FraudGPT is a criminally marketed large language model service positioned as an uncensored AI assistant for cybercrime, fraud, phishing, and malicious code generation. It has been promoted on underground forums, Telegram channels, dark web markets, and in discussions alongside similar so-called dark LLMs such as WormGPT, GhostGPT, and DarkGPT. Advertised use cases have included generating phishing emails and pages, scam scripts, social-engineering content, malicious code, hacking tools, vulnerability-scanning assistance, and payment-card fraud workflows. FraudGPT is commonly cited as an example of how generative AI can lower the skill barrier for cybercrime by automating persuasive text generation, coding assistance, and fraud enablement.
High-confidence reporting indicates that FraudGPT was marketed by an actor using the handle CanadianKingpin12 and was sold as a subscription service aimed at cybercriminal buyers. However, multiple investigations and forum discussions concluded that the offering was likely fraudulent or nonfunctional, with claimed malware-generation and related capabilities not substantiated in practice. Prospective buyers and forum participants accused the operator of scamming customers, and at least one investigation found no evidence of a working product behind the branding. As a result, FraudGPT is best understood as a purported malicious AI service and cybercrime brand rather than a verified standalone malware family.
FraudGPT has nevertheless become a widely recognized label in discussions of AI-enabled cybercrime. It is frequently referenced in the context of phishing, social engineering, fraud automation, and the broader commercialization of offensive AI tooling. Its significance lies less in demonstrated technical novelty than in its role as a symbol of the emerging market for illicit AI assistants and the use of LLM branding to attract criminal customers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Drafting phishing lures, profiling targets... Threat actors use it to systematically design lookalike phishing pages, scrape target data...
key capabilities have been segmented into phishing automation, malware development, reconnaissance, brute force, vulnerability exploitation, and social engineering.
Advertised features of malicious LLMs indicate that cybercriminals are connecting these systems to various external tools for... scanning sites for vulnerabilities... Scan websites for vulnerabilities across a massive CVE database... users were discussing connecting LLMs to external tools like Nmap, and using the LLM to summarize the Nmap output.
Some tools extend into finding leaked data, locating usable stolen payment card numbers, and building supporting infrastructure like phishing pages...
Deepfake voice and video tools have advanced to the point where live video verification, once the victim’s last defense, no longer disqualifies the scammer. The Arup engineering firm deepfake in early 2024, in which a finance employee was tricked into wiring $25 million by AI-rendered “executives” on a Zoom call, is no longer an outlier.
Because these tools are frequently used to weaponize leaked data, combining stolen credentials, breached personal information, or exposed corporate details into personalized lures...
FraudGPT is described as a great tool for creating undetectable malware, writing malicious code, finding leaks and vulnerabilities, creating phishing pages, and for learning hacking.
Other threat actors use AI to draft convincing phishing emails and run voice-phishing calls that impersonate real staff, and commodity tools like WormGPT, DarkGPT, and FraudGPT exist specifically to strip away the skill requirement for that kind of social engineering.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a commodity malicious AI tool used to lower the barrier for social-engineering activity.
A malicious AI tool cited as accelerating ransomware operations.
An illicit large language model variant referenced as being used in scam operations to generate convincing social-engineering content at scale.
AI-powered cybercrime tool focused on automating phishing, fraud, and related criminal content generation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.