WormGPT is a commercially marketed large language model chatbot associated with cybercrime, rather than a worm or an endpoint malware family. It emerged in June 2023 as a private service based on GPT-J and was promoted on underground forums for generating phishing messages, supporting business email compromise, and assisting with malicious code development. Its appeal centered on reduced content restrictions and the ability to produce fluent social-engineering text with less manual effort.
The original project shut down in 2023 following extensive publicity. Subsequent services reused the WormGPT name, including offerings branded Keanu and xzin0vich. These offerings do not represent a single consistent model or codebase; some repackage publicly available models or commercial APIs with jailbreak prompts and subscription-based interfaces.
Black Basta members explored WormGPT alongside other AI tools for phishing, scripting, automation, and deception. This interest does not establish successful operational deployment. WormGPT's real-world attack impact remains unquantified, and claims of sophisticated malware generation or autonomous intrusion capabilities are not established. No specific target operating system or industry is intrinsic to the service.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Funksec … uses AI-created phishing templates and and a called dubbed ‘WormGPT.’”
18 distinct techniques documented for this family, organized by ATT&CK tactic.
First, the AI could conduct reconnaissance, scraping publicly available data about target companies from search engines, social media, and other open sources...
...scanning for vulnerable servers or open network ports and attempting to breach the entry points.
Deepfake voice and video tools have advanced to the point where live video verification, once the victim’s last defense, no longer disqualifies the scammer. The Arup engineering firm deepfake in early 2024, in which a finance employee was tricked into wiring $25 million by AI-rendered “executives” on a Zoom call, is no longer an outlier.
The chatbot was trained in materials related to malware development, which is how WormGPT was born.
Malware (T1587.001) — разработка AI-малвари и вредоносных скриптов с помощью LLM
Artificial Intelligence (T1588.007) — приобретение доступа к AI-capabilities для подготовки атаки
The service follows WormGPT and FraudGPT, underground tools marketed for phishing emails, business email compromise lures, malicious scripts and malware code.
ten package names on npm impersonating real DeFi protocol and standards libraries ... The largest single cluster this week impersonated Alelo, a Brazilian corporate benefits and payment card provider ... a separate scoped-namespace campaign published twenty-one lookalike n8n-nodes-utils-helper-* packages
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An uncensored language-model-based offensive tool described as having guardrails removed so attackers could use it to identify vulnerabilities and support malicious activity.
Named as a commodity malicious AI tool used to lower the barrier for social-engineering activity.
A malicious AI tool cited as accelerating ransomware operations.
Cyber-oriented LLM marketed on underground forums for offensive use without content filtering; described as useful for phishing content or simple malware stubs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.