Even as Iran maintains a truce with the United States, its cyberwar operations are accelerating — and Western AI models, including ChatGPT and Gemini, are playing a central role.
The Financial Times reported May 31 that Iran has been using ChatGPT and Gemini to develop malware and produce phishing messages in Hebrew and Arabic, drawing heavily on AI tools built by Western companies to sustain its cyber offensive.
Iranian operatives continue to lure targets into clicking suspicious links. The FT also reported that advances in AI have enabled them to create fake personas to deceive targets in the United States and Israel.
Iranian government accounts on social media also regularly circulate posts and videos mocking U.S. President Donald Trump — a form of propaganda in which AI models help generate the content.
The cyberwar has continued through the truce period, inflicting significant damage on U.S. allies. The United Arab Emirates is absorbing more than 500,000 cyberattacks a day, with Iran using ChatGPT to mount the offensive. Israel, meanwhile, has been bombarded with phishing emails and text messages designed to recruit targets as informants for Iranian intelligence.
Google disclosed in February — just before the war with Iran began — that it had detected the Iranian government-backed hacking group APT42 using Gemini for cyberwarfare purposes. Last year, Google also confirmed that Iranian hackers used Gemini far more than their counterparts from North Korea, Russia and China. APT42 is also reported to have used Gemini to research methods for jamming U.S. Air Force F-35 fighter jets.
The FT said Iranian hackers, who have been experimenting with AI for years, have become an increasingly formidable threat as they harness more powerful new AI models.
OpenAI, the maker of ChatGPT, said in a statement that it had determined Iranian hackers used the service for research, translation, debugging and scripting support, and that it regularly identifies and blocks attempts to misuse its platform. "When we identify harmful activity, we take immediate action — including deactivating accounts, blocking access and restricting misused features," OpenAI said, adding that its most advanced models with safety guardrails "are restricted from broad availability."
kate01@heraldcorp.com
