Live data from Hacker News

WormGPT – The Generative AI Tool Cybercriminals Are Using

slashnext.com

51–60 of 61 posts

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#52
post #33

ChatGPT helps Cybercriminals with grammar to form high quality phishing emails. Some trained a model on malware and sell it to aid in malware development and email composition. Summarized the bloated thing in two sentences. Garbage site. Garbage popups. Garbage empty blog post.

But for years everyone has been saying that phishing emails have bad grammar on purpose. Was that a lie?

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#53
post #36
post #33

ChatGPT helps Cybercriminals with grammar to form high quality phishing emails. Some trained a model on malware and sell it to aid in malware development and email composition. Summarized the bloated thing in two sentences. Garbage site. Garbage popups. Garbage empty blog post.

Articles like this are also harmful, prompting companies to lock down their powerful models even further, while spammers could achieve their goal using simpler, open source models.

Information is never harmful.

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#54

There is a wider problem here - that Companies have almost no internal firewalls. Yes it's great that the CEO of company X can email a low level employee but then how do we know that is the CEO? Secure messaging, even the maligned GPG (see tptacek) would simply stop this attack (#). And stop most "cyber criminal" which appears to be mostly identify theft which ia another name for impersonation for fraudulent gain. We…

> no internal firewalls

do you mean this in the metaphorical sense? an internal firewall has little effect on compromised email accounts.

> But we probably cannot make email (more) secure? Can we create standard business messages that can be sent and revived by anyone and signed ?

DMARC is fairly well adopted, of course it does nothing against using a typosquatted domain.

> (#) a non technical friend lost thousands of pounds because their small compmay used non 2FA Gmail, was compromised and then "he" sent half a dozen emails to clients asking them to pay genuine invoices for work done to their "new" business account. Some kind of public key verification would stop that. But what kind?

The clue is in your own text. This wouldn't have happened if they used 2FA.

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#55
post #36

Earlier quoted context omitted.

Articles like this are also harmful, prompting companies to lock down their powerful models even further, while spammers could achieve their goal using simpler, open source models.

Information is never harmful.

https://en.wikipedia.org/wiki/Chicago_Tylenol_murders#Copyca...

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#56
post #33

ChatGPT helps Cybercriminals with grammar to form high quality phishing emails. Some trained a model on malware and sell it to aid in malware development and email composition. Summarized the bloated thing in two sentences. Garbage site. Garbage popups. Garbage empty blog post.

But for years everyone has been saying that phishing emails have bad grammar on purpose. Was that a lie?

There are different flavors of phishing, the bad grammar ones are more effective in the "spray and pray" techniques to get easy targets, whereas grammar and style matching is more useful in targeted spear phishing campaigns.

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#58

Earlier quoted context omitted.

But for years everyone has been saying that phishing emails have bad grammar on purpose. Was that a lie?

There are different flavors of phishing, the bad grammar ones are more effective in the "spray and pray" techniques to get easy targets, whereas grammar and style matching is more useful in targeted spear phishing campaigns.

I think this is an oversimplification. I've seen well made dragnet style messages as well. I'm of the opinion that the chain of arguments that says I'm not important, I will not be a target of spearfishing, I only need to care about dragnet style messages and everyone knows they are easy to spot because they are always so amateurish is very, very dangerous.

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#59
post #54

There is a wider problem here - that Companies have almost no internal firewalls. Yes it's great that the CEO of company X can email a low level employee but then how do we know that is the CEO? Secure messaging, even the maligned GPG (see tptacek) would simply stop this attack (#). And stop most "cyber criminal" which appears to be mostly identify theft which ia another name for impersonation for fraudulent gain. We…

> no internal firewalls do you mean this in the metaphorical sense? an internal firewall has little effect on compromised email accounts. > But we probably cannot make email (more) secure? Can we create standard business messages that can be sent and revived by anyone and signed ? DMARC is fairly well adopted, of course it does nothing against using a typosquatted domain. > (#) a non technical friend lost thousands o…

"firewalls" between people / departments. There are billions sent daily on little more the "approved" in a reply all email.

It's not the 2FA. a typo-squat would probably have worked, or just chnaging the email header. This is "just" social engineering / fraud as it has been for hundreds of years.

We have the tools to prevent it. if not the processes and training - but do we have the incentive now?

Re: WormGPT – The Generative AI Tool Cybercriminals Are Using

#60
post #54

There is a wider problem here - that Companies have almost no internal firewalls. Yes it's great that the CEO of company X can email a low level employee but then how do we know that is the CEO? Secure messaging, even the maligned GPG (see tptacek) would simply stop this attack (#). And stop most "cyber criminal" which appears to be mostly identify theft which ia another name for impersonation for fraudulent gain. We…

> no internal firewalls do you mean this in the metaphorical sense? an internal firewall has little effect on compromised email accounts. > But we probably cannot make email (more) secure? Can we create standard business messages that can be sent and revived by anyone and signed ? DMARC is fairly well adopted, of course it does nothing against using a typosquatted domain. > (#) a non technical friend lost thousands o…

Every time our C-levels get implicated in this stuff, email is never the medium. It's always text messages.

Which makes sense; they're way easier to spoof, especially if the initial recipient lacks authority to initiate bank transfers and forwards a screenshot of the forged message as "proof" to someone who does-- it launders all metadata from the message itself. Even the timestamp is lost.

And it's all out of band and not subject to internal firewalling, DMARC, nothing.

Never trust text messages (or screenshots of them) as evidence of anything.

Post reply on HN