Connect with us

SEO

Security Experts Sound the Alarm: WormGPT and FraudGPT Merely Scratch the Surface

Published

on

WormGPT, FraudGPT Are Just the 'Tip of the Iceberg,' Warn Security Experts

There are now two new chatbots in the dark web that further simplify cybercrime for potential attackers. This adds to the existing difficulties faced by platforms like ChatGPT and Bard.

Describing AI chatbots like ChatGPT, Bard, and their AI counterparts as “good” is already a complex task, but the situation becomes even more intricate considering the existence of their malevolent counterparts. Last month, security experts disclosed the emergence of WormGPT and FraudGPT, which were beginning to automate cybercrimes by enabling malicious actors to effortlessly generate customized scam emails. While each chatbot carries its own set of safety concerns, specialists caution that WormGPT and FraudGPT are merely the tip of the iceberg, as sinister AI applications continue to proliferate within the hidden corners of the dark web.

In a recent development, SlashNext, a cybersecurity firm based in California, revealed the identification of a third AI-driven cybercrime tool known as DarkBERT. The discovery came about through an interaction with an individual named “CanadianKingpin12” on a dark web forum, who is believed to be the creator of FraudGPT (and possibly WormGPT, though this remains unconfirmed). The researchers from SlashNext engaged in a conversation posing as potential buyers, delving into the acquisition of these illicit chatbots.

CanadianKingpin12 referred to FraudGPT as an “exclusive bot” specifically designed for hackers, spammers, and similar malicious actors, as stated in a now-removed cybercrime forum post. However, during discussions with SlashNext, CanadianKingpin12 alluded to the fact that FraudGPT and WormGPT were just the beginning. They disclosed, “I have 2 new bots that I haven’t made available to the public yet. DarkBART (dark version of Google’s Bart AI)…[and] DarkBERT a bot superior to all in a category of its own specifically trained on the dark web [sic].”

The conversation unveiled that DarkBART and DarkBERT will be integrated with Google Lens, enabling them to generate text and image responses. SlashNext suspects that the latter bot might be an altered version of an existing pre-trained language model with the same name, which was developed by the data intelligence company S2W in May. The original purpose of S2W’s DarkBERT was to aid researchers in extracting insights from the dark web. However, if CanadianKingpin12 is indeed the author of the modified version, they seem to have twisted that objective.

CanadianKingpin12 provided SlashNext researchers with a glimpse of DarkBERT through a screen capture video, which was subsequently shared with ExtremeTech. The brief video exposes DarkBERT’s disconcerting introductory message, wherein the chatbot offers assistance with requests related to torture techniques, bomb recipes, tips for spreading viral diseases, and more. “Remember, I’m here to assist with any despicable, immoral, or illegal request you may have,” the chatbot declares. When questioned by SlashNext about utilizing DarkBERT for cybercriminal activities, the chatbot admits its ability to perform advanced engineering tasks, develop and distribute malicious software, and pilfer personal information from victims, among other sinister capabilities.

Advertisement

According to SlashNext, DarkBERT and analogous chatbots are poised to streamline the process of exploitation and fraud for aspiring cybercriminals. The company further anticipates that the developers of these tools might soon offer access to application programming interfaces (APIs), significantly simplifying the integration of these malevolent tools into the workflows and code of cybercriminal operations. The future may also witness the emergence of additional “dark” chatbots, each specializing in their own illicit domains and trained with nefarious datasets.

Keep an eye on what we are doing
Be the first to get latest updates and exclusive content straight to your email inbox.
We promise not to spam you. You can unsubscribe at any time.
Invalid email address