FraudGPT is a criminally marketed large language model service positioned as an uncensored AI assistant for cybercrime and online fraud. It has been promoted on underground forums, Telegram, Tor-hosted services, and dark-web markets as a tool for generating phishing content, scam messaging, malicious code, credential-harvesting pages, vulnerability-scanning workflows, and other offensive material. FraudGPT is commonly grouped with other so-called dark LLMs such as WormGPT, GhostGPT, and DarkGPT, and is frequently cited as an example of how generative AI lowers the skill barrier for social engineering and cyber-enabled fraud.
The service has been advertised with capabilities spanning phishing-page creation, scam-letter generation, malware or hacking-tool development, code obfuscation, credential-related automation, and support for broader fraud operations. Across reporting, its most consistently supported role is as an AI-enabled facilitator for phishing, fraud, and malicious code generation rather than as a distinct self-contained malware family deployed on victim systems. It has also been referenced as part of the broader trend of AI-assisted ransomware and intrusion operations, where such tools accelerate content generation, scripting, and attacker workflow automation.
FraudGPT has been associated with underground commercialization efforts aimed at subscription-based access for cybercriminals. However, multiple investigations and forum discussions indicate that at least some FraudGPT offerings were likely fraudulent themselves, with researchers and underground users alleging that the advertised product either did not function as claimed or was used to scam prospective buyers. As a result, FraudGPT is best understood as a malicious AI service brand and cybercrime-enablement platform whose claimed capabilities exceeded what could be independently verified.
Operationally, FraudGPT is relevant because it illustrates the convergence of generative AI with phishing, social engineering, fraud automation, and low-complexity malicious tooling. Its significance lies less in novel malware tradecraft than in commoditizing offensive assistance for less-skilled actors and improving the scale, fluency, and personalization of criminal campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Drafting phishing lures, profiling targets... Threat actors use it to systematically design lookalike phishing pages, scrape target data...
key capabilities have been segmented into phishing automation, malware development, reconnaissance, brute force, vulnerability exploitation, and social engineering.
Advertised features of malicious LLMs indicate that cybercriminals are connecting these systems to various external tools for... scanning sites for vulnerabilities... Scan websites for vulnerabilities across a massive CVE database... users were discussing connecting LLMs to external tools like Nmap, and using the LLM to summarize the Nmap output.
Some tools extend into finding leaked data, locating usable stolen payment card numbers, and building supporting infrastructure like phishing pages...
Deepfake voice and video tools have advanced to the point where live video verification, once the victim’s last defense, no longer disqualifies the scammer. The Arup engineering firm deepfake in early 2024, in which a finance employee was tricked into wiring $25 million by AI-rendered “executives” on a Zoom call, is no longer an outlier.
Because these tools are frequently used to weaponize leaked data, combining stolen credentials, breached personal information, or exposed corporate details into personalized lures...
FraudGPT is described as a great tool for creating undetectable malware, writing malicious code, finding leaks and vulnerabilities, creating phishing pages, and for learning hacking.
AI was mainly used for “polishing” phishing emails... attackers using it to generate phishing pages... Six key ways AI is used in intrusions today: Phishing at industrial scale
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a commodity malicious AI tool used to lower the barrier for social-engineering activity.
A malicious AI tool cited as accelerating ransomware operations.
A malicious AI-enabled tool referenced as part of the broader underground ecosystem supporting phishing and script generation.
An illicit large language model variant referenced as being used in scam operations to generate convincing social-engineering content at scale.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.