Threat actors linked to Iran are increasingly using artificial intelligence to enhance their cyber operations, according to a report from Recorded Future. State-linked and hacktivist groups have used generative AI and large language models for malware development, research on industrial control systems, and multilingual phishing campaigns.
“AI has not transformed Iran into a fundamentally different cyber power, but it has compressed the distance between intent and action,” said Alexander Leslie, senior advisor at Recorded Future. Iranian groups have used LLMs to map industrial control systems, research exploitation techniques, and sustain phishing conversations in languages their human operators may not speak fluently.
Specific examples include the threat group MuddyWater, which used AI to develop four malware variants through malicious Office documents targeting organizations in the Middle East and North Africa. The Iran-nexus group tracked as Ababil of Minab used ChatGPT to refine scripts for database enumeration during an attack against a US-based GPS technology firm.
OpenAI previously disclosed efforts by the Iran-linked CyberAv3ngers group to use ChatGPT for reconnaissance on programmable logic controllers. Iran has also worked closely with Russia and China to enhance its AI capabilities, and analysts warn the country could begin using Chinese frontier AI models to power its offensive cyber operations.

