

(Maxim Apryatin/Shutterstock)
Companies are flocking to GenAI technologies to help automate business functions, such as reading and writing emails, generating Java and SQL code, and executing marketing campaigns. At the same time, cybercriminals are also finding tools like WormGPT and FraudGPT useful for automating nefarious deeds, such as writing malware, distributing ransomware, and automating the exploitation of computer vulnerabilities around the Internet. With the pending release of API acceess to a language model dubbed DarkBERT into the criminal underground, the GenAI capabilities available to cybercriminals could increase significantly.
On July 13, researchers with SlashNext reported the emergence of WormGPT, an AI-powered tool that’s being actively utilized by cybercriminals. About two weeks later, it let the world know about another digital creation from the criminal underground, dubbed FraudGPT. FraudGPT is being promoted by its creator, who goes by the name “CanadianKingpin12,” as an “exclusive bot” designed for fraudsters, hackers, spammers, SlashNext says in a blog post this week.
FraudGPT is replete with a number of advanced GenAI capabilities, according to an ad posted on a cybercrime forum discovered by SlashNext, including:
- Write malicious code;
- Create undetectable malware;
- Create phishing pages;
- Create hacking tools;
Image from a video produced by cybercriminals and shared by SlashNext
- Write scam pages / letters;
- Find leaks and vulnerabilities;
- Find “cardable” sites;
- “And much more | sky is the limit.”
When SlashNext contacted the malware’s author, the author insisted that FraudGPT was superior to WormGPT, which was the main goal that SlashNext had in the conversation. Then the malware author went to to say that he or she had two more malicious GenAI products in development, including DarkBART and DarkBERT, and that they would be ingrated with Google Lens, which gives the tools the capability to send text accompanied by images.
This perked up the ears of the security researchers at SlashNext, a Pleasanton, California company that provides protection against phishing and human hacking. DarkBERT is a large language model (LLM) created by a South Korean security research firm and trained on a large corpus of data culled from the Dark Web to fight cybercrime. It has not been publicly released, but CanadianKingpin12 claimed to have access to it (although it was not clear whether they actually did).
DarkBERT could potentially provide cybercriminals with a leg up in their malicious schemes. In his blog post, SlashNext’s Daniel Kelley, who identifies as “a reformed black hat computer hacker,” shares some of the potential ways that CanadianKingpin12 envisions the tool being used. They include:
- “Assisting in executing advanced social engineering attacks to manipulate individuals;”
- “Exploiting vulnerabilities in computer systems, including critical infrastructure;”
- “Enabling the creation and distribution of malware, including ransomware;”
- “The development of sophisticated phishing campaigns for stealing personal information;” and
- “Providing information on zero-day vulnerabilities to end-users.”
“While it’s difficult to accurately gauge the true impact of these capabilities, it’s reasonable to expect that they will lower the barriers for aspiring cybercriminals,” Kelley writes. “Moreover, the rapid progression from WormGPT to FraudGPT and now ‘DarkBERT’ in under a month, underscores the significant influence of malicious AI on the cybersecurity and cybercrime landscape.”
What’s more, just as OpenAI has enabled thousands of companies to leverage powerful GenAI capabilites through the power of APIs, so too will the cybercriminal underground leverage APIs.
“This advancement will greatly simplify the process of integrating these tools into cybercriminals’ workflows and code,” Kelley writes. “Such progress raises significant concerns about potential consequences, as the use cases for this type of technology will likely become increasingly intricate.”
The GenAI criminal activity recently caugh the eye of Cybersixgill, an Israeli security firm. According to Delilah Schwartz, who works in threat intel at Cybersixgill, all three products are being advertised for sale.
“Cybersixgill observed threat actors advertising FraudGPT and DarkBARD on cybercrime forums and Telegram, in addition to chatter about the tools,” Schwartz says. “Malicious versions of deep language learning models are currently a hot commodity on the underground, producing malicious code, creating phishing content, and facilitating other illegal activities. While threat actors abuse legitimate artificial intelligence (AI) platforms with workarounds that evade safety restrictions, malicious AI tools go a step further and are specifically designed to facilitate criminal activities.”
The company has noted ads promoting FraudGPT, FraudBot, and DarkBARD as “Swiss Army Knife hacking tools.”
“One ad explicitly stated the tools are designed for ‘fraudsters, hackers, spammers, [and] like-minded individuals,'” Schwartz says. “If the tools perform as advertised, they would certainly enhance a variety of attack chains. With that being said, there appears to be a dearth of actual reviews from users championing the products’ capabilities, despite the abundance of advertisements.”
Related Items:
Feds Boost Cyber Spending as Security Threats to Data Proliferate
Security Concerns Causing Pullback in Open Source Data Science, Anaconda Warns
Filling Cybersecurity Blind Spots with Unsupervised Learning
April 2, 2025
- Lovelytics and Nousot Announce Merger to Form New Databricks Consulting Firm
- The Linux Foundation Announces General Availability of Valkey 8.1
- John Snow Labs Launches Generative AI Lab 7.0 to Streamline LLM Evaluation for Domain Experts
- Informatica Introduces New AI-Powered Cloud Integration and MDM Capabilities
- MLCommons Releases New MLPerf Inference v5.0 Benchmark Results
- IDC: AI Investments to Represent 3.7% of Global GDP by 2030
April 1, 2025
- Carahsoft and ZL Technologies Partner to Bring Unstructured Data Management Solutions to Public Sector
- OneStream Named a Leader in 2025 Gartner Magic Quadrant for Financial Close and Consolidation
- Kinaxis Partners with Databricks to Accelerate AI-Powered Supply Chain Orchestration
- Dataiku Achieves AWS Generative AI Competency
- ControlTheory Secures $5M Seed Funding to Bring Controllability to Observability
- Crunchy Data Unveils Kubernetes-Native Data Warehouse with Iceberg and DuckDB
- OpenText Launches Titanium X with CE 25.2 for AI-Powered Digital Workforce
- Sourcetable Raises $4.3M to Launch AI-Powered ‘Self-Driving’ Spreadsheet
- Intel and IBM Announce Availability of Intel Gaudi 3 AI Accelerators on IBM Cloud
- Hitachi Vantara Validated for US Government Software Security Framework Compliance
March 31, 2025
- Striim Expands SQL Server Replication Capabilities with SQL2Fabric-X GA Release
- Precisely Acquires DTS Software to Expand Mainframe Storage Optimization Portfolio
- Fivetran Expands Microsoft Fabric Integration with 700+ Connectors, Enabling AI-Ready Data Lakes
- CData Launches Microsoft Fabric Integration Accelerator
- PayPal Feeds the DL Beast with Huge Vault of Fraud Data
- OpenTelemetry Is Too Complicated, VictoriaMetrics Says
- Accelerating Agentic AI Productivity with Enterprise Frameworks
- When Will Large Vision Models Have Their ChatGPT Moment?
- Will Model Context Protocol (MCP) Become the Standard for Agentic AI?
- Your Next Big Job in Tech: AI Engineer
- Data Warehousing for the (AI) Win
- Nvidia Touts Next Generation GPU Superchip and New Photonic Switches
- Can You Afford to Run Agentic AI in the Cloud?
- What Benchmarks Say About Agentic AI’s Coding Potential
- More Features…
- Clickhouse Acquires HyperDX To Advance Open-Source Observability
- NVIDIA GTC 2025: What to Expect From the Ultimate AI Event?
- Grafana’s Annual Report Uncovers Key Insights into the Future of Observability
- Google Launches Data Science Agent for Colab
- FlashBlade//EXA Moves Data at 10+ TB/sec, Pure Storage Says
- Reporter’s Notebook: AI Hype and Glory at Nvidia GTC 2025
- Weaviate Introduces New Agents to Simplify Complex Data Workflows
- Mathematica Helps Crack Zodiac Killer’s Code
- HPE Preps for the AI Era with Updated Data Fabric, Storage, and Compute Offerings
- Immuta Brings AI to Data Governance, Launches Copilot
- More News In Brief…
- Gartner Predicts 40% of Generative AI Solutions Will Be Multimodal By 2027
- Snowflake Ventures Invests in Anomalo for Advanced Data Quality Monitoring in the AI Data Cloud
- Seagate Unveils IronWolf Pro 24TB Hard Drive for SMBs and Enterprises
- NVIDIA Unveils AI Data Platform for Accelerated AI Query Workloads in Enterprise Storage
- Accenture Invests in OPAQUE to Advance Confidential AI and Data Solutions
- MinIO: Introducing Model Context Protocol Server for MinIO AIStor
- Alation Introduces Agentic Platform to Automate Data Management and Governance
- Gartner Identifies Top Trends in Data and Analytics for 2025
- Qlik Survey Finds AI at Risk as Poor Data Quality Undermines Investments
- Palantir and Databricks Announce Strategic Product Partnership to Deliver Secure and Efficient AI to Customers
- More This Just In…