WormGPT is a malicious large language model brand used to support offensive cyber activity. It has been advertised in underground and Telegram-based communities and has evolved into newer variants, including versions described as being built on open-source model foundations such as Mixtral and Grok. WormGPT is associated with lowering the barrier to entry for cybercrime by enabling users to generate malicious content and attack code with minimal technical expertise. High-confidence reporting links WormGPT directly to distributed denial-of-service activity, including generation of malicious code intended to disrupt websites and infrastructure by overwhelming them with traffic. In the broader criminal ecosystem, WormGPT is part of a class of weaponized AI tools used to accelerate attack development, improve operational efficiency, and help adversaries adapt offensive workflows more quickly than traditional manual methods. Its role is best understood as an enabling offensive platform rather than a conventional intrusion set or state-backed espionage group. Known aliases are limited to WormGPT. Available information supports characterization of WormGPT as a cybercriminal tool or service associated with offensive enablement and DDoS-related abuse, but does not provide high-confidence attribution to a specific nation state, operator identity, or stable organizational structure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.