{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/microsoft-openai-state-actors-llm-use-2024/",
 "asOf": "2026-09-26",
 "id": "microsoft-openai-state-actors-llm-use-2024",
 "date": "2024-02-14",
 "datePrecision": "day",
 "title": "Microsoft and OpenAI report state-backed hackers using LLMs as a productivity tool",
 "lane": "attack",
 "kind": "misuse-report",
 "summary": "Microsoft Threat Intelligence, publishing jointly with OpenAI, describes five state-affiliated actors from Russia, North Korea, Iran and China using LLMs for tasks such as research, scripting help and drafting phishing content. Microsoft says it and OpenAI had not seen novel or unique AI-enabled attack techniques, and that assets and accounts associated with the actors were disrupted.",
 "whyItMatters": "It is the earliest provider disclosure in this record of named state actors using LLMs, and the baseline that later reports of agentic misuse are measured against.",
 "actors": [
  "microsoft",
  "openai",
  "apt28"
 ],
 "topics": [
  "threat-intelligence",
  "ai-enabled-intrusion"
 ],
 "atlas": [],
 "artifacts": [],
 "sources": [
  {
   "url": "https://www.microsoft.com/en-us/security/blog/2024/02/14/staying-ahead-of-threat-actors-in-the-age-of-ai/",
   "publisher": "Microsoft Security",
   "title": "Staying ahead of threat actors in the age of AI",
   "date": "2024-02-14",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Names five state-affiliated actors: Forest Blizzard (Russia), Emerald Sleet (North Korea), Crimson Sandstorm (Iran), and Charcoal Typhoon and Salmon Typhoon (China).",
   "locator": "Threat actor sections"
  },
  {
   "fact": "Microsoft states that it and OpenAI had not observed particularly novel or unique AI-enabled attack or abuse techniques from these actors.",
   "locator": "Introduction"
  },
  {
   "fact": "Microsoft announces principles for acting against threat actors using its AI services, including disabling accounts and notifying other AI providers.",
   "locator": "A principled approach to detecting and blocking threat actors"
  }
 ],
 "significance": 4,
 "fideQuestions": [],
 "methods": [],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}