WormGPT 4 and KawaiiGPT operators are cybercriminal users and promoters of malicious generative AI tools designed to support phishing and ransomware-related activity. These tools are associated with lowering the barrier to entry for offensive operations by automating the creation of convincing phishing lures and facilitating generation of ransomware code. WormGPT 4 has been marketed as a paid criminal service, while KawaiiGPT has been distributed freely, increasing accessibility for less technically capable threat actors. The activity associated with these operators is financially motivated and aligned with cybercrime enablement rather than a distinct nation-state intrusion set. Their observed capabilities center on initial access and follow-on criminal operations through AI-assisted social engineering and malware development workflows. The operators are best understood as part of a broader ecosystem of cybercriminal tooling providers and users that accelerate phishing, credential theft, and extortion-enabling attacks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.