberoperations," Microsoft said in a report.

The company alleged that Forest Blizzard is a "highly effective Russian military intelligence actor" linked to the Main Directorate of the General Staff of the Armed Forces.

"Its activities span a variety of sectors including defense, transportation/logistics, government, energy, NGOs, and information technology," the report stated.

North Korea's Emerald Sleet allegedly uses Artificial Intelligence to get expert opinions on North Korea. Content generation is likely to be used in phishing campaigns, the report said.

Crimson Sandstorm is an "Iranian threat actor" purportedly connected to the Islamic Revolutionary Guard Corps, according to Microsoft. "The use of LLMs has involved requests for support around social engineering, assistance in troubleshooting errors, .NET development, and ways in which an attacker might evade detection when on a compromised machine," the report said.

The company also identified two Chinese groups of concern.

Charcoal Typhoon, according to Microsoft, mostly focuses on tracking groups and individuals in Taiwan, Thailand, Mongolia, France, Nepal and globally who oppose Beijing's policies.

Another group, Salmon Typhoon, has been assessing the effectiveness of using LLMs throughout 2023 to source information on potentially sensitive topics, the report said.

"Our research with OpenAI has not identified significant attacks employing the LLMs we monitor closely," the report stated.

Microsoft reassured clients that the company has taken measures to disrupt assets and accounts associated with the alleged threat actors and shape the guardrails and safety mechanisms around its models.

(With UNI/SPUTNIK inputs)

Support Our Journalism

We cannot do without you.. your contribution supports unbiased journalism

IBNS is not driven by any ism- not wokeism, not racism, not skewed secularism, not hyper right-wing or left liberal ideals, nor by any hardline religious beliefs or hyper nationalism. We want to serve you good old objective news, as they are. We do not judge or preach. We let people decide for themselves. We only try to present factual and well-sourced news.

Support objective journalism for a small contribution.