WormGPT: A Cybercriminal's AI Companion

Nov 01, 2023
WormGPT: A Cybercriminal's AI Companion

As discussions surrounding Low-Level Models (LLMs) tailored for cyberattacks began surfacing on Dark Web forums in early July, they soon found their way onto the Telegram messaging platform. These tools, often available through subscription models, cater to prospective attackers. They resemble mainstream LLMs but lack safety measures, being trained on datasets conducive to enabling cyberattacks.

WormGPT emerges as a front-runner among AI tools harnessing generative AI for malicious intents. This module, rooted in the GPTJ language model and crafted in 2021, has already been implicated in Business Email Compromise (BEC) exploits among other malevolent activities.

The simplicity of WormGPT's operation is alarming. Users can input commands to craft fraudulent emails, for instance, instructing, "Compose an email impersonating a bank, aimed at deceiving the recipient into disclosing their login details."

In response, WormGPT fabricates a distinctive, often ingenious and grammatically impeccable email that significantly surpasses the persuasive ability of most BEC attackers, as per several analysts. For instance, cybersecurity researcher Daniel Kelley uncovered a scam email generated by WormGPT that was not only exceedingly persuasive but also strategically astute.

The purported developer of WormGPT disclosed its foundation on the open-source GPTJ language model by EleutherAI. He is reportedly advancing towards integrating Google Lens (allowing the chatbot to send images alongside text) and facilitating API access.

The conventional method of spotting fraudulent phishing emails has been through their dubious wording. However, with the advent of AI tools like WormGPT, this line of defense is now obliterated, posing new challenges in the cybersecurity landscape.

 

Want to learn more?

Join us in the Cyber Defense Army communities to learn more and discuss approaches others are using to defend their organizations.

Stay connected with news and updates!

Join our mailing list to receive the latest news and updates from our team.
Don't worry, your information will not be shared.

We hate SPAM. We will never sell your information, for any reason.