OpenAI pulled the plug on a cluster of accounts it says Russian-speaking criminal groups were using to build hacking tools.
The company's latest threat report describes accounts that used its models to write malware loaders - code that quietly installs a bigger payload once a victim machine is compromised. The same accounts built evasion layers meant to dodge antivirus and endpoint detection, plus credential-theft scripts aimed at harvesting logins. OpenAI also found its models being used to help stand up command-and-control, or C2, infrastructure - the servers attackers use to remotely direct infected machines. Once the company spotted the pattern, it banned the accounts behind it.
This is the unglamorous, high-volume side of AI misuse: not chatbots scheming world domination, but criminals using a capable assistant to write boilerplate exploit code faster than they could by hand. It also puts OpenAI in the same spot email providers and cloud hosts have occupied for years - running a constant, mostly invisible moderation effort against people actively trying to route around it.
Expect more bans like this one. The tooling gets easier to build, so the takedown notices are going to keep coming.