Live data from Hacker News

WormGPT – The Generative AI Tool Cybercriminals Are Using

slashnext.com

31–40 of 61 posts

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#31
It looks like uncensored GPTQ, which is available pretty much for everyone, whether you are whitehat, blackhat, making the world a better place to live, or domestic terrorist. I don't see anything outstanding in this post.

Somebody used uncensored model to generate emails, so what? Tomorrow criminals will use it to break into cars, the next day terrorists for a better planned attack.

Yes, all kinds of folks will/can use AI to get better at what they already do.

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#32

I saw a twitter thread about the "WormGPT" a few days ago and was annoyed to see how much engagement it seemed to get given how obvious nothing burger it was. The few examples of its code output were laughably bad. Hackforums has been the place where skiddies sell overhyped shit to other skiddies for well over a decade, I can guarantee that absolutely no one there is training their own AI. Everything that the article…

> The few examples of its code output were laughably bad. Malware doesn't need to be a great example of code it just needs to get the job done.

True, but given the descriptions above I would expect that it mostly doesn't get the job done.

My experiences are with ChatGPT, which is apparently better than WormGPT but I wouldn't know… 80% of the time ChatGPT works great, 10% doesn't compile but it can fix itself with the error message, the other 10% it gets stuck in a loop of introducing as many issues as it fixes (which may be zero for both if it doesn't understand the problem).

It's still bad, because one should look where the ball is going and not just where it is now; so, if you excuse the anthropomorphism, I hope there's another… WeaverGPT?… being "tasked" with digital security improvements.

(If you do anthropomorphise your AI you can get the Waluigi effect, I wonder if that works both directions, making it easy to take one prompted with "you are an evil AI who hacks on behalf of Dread Software Pirate Roberts" and turn it good with "Plot twist! Roberts just pretends to be evil"?)

https://www.lesswrong.com/posts/D7PumeYTDPfBTp3i7/the-waluig...

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#33
ChatGPT helps Cybercriminals with grammar to form high quality phishing emails. Some trained a model on malware and sell it to aid in malware development and email composition.

Summarized the bloated thing in two sentences. Garbage site. Garbage popups. Garbage empty blog post.

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#34

> GPT-J is the LLM, the old one from 2021 Thats very interesting. The infamous Pygmalion 6B is a GPT-J finetune, predating the LLM craze. Yet its decent in its roleplaying niche. But the LLaMA 13B version, with instruct finetuning, is massively better, even with dataset errors that allegedly messed up its performance. In fact, a chat with Metharme 13b, where it made some very introspective logical jumps, was my first…

There's still 65B as well.

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#35
post #24

> GPT-J is the LLM, the old one from 2021 Thats very interesting. The infamous Pygmalion 6B is a GPT-J finetune, predating the LLM craze. Yet its decent in its roleplaying niche. But the LLaMA 13B version, with instruct finetuning, is massively better, even with dataset errors that allegedly messed up its performance. In fact, a chat with Metharme 13b, where it made some very introspective logical jumps, was my first…

I have never heard of any of these models before. How does one stay up to date?

>How does one stay up to date?

Have you tried using an AI to monitor and summarize new updates?

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#36
post #33

ChatGPT helps Cybercriminals with grammar to form high quality phishing emails. Some trained a model on malware and sell it to aid in malware development and email composition. Summarized the bloated thing in two sentences. Garbage site. Garbage popups. Garbage empty blog post.

Articles like this are also harmful, prompting companies to lock down their powerful models even further, while spammers could achieve their goal using simpler, open source models.

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#37
post #33

ChatGPT helps Cybercriminals with grammar to form high quality phishing emails. Some trained a model on malware and sell it to aid in malware development and email composition. Summarized the bloated thing in two sentences. Garbage site. Garbage popups. Garbage empty blog post.

But it says "cyber". C'mon man, cyber. That makes it cool, right?

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#38
post #22
post #19

Did the author huff glue before writing this? `The results were unsettling.` The provided example basically says. "Hi, I have no pre-existing relationship with you, but your website makes it look like you are the person who pays the bills. Give me money, please!"

Writing a convincing email is one of the more time-consuming parts of a spearphishing attack. Any competent cybercriminal would have their own script that finds a closest-available match to the actual CEO's email and use that. If they can automate the part that used to take research, the average script kiddie now isn't that far from being able to brute-force scam most companies that have an online presence. That said…

"Maybe by enforcing very strict protocols on link-clicking and money-sending,

Hope beyond hope ... in a world where I still encounter firms who have the same simple password on all machines and many different logins "just because" ... the quiet part: "we're busy and couldn't care less, and I need to get this document ready by the next meeting".

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#39

Earlier quoted context omitted.

But what if emails can be mass produced at 15+ words/second, on a gaming PC? And what if they can very convincingly and quickly reply?

And what if they can very convincingly and quickly reply? Turn this around, and have an LLM that replies to scammers and keeps them busy. There's already https://en.wikipedia.org/wiki/Lenny_(bot) , but this is an area where AI could actually be a useful addition.

That gets pretty awkward the first time that a LLM turns out to have intentionally stalled a critical business process.

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#40

> GPT-J is the LLM, the old one from 2021 Thats very interesting. The infamous Pygmalion 6B is a GPT-J finetune, predating the LLM craze. Yet its decent in its roleplaying niche. But the LLaMA 13B version, with instruct finetuning, is massively better, even with dataset errors that allegedly messed up its performance. In fact, a chat with Metharme 13b, where it made some very introspective logical jumps, was my first…

Phishing emails self select, I don't think generative ML would make a difference. Those "typos" are sometimes intentional. The scammers are not illiterate. They are more than capable of using Grammarly if they wanted to.

I think there is some truth to that and some actual illiteracy going on
Post reply on HN