Cyber Security News

Hackers use WormGPT to Launch Sophisticated cyberattacks

Generative AI technology is rapidly growing and advancing, driven by continuous research and development efforts.

But, besides the growing advancements and positive things, these generative AI technologies are also actively exploited by threat actors for their illicit activities.

Recently, cybersecurity researchers from SlashNext reported that threat actors are actively using ChatGPT and a black-hat alternative to GPT models, WormGPT, to launch business email compromise (BEC) attacks.

WormGPT is Revolutionizing BEC Attacks

ChatGPT and other advanced AI tech enable threat actors to automate convincing personalized fake emails, expanding the scope of BEC attacks and boosting the attack’s success.

These advanced AI technologies are indirectly aiding the threat actors to craft sophisticated phishing emails, surpassing language barriers and enhancing their attack effectiveness.

WormGPT

In these types of events, threat actors exploit the interfaces of the ChatGPT or similar tools with specialized prompts to manipulate and compromise AI.

So, this is clearly highlighting the urgent implementation of robust AI security measures.

Moreover, to reach the next level, cybercriminals also develop user-friendly custom AI modules similar to ChatGPT for illicit use, amplifying the complexity of cybersecurity in an AI-driven world.

Custom ChatGPT Modules (Source – SlashNext)

WormGPT

WormGPT is mainly designed for malicious activities since it’s a malicious alternative to GPT models. Apart from this, WormGPT offers several powerful features, such as:-

  • Unlimited character support
  • Chat memory retention
  • Code formatting

WormGPT trained on undisclosed malware-related datasets, keeping its training sources confidential as per the author’s decision.

WormGPT Source (Source – SlashNext)

Researchers thoroughly evaluated the risks of WormGPT by testing its ability to generate a convincing threatful email targeting an unsuspecting account manager for payment of a fraudulent invoice.

The disturbing outcome revealed the exceptional persuasive and tactful email generation capabilities of WormGPT, demonstrating its dangerous capabilities to:-

  • Generate  advanced phishing emails
  • Launch BEC attacks

WormGPT is an unrestricted variant of ChatGPT since it lacks ethical boundaries or limitations, unlike ChatGPT. WormGPT highlights the significant risk of generative AI.

Here below, we have mentioned all the advantages of generative AI for BEC attacks:-

  • Exceptional Grammar
  • Lowered Entry Threshold

Recommendations

Here below, we have mentioned all the recommendations offered by the security analysts:-

  • BEC-Specific Training
  • Enhanced Email Verification Measures
  • Make sure to test your security efficacy in observability mode
  • Always use a robust security solution.
Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…

24 minutes ago

Critical Grafana Vulnerability Let Attackers Escalate Privilege

Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…

28 minutes ago

Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges

A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…

1 hour ago

Windows 11 to Hide BSOD Crash Errors on Public Displays

Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…

3 hours ago

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

5 hours ago

OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently

OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The…

5 hours ago