INC-23-0006 confirmed high WormGPT: AI-Powered Business Email Compromise Tool (2023)
Unknown cybercriminal developers developed and Cybercriminals on dark web forums deployed large language models, harming Business email users and Corporate targets of phishing campaigns ; contributing factors included weaponization and intentional fraud.
Incident Details
| Date Occurred | 2023-07 | Severity | high |
| Evidence Level | corroborated | Impact Level | Sector |
| Domain | Security & Cyber | ||
| Primary Pattern | PAT-SEC-002 AI-Morphed Malware | ||
| Secondary Patterns | PAT-SEC-009 AI-Powered Social Engineering |, PAT-INF-003 Disinformation Campaigns | ||
| Regions | north america, europe | ||
| Sectors | Corporate, Finance | ||
| Affected Groups | Business Organizations, General Public | ||
| Exposure Pathways | Adversarial Targeting | ||
| Causal Factors | Weaponization, Intentional Fraud | ||
| Assets & Technologies | Large Language Models | ||
| Entities | Unknown cybercriminal developers(developer), ·Cybercriminals on dark web forums(deployer) | ||
| Harm Types | financial, operational | ||
WormGPT, an AI tool specifically designed for malicious purposes without ethical guardrails, was marketed on cybercrime forums to generate sophisticated phishing emails and business email compromise attacks.
Incident Summary
In mid-2023, a tool called WormGPT appeared on cybercrime forums as a purpose-built AI system for generating malicious content, including phishing emails, business email compromise (BEC) messages, and social engineering scripts. Unlike mainstream AI systems that incorporate safety guardrails to prevent misuse, WormGPT was specifically designed without ethical restrictions and was trained on malware-related data to optimize its utility for cybercriminal activities.
Cybersecurity researchers at SlashNext conducted a detailed analysis of the tool and published their findings in July 2023.[1] They demonstrated that WormGPT could generate highly persuasive, grammatically polished phishing emails in multiple languages, including messages designed to impersonate executives and instruct employees to make fraudulent wire transfers. The tool significantly lowered the technical barrier for conducting BEC attacks, a category of cybercrime that the FBI estimates causes billions of dollars in losses annually.
Following the public exposure, the original developer shut down the WormGPT project in August 2023. However, the tool’s appearance catalyzed a broader trend of malicious AI tools, with variants such as FraudGPT and DarkBART subsequently appearing on dark web marketplaces. The FBI issued an advisory in September 2023 warning organizations about the growing use of AI to enhance social engineering and BEC attacks.[2]
Key Facts
- Method: Jailbroken large language model specifically trained for generating malicious content
- Capabilities: Grammatically correct phishing emails, BEC attack scripts, social engineering content in multiple languages
- Distribution: Sold on cybercrime forums as a subscription service
- Shutdown: Original project ceased following public exposure; copycat tools emerged
- Threat context: BEC attacks cause estimated $2.7 billion in losses annually (FBI IC3, 2022)
- Law enforcement response: FBI advisory issued warning of AI-enhanced BEC threats
Threat Patterns Involved
Primary: AI-Morphed Malware — WormGPT represents a new category of malicious AI tools specifically designed to generate and enhance cyberattack content, lowering the skill threshold for conducting sophisticated attacks.
Secondary: Disinformation Campaigns — The tool’s ability to generate persuasive, contextually appropriate false messages at scale connects it to broader patterns of AI-enabled deception, particularly in the context of targeted social engineering.
Significance
- Democratization of cybercrime capabilities. WormGPT demonstrated that AI tools can lower the barrier to entry for cybercrime by enabling attackers without strong language skills or social engineering expertise to generate convincing attack content.
- Failure of safety guardrails as a containment strategy. The existence of WormGPT and its variants illustrated that safety restrictions on mainstream AI systems do not prevent the development of unrestricted alternatives specifically designed for malicious purposes.
- Scalability of AI-enhanced attacks. The tool’s ability to generate personalized phishing content in multiple languages at scale represents a qualitative shift in the threat landscape for business email compromise.
- Proliferation through the cybercrime ecosystem. The rapid emergence of copycat tools following WormGPT’s exposure demonstrated how malicious AI capabilities can proliferate quickly through underground markets, making individual takedowns insufficient as a defensive strategy.
Timeline
WormGPT, a jailbroken large language model, appears for sale on cybercrime forums
SlashNext cybersecurity researchers publish analysis of WormGPT's capabilities for generating phishing emails and BEC attacks
WormGPT developer markets the tool as capable of generating grammatically correct, contextually persuasive phishing emails in multiple languages
Original WormGPT project is shut down by its developer following public exposure
FBI issues advisory warning of AI-enhanced business email compromise threats
Multiple copycat tools (FraudGPT, DarkBART) emerge on dark web marketplaces
Outcomes
- Financial Loss:
- Not quantified; BEC attacks globally cause billions annually
- Arrests:
- None publicly reported for WormGPT specifically
- Recovery:
- Not applicable
- Regulatory Action:
- FBI advisory issued; original tool development ceased after public exposure; variants emerged
Glossary Terms
Use in Retrieval
INC-23-0006 documents wormgpt: ai-powered business email compromise tool, a high-severity incident classified under the Security & Cyber domain and the AI-Morphed Malware threat pattern (PAT-SEC-002). It occurred in north america, europe (2023-07). This page is maintained by TopAIThreats.com as part of an evidence-based registry of AI-enabled threats. Cite as: TopAIThreats.com, "WormGPT: AI-Powered Business Email Compromise Tool," INC-23-0006, last updated 2025-01-15.
Sources
- SlashNext: WormGPT — The Generative AI Tool Cybercriminals Are Using to Launch Business Email Compromise Attacks (news, 2023-07)
https://slashnext.com/blog/wormgpt-the-generative-ai-tool-cybercriminals-are-using-to-launch-business-email-compromise-attacks/ (opens in new tab) - FBI Advisory on AI-Enhanced Business Email Compromise (primary, 2023-09)
(opens in new tab)
Update Log
- — First logged (Status: Confirmed, Evidence: Corroborated)