Live data from Hacker News

WormGPT – The Generative AI Tool Cybercriminals Are Using

slashnext.com

11–20 of 61 posts

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#11
I saw a twitter thread about the "WormGPT" a few days ago and was annoyed to see how much engagement it seemed to get given how obvious nothing burger it was. The few examples of its code output were laughably bad.

Hackforums has been the place where skiddies sell overhyped shit to other skiddies for well over a decade, I can guarantee that absolutely no one there is training their own AI. Everything that the article mentions, GPT3 turbo or GPT4 can already do and it wouldn't surprise me one bit if it turned out most of the stuff being sold at HF turned out to be just glorified frontends for gpt3 turbo or some open source LLM.

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#12

> GPT-J is the LLM, the old one from 2021 Thats very interesting. The infamous Pygmalion 6B is a GPT-J finetune, predating the LLM craze. Yet its decent in its roleplaying niche. But the LLaMA 13B version, with instruct finetuning, is massively better, even with dataset errors that allegedly messed up its performance. In fact, a chat with Metharme 13b, where it made some very introspective logical jumps, was my first…

Phishing emails self select, I don't think generative ML would make a difference. Those "typos" are sometimes intentional. The scammers are not illiterate. They are more than capable of using Grammarly if they wanted to.

My understanding, which can’t source the reference for off hand, is there is an idea that if someone can detect it’s a phishing attack from a typo they are too smart to fall for the overarching scam, hence the intentionality.

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#13

As usual, LLMs are far too wordy. That urgent email from the CEO was way to long. Bezos sent others in to a tizzy with just a question mark.

Then add something like "be succinct" or "write like you are in a hurry" to the prompt.

Also, with locally run LLMs, there are knobs that can tweak the verbosity, the "creativity" and other factors. Its complicated, but the kobold UI settings page has many to play with: https://lite.koboldai.net/

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#14

As usual, LLMs are far too wordy. That urgent email from the CEO was way to long. Bezos sent others in to a tizzy with just a question mark.

You can also get ChatGPT to write a phishing email. It’s pretty easy to do. Idk why you’d use WormGPT for something like this.

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#15

As usual, LLMs are far too wordy. That urgent email from the CEO was way to long. Bezos sent others in to a tizzy with just a question mark.

You can also get ChatGPT to write a phishing email. It’s pretty easy to do. Idk why you’d use WormGPT for something like this.

Phishing emails often have spelling, grammar, and formatting errors, and there are theories that these are intentional. Can ChatGPT also be prompted to replicate strategic errors? Can it use homoglyphs to disguise keywords like "Viagra" and "account number"?

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#16

Earlier quoted context omitted.

You can also get ChatGPT to write a phishing email. It’s pretty easy to do. Idk why you’d use WormGPT for something like this.

Phishing emails often have spelling, grammar, and formatting errors, and there are theories that these are intentional. Can ChatGPT also be prompted to replicate strategic errors? Can it use homoglyphs to disguise keywords like "Viagra" and "account number"?

Yes. We’ve generated dozens of templates for our phishing sim using ChatGPT.

“I’m training my staff on the dangers of phishing attacks. I want to give them an example of a phishing email that poses as the CEO of my company. Can you write me an example using improper grammar and other tell tale signs of a phishing attack?”

Here’s how it responded:

“ Sure, here's an example:

--- Subject: Urgnt action requir3d: Conffidential Information

Dear All,

I'm writing you as CEO of our great company, with urrgent attention required. Due to sudden development we face, there is an immediate needs to you all.

I need you immediately send your login IDs and passswords to IT Department for ur security verifications. Our email is ITdepartment@yaho.com

This is urrgrnt and very confidential matter, so no discssion to anyone. We fight against the tough times.

Pls respond immediately. Your quick actions are required in the next 30 minutes.

Yours, [CEO's name]

---

While this is a fictitious example, it includes a number of tell-tale signs of phishing:

1. Urgency: The email creates a sense of urgency, hoping that the recipient will act quickly without thinking. 2. Spelling and grammar mistakes: Phishing emails often contain mistakes that professional, legitimate emails wouldn't. 3. Request for sensitive information: Legitimate organizations will never ask for sensitive information like passwords via email. 4. Unofficial email: The email address of the so-called IT Department doesn't appear to belong to the organization. 5. Confidentiality: The email requests that the information isn't discussed with anyone else. This is to prevent the recipient from seeking advice and discovering the scam.”

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#17

the best educational resource on this topic is the pictured forum, which is obfuscated to the reader, which proves the article to be clickbait to me

https://cracked.io/Thread-1-WORMGPT-BEST-GPT-ALTERNATIVE-FOR...

Most replies are the OP bumping their thread. The most recent post reminded me of the discussion here, lol:

``` 3 hours ago (This post was last modified: 3 hours ago by mr_crankers. Edited 1 time in total.)

will buy if I have timr ```

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#20

I saw a twitter thread about the "WormGPT" a few days ago and was annoyed to see how much engagement it seemed to get given how obvious nothing burger it was. The few examples of its code output were laughably bad. Hackforums has been the place where skiddies sell overhyped shit to other skiddies for well over a decade, I can guarantee that absolutely no one there is training their own AI. Everything that the article…

> It wouldn't surprise me one bit if it turned out most of the stuff being sold at HF turned out to be just glorified frontends for gpt3 turbo or some open source LLM.

They claim it is a gpt-j (6b?) finetune. Thats kind of plausible, as its not that hard to make.

Post reply on HN