Russian Hackers Used ChatGPT to Create Malware Hidden in a Gaming Tool
Cybersecurity is facing a new type of threat—Russian hackers have begun using the ChatGPT artificial intelligence as a programming assistant when developing malicious software. The operation, dubbed "ScopeCreep," is a troubling example of how state-sponsored attackers can misuse generative AI technologies to accelerate and enhance their cyber campaigns.
What Exactly Did ScopeCreep Do?
The ScopeCreep group chose a sophisticated strategy to distribute its malware through a trojanized version of the popular gaming tool Crosshair X, which serves as an overlay for gamers. This approach is particularly insidious because it targets the gaming community, whose members often download various tools and modifications to improve their gaming experience. Users who downloaded the fake version of this tool inadvertently installed sophisticated malware on their Windows systems.
The technical sophistication of this malware is remarkable. Once launched, it first deploys a loader that downloads additional payloads from a remote server, then escalates system privileges and establishes persistence to survive computer restarts. The malware uses advanced evasion techniques, including DLL sideloading and Base64 obfuscation. Particularly dangerous is its ability to disable Windows Defender using PowerShell commands and subsequently steal login credentials, tokens, and cookies from victims' web browsers.
Hackers Used ChatGPT
What makes this operation exceptional is the way the hackers used ChatGPT. They used it to iteratively develop and refine their code, specifically to debug Go code for HTTPS requests and Telegram API integration. The hackers used a Telegram channel to send themselves notifications about new victims. For security reasons, they used multiple temporary ChatGPT accounts, using each account for only one query to minimize the risk of their operation being detected.
Fortunately, OpenAI, in collaboration with security partners, quickly identified and blocked the malicious accounts before the malware could spread to the wider public. The company also worked to remove the associated code repositories. According to OpenAI's official statement, the ScopeCreep campaign was disrupted in its early stages, significantly limiting its potential damage. However, this incident serves as a warning sign for the entire cybersecurity sector and demonstrates the need to monitor how cyberattackers' misuse of AI technologies evolves.



