Eigen RadarAI
Analysis

OpenAI shuts ChatGPT accounts used in a Russia-origin influence operation

OpenAI says it shut Russia-origin accounts producing material for a purported Israel-based institute, while TeamT5 reports wider AI use by Chinese state-backed hacking groups.

Artificial Intelligence··Evening
On a bright forensic table, anonymous network nodes carrying blank message cards are cut off at a closed gateway.

TeamT5 names DeepSeek as attackers' most-used tool

Taiwanese security company TeamT5 says Chinese state-backed hacking groups have more than doubled their attacks since adopting AI models for routine work and malware development. It names DeepSeek as the tool used most often; chief analyst Charles Li attributes that preference to the model being relatively powerful while carrying low cyber guardrails. TeamT5 links exploit-code work to a group it calls Grimfengxi, IP collection and domain mapping to Teleboyi, and Claude Code use to Slime22. The company did not publish the attack counts behind its doubling claim.[1]

Russian prompts became English-language comments

OpenAI said it banned a cluster of Russia-origin ChatGPT accounts. According to the company, the accounts created material for the International Burke Institute, presented as an expert community based in Israel, and for a sovereignty index that praised Russia while criticising France, Germany and the US. Operators accessed the models through VPNs, used Russian prompts to generate English-language comments and asked ChatGPT to mask linguistic signs of their origin. The output appeared on Substack, Telegram, X, Facebook and LinkedIn. The institute's website was registered in February 2025 and carried articles copied from real academic work, sometimes with false attribution.[2]

One report withholds counts; the other finds limited reach

A UK AI Safety Institute study cited by TeamT5 finds that open-source models' cyber capabilities have risen sharply while still trailing Western frontier models in fully autonomous attacks. TeamT5 does not provide raw numbers for its own reported increase in attacks. OpenAI places the influence operation it disrupted at the lower end of category three on the Brookings Breakout Scale. In the company's account, that means the material appeared across several platforms but reached real audiences only to a limited degree. The reports therefore identify expanded uses of AI while leaving different boundaries: TeamT5 withholds the counts needed to check attack volume, and OpenAI characterises the operation it observed as limited in reach.[1], [2]

References

  1. News sourceTHE DECODERChinese state-backed groups more than doubled their attacks after picking up AI tools↩1↩2
  2. News sourceOpenAIOpenAI shuts Russian accounts behind an institute presented as Israel-based↩1↩2