WormGPT is a maliciously oriented large language model service that emerged in 2023 and became one of the earliest widely publicized "dark LLM" brands marketed to cybercriminals. It has been described as based on GPT-J and promoted as an uncensored or jailbroken AI assistant intended to remove the safety restrictions present in mainstream consumer models. WormGPT was advertised for offensive use cases including business email compromise, phishing, social engineering, malicious code generation, vulnerability research, and broader cybercrime automation, and it helped popularize the commercialization of AI-as-a-service offerings in underground communities.
WormGPT is not malware in the traditional sense of a self-executing malicious program. Rather, it is an illicit AI tool used to assist operators in producing malicious content and accelerating attack workflows. Reported use cases center most consistently on generating persuasive phishing and BEC lures, improving language quality for fraud operations, assisting with malware or exploit development, and supporting reconnaissance or vulnerability analysis. Multiple later criminal AI offerings were marketed as successors, imitators, or alternatives to WormGPT, and the name has continued to resurface in underground and media reporting even after the original service was reportedly shut down.
The service was marketed on criminal forums and Telegram channels and was sold commercially to threat actors as a subscription-style offering. Reporting consistently notes that many similar GPT-branded criminal services were scams, wrappers around legitimate commercial models, or lightly modified open-source models with safeguards removed, and the real-world operational impact of WormGPT itself remains unclear. Nonetheless, WormGPT became a reference point for the broader trend of adversarial use of generative AI in cybercrime, especially for phishing, fraud, and malware-development assistance.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Funksec … uses AI-created phishing templates and and a called dubbed ‘WormGPT.’”
14 distinct techniques documented for this family, organized by ATT&CK tactic.
key capabilities have been segmented into phishing automation, malware development, reconnaissance, brute force, vulnerability exploitation, and social engineering.
Deepfake voice and video tools have advanced to the point where live video verification, once the victim’s last defense, no longer disqualifies the scammer. The Arup engineering firm deepfake in early 2024, in which a finance employee was tricked into wiring $25 million by AI-rendered “executives” on a Zoom call, is no longer an outlier.
Malicious AI models are custom or fine-tuned language models, stripped of safety filters, that criminals sell on dark web forums to write phishing emails, generate malware, and automate fraud.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyber-oriented LLM marketed on underground forums for offensive use without content filtering; described as useful for phishing content or simple malware stubs.
An illicit large language model variant referenced as being used in scam operations to improve social-engineering content and remove linguistic indicators that might expose operators.
Commercially available malicious LLM used to support phishing, fraud, malware development, and attack automation in the cybercrime ecosystem.
AI-based hacking tool distributed via underground and open platforms; described as enabling phishing automation, malware development, reconnaissance, brute force, vulnerability exploitation, and social engineering.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.