Microsoft Threat Intelligence, publishing jointly with OpenAI, describes five state-affiliated actors from Russia, North Korea, Iran and China using LLMs for tasks such as research, scripting help and drafting phishing content. Microsoft says it and OpenAI had not seen novel or unique AI-enabled attack techniques, and that assets and accounts associated with the actors were disrupted.
Why it matters
It is the earliest provider disclosure in this record of named state actors using LLMs, and the baseline that later reports of agentic misuse are measured against.
Key facts
As stated in the sources, with where to find them.
- Names five state-affiliated actors: Forest Blizzard (Russia), Emerald Sleet (North Korea), Crimson Sandstorm (Iran), and Charcoal Typhoon and Salmon Typhoon (China).Threat actor sections
- Microsoft states that it and OpenAI had not observed particularly novel or unique AI-enabled attack or abuse techniques from these actors.Introduction
- Microsoft announces principles for acting against threat actors using its AI services, including disabling accounts and notifying other AI providers.A principled approach to detecting and blocking threat actors
Findings that cite this record
Sources
Related records
Jan 24, 2024
Sep 25, 2026
Jan 29, 2025
Sep 16, 2026
Sep 8, 2026
September 2026