WormGPT is a malicious large language model service that emerged in June 2023 and became one of the first widely publicized "dark LLM" offerings marketed to cybercriminals. It was promoted as an uncensored alternative to mainstream chatbots, reportedly based on GPT-J, with safety guardrails removed or weakened to facilitate abusive use. WormGPT was advertised and discussed on underground forums and Telegram channels as a subscription-style service intended to help users generate phishing content, business email compromise lures, malicious code, and other offensive material.
WormGPT is not malware in the traditional sense of a self-executing payload or implant. Rather, it is an AI-enabled offensive tool that lowers the skill barrier for cybercrime by automating or accelerating tasks normally requiring more expertise. High-confidence reporting consistently associates it with phishing and social-engineering support, especially convincing email generation, and with assistance for malware development, scripting, and vulnerability-related research. It has also been cited as part of the broader commercialization of AI-as-a-service for criminal use, alongside similar offerings such as FraudGPT, GhostGPT, and DarkGPT.
Available reporting indicates that many WormGPT-style services were likely wrappers around existing models or commercial APIs rather than uniquely advanced autonomous hacking platforms. Researchers and forum users have described uneven quality, instability, and scam-like behavior in parts of this market, and the real-world operational impact of WormGPT specifically remains unclear. The original WormGPT service was reported shut down in 2023 after intense public attention, though later imitators and rebranded variants continued to appear.
WormGPT has been referenced in connection with ransomware and fraud ecosystems as an enabling tool for faster phishing, deception, and attack preparation, but not as a ransomware family or standalone intrusion implant. Its significance lies in demonstrating how generative AI can be packaged for criminal use to support initial access and downstream offensive operations, particularly against organizations targeted through email-based social engineering.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Funksec … uses AI-created phishing templates and and a called dubbed ‘WormGPT.’”
18 distinct techniques documented for this family, organized by ATT&CK tactic.
First, the AI could conduct reconnaissance, scraping publicly available data about target companies from search engines, social media, and other open sources...
...scanning for vulnerable servers or open network ports and attempting to breach the entry points.
Deepfake voice and video tools have advanced to the point where live video verification, once the victim’s last defense, no longer disqualifies the scammer. The Arup engineering firm deepfake in early 2024, in which a finance employee was tricked into wiring $25 million by AI-rendered “executives” on a Zoom call, is no longer an outlier.
WormGPT — the Dark Web imitation of ChatGPT that quickly generates convincing phishing emails...
ten package names on npm impersonating real DeFi protocol and standards libraries ... The largest single cluster this week impersonated Alelo, a Brazilian corporate benefits and payment card provider ... a separate scoped-namespace campaign published twenty-one lookalike n8n-nodes-utils-helper-* packages
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An uncensored language-model-based offensive tool described as having guardrails removed so attackers could use it to identify vulnerabilities and support malicious activity.
Named as a commodity malicious AI tool used to lower the barrier for social-engineering activity.
A malicious AI tool cited as accelerating ransomware operations.
Cyber-oriented LLM marketed on underground forums for offensive use without content filtering; described as useful for phishing content or simple malware stubs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.