News + Trends

WormGPT: This chatbot creates perfect phishing emails

Florian Bodoky
17.7.2023
Translation: machine translated

We know that dubious things can also be done with A.I.. But WormGPT takes this to a whole new level. The chatbot was specially developed to generate malware and phishing emails. It requires hardly any prior knowledge.

The security experts at Slashnext.com have come across a new chatbot in a forum: WormGPT helps with illegal activities online. The artificial intelligence creates phishing emails or develops malicious code on request. According to Slashnext author Daniel Kelley, WormGPT has been available for purchase in a forum since the beginning of July. A beta version has been available since March. The bot could therefore already be in use.

Unconscious language genius and Python pro

WormGPT lacks ethical guidelines of any kind, which sets it apart from other chatbots such as ChatGPT or Bard. The lack of restrictions means that it does not reject or ignore "malicious" requests. This makes it a powerful tool for illegal endeavours.

The chatbot is offered in relevant forums.
The chatbot is offered in relevant forums.
Source: Slashnext

The creators used a GPT-J language model from 2021 as the basis for WormGPT and fed the artificial intelligence with data sets that were specifically targeted at malware and phishing. The data comes from a variety of sources. However, the authors want to keep the sources secret.

Slashnext has tested the A.I.. The result is "worrying". WormGPT is a language genius that uses the language patterns of actual suppliers for phishing emails. The grammar and wording are also impeccable. This makes it difficult to recognise fake emails. The chatbot is also proficient in the Python programming language. This enables it to generate perfidious malicious code in a short space of time. According to Slashnext, the results here are also "remarkably convincing and strategically cunning".

Phishing for beginners

The user interface of WormGPT is self-explanatory. According to Daniel Kelley, hardly any prior knowledge is required to use it to generate malicious software or phishing emails. He bases this statement on his own tests as well as on the screenshots provided by the suppliers. This makes it easier for laypersons to enter this terrain.

WormGPT is very easy to use.
WormGPT is very easy to use.
Source: Slashnext

There is no doubt about the motivation behind the development of WormGPT: The screenshots show how bluntly the chatbot is used to advertise simplified phishing.

Cover image: Shutterstock

15 people like this article


User Avatar
User Avatar

I've been tinkering with digital networks ever since I found out how to activate both telephone channels on the ISDN card for greater bandwidth. As for the analogue variety, I've been doing that since I learned to talk. Though Winterthur is my adoptive home city, my heart still bleeds red and blue. 

6 comments

Avatar
later