Hello readers! Think about the email sent by your company CEO requesting you to process an urgent payment. Everything looks professionally done – from the language to the request itself. Would you follow it?
This is the kind of situation that made Worm GPT so popular among security experts.
As opposed to traditional AI technology, WormGPT appeared in 2023 and was designed as a malicious tool that would assist criminals in crafting phishing messages, business email compromises, social engineering texts, as well as any malicious code. What is more, it removed all possible restrictions on users that prevent people from generating harmful content.
What made WormGPT AI dangerous is the way it made cybercrimes easier. The person attacking the company did not necessarily need to be an accomplished writer or know a lot about social engineering.
Definition and Origin of WormGPT
Worm GPT first appeared in March 2023 on the most common cybercrime forums and was extensively discussed by security experts as of July 2023. WormGPT was designed by a threat actor under the pseudonym "Last" as "the blackhat alternative to GPT models". It was sold as a subscription service for approximately €60-€100 monthly or €550 annually, offering its subscribers access via a private web interface.
The tool was allegedly based on GPT-J, which is an open-source Large Language Model (LLM) designed by EleutherAI back in 2021. GPT-J is an official LLM and is open-source; however, the WormGPT author fine-tuned and retrained the LLM using data related to the creation of malware, phishing, and various types of attack methods.
This resulted in a chatbot equipped with a powerful generative artificial intelligence with no content moderation, ethics, or constraints on its capabilities.
According to reports, in late August 2023, the author shut down the publicly available version of Worm GPT out of concerns about the media attention and possible legal investigations. However, cybersecurity specialists noticed that copies of the tool and its successors (such as FraudGPT, DarkBARD, and Evil-GPT) rapidly emerged in dark web marketplaces. The basic idea behind the above is still very much alive.
How does WormGPT Function?
On a fundamental level, WormGPT functions as a generative AI chatbot. The user provides a prompt, and the system produces a textual response. What distinguishes WormGPT is what it will be willing to generate.
Popular AI programs such as ChatGPT, Google Gemini, and Microsoft Copilot come with safety filters to prevent the generation of phishing emails, malware, and other types of dangerous content. However, Worm GPT lacks these limitations.
According to reports, WormGPT's training data consists of:
Malware code and techniques of its development;
Phishing templates and social engineering approaches;
Exploits and vulnerabilities;
Business email compromise and other fraud techniques.
For instance, a hacker can ask the WormGPT model to write a business email to deceive the employee into making an immediate payment. Such a request will result in a nicely formatted text with persuasive language.
The multilingual capacity of WormGPT adds to the effectiveness of phishing due to fewer grammatical and language mistakes.
ChatGPT Vs WormGPT
Feature | ChatGPT | WormGPT |
Ethical guardrails | Extensive safety filters and content policies | No restrictions |
Developer | OpenAI | Anonymous threat actor (‘Last’) |
Availability | Public (free and paid tiers) | Subscription-based, and dark web forums |
Training data | Broad internet text, filtered and curated | Supplemented with phishing, malware, and exploit data |
Intended use | Education, productivity, and creative data | Cybercrime-BEC, phishing, malware generation |
Content moderation | Active-denies harmful requests | None-fulfils any requests |
Legal status | Legal | Illegal |
Language support | Multilingual | Multilingual |
What Makes WormGPT Dangerous?
Lack of Guardrails and Ethics Filters
Worm GPT generates text based on prompts that other AI systems refuse to process – for instance, creating malware, crafting spear-phishing emails, or generating impersonation emails that target individual victims.
Automation and Scaling
Since LLMs can produce high-quality text instantaneously, an attacker could create thousands of emails that can be sent out immediately.
Increased Ability to Deceive
The output of WormGPT Instagram is generally more coherent, contextually accurate, and grammatically correct than what would be written by hand.
Rapid Emergence of Variants
In response to countermeasures that target some tools, others appear – like FraudGPT, KawaiiGPT, or other variants based on Grok, Mixtral, or other architectural models.
How Do Criminals Utilize the Worm GPT?
It is important for security experts to know the possible use cases of WormGPT in practice. Hackers and cybercriminals have explored WormGPT for Insta to access various details on this.
Phishing Attacks and BEC (Business Email Compromise)
The model can generate convincing emails in the style of a person who plays an executive, vendor, or partner. It is capable of altering the tone of emails depending on the BEC technique used.
When it comes to phishing attacks, you should also know about AI-powered phishing attacks, which have been on the rise.
Social Engineering
A generative AI can immediately transform the message or rewrite it into another language; in such a way, the attacker does not have to be a fluent speaker of any particular language.
Malware Code Generation
Attackers can generate some code using the model – it will generate code snippets, obfuscate scripts, or assist with writing malware. Even though the generated code may not be ready for use, it considerably decreases attackers’ workload.
Research Assistance and Reconnaissance
Attackers can ask the illicit LLM for explanations of vulnerabilities, exploitation techniques, and lists of common misconfigurations that would be banned or edited in legitimate AI systems.
How to Defend Against Worm GPT?
Utilize AI-Powered Mail Security
Conventional email gateways use blocklists and known signatures, which are insufficient against AI-generated content. This is why you need to deploy modern email security solutions which uses ML (Machine Learning), and NLP (Natural Language Processing) to analyse the tone, intent, and context of messages. This is how you can detect anomalies even while the content is visually convincing and grammatically flawless.
Upgrade Your Security
Upgrade your security and arrange security awareness campaigns to educate your employees. It is your best way to protect yourself from AI-enabled phishing attacks. Emphasize the need for verification processes where all strange requests, especially financial ones, should be verified through other means of communication.
Simulation of phishing attacks involving AI-generated content is useful for training staff.
Implement Verification Procedures Rigorously
Such verification processes would help prevent costly mistakes. Organizational policies should require several levels of approval whenever there are wire transfers or changes in payment transactions. Large transaction amounts should be verified over the phone or in person in addition to the use of challenge phrases or code words.
Apply Layered Security Approach
As no single security approach is enough to fend off AI attacks, companies should employ several security approaches. On the other hand, EDR technologies can also be employed to detect malware.
In this regard, employing endpoint management will also be useful.
WormGPT and Business Email Compromise
BEC entails deception through impersonation of trusted personnel like executives, suppliers, or other workers to affect financial or business-related decisions.
Worm GPT could help in creating convincing communication related to these frauds. It’s not simply a matter of grammar or typos since artificial intelligence can craft credible messages.
In fact, an employee could receive an urgent request for payment that seems to be sent by a high-level executive but looks perfectly authentic. That is why organizations need to depend on credible verification methods instead of appearances. Any requests for money, credentials, or sensitive data should be independently verified.
Is WormGPT Reshaping Cybercrime by Bringing About a New Cyber Crime?
No. WormGPT has not been responsible for inventing any of these cybercrimes such as phishing, BEC, malware, and social engineering. These cybercrimes existed long before the arrival of AI.
What is new here is the increased speed and scalability of such cybercrimes. Instead of taking several hours to compose each message for an attacker, they can easily do so by employing AI.
What Does WormGPT Reveal about AI and Cybersecurity?
What can be concluded based on WormGPT? The main conclusion that can be drawn is that AI can eliminate friction in cybercrime. It allows the attacker to lower the requirement for technical and writing skills, time, and linguistic proficiency.
It doesn't necessarily mean that attacks would inevitably be successful, however. Employees will have to go beyond grammar errors in recognizing phishing attempts, and cybersecurity teams will have to focus on behavior rather than signatures.
Furthermore, the organization can strengthen the validation process of all critical and financial requests and not rely only on emails. In general, it is important to strengthen the security process as a whole and not concentrate only on the technologies used by the attackers.
In regard to cybersecurity, you should know about cybersecurity maturity.
Conclusion
WormGPT became a tool for criminals due to the combination of generative AI and a deliberate readiness to assist in the creation of harmful content. This shows how uncontrolled AI would enable improvements in phishing, social engineering, BEC schemes, and other criminal activities in cyberspace.
The original WormGPT service was eventually shut down; however, the core concept has remained valid. People used to access WormGPT Instagram profile to learn more about this.
It is clear that the key takeaway here is quite obvious: a professionally made email is not necessarily a safe email.
Organizations should consider combining email protection measures, MFA, behavior monitoring, user training, and third-party confirmation of sensitive actions.
Despite AI boosting the speed while making the attacks believable, businesses need to utilize proper security measures to prevent such attacks.
FAQs (Frequently Asked Questions)
Q1. When was WormGPT released?
March, 2023.
Q2. Can hackers use WormGPT at present?
No. But this tool has some variants available under different names.
Q3. Did the FBI give a warning about WormGPT?
Yes.
Q4. What other things did the FBI do to defend against this malicious AI tool?
They advised security professionals to employ proper security measures to defend against such AI tools.
