TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

WormGPT – The Generative AI Tool Cybercriminals Are Using

168 pointsby mikpankoalmost 2 years ago

14 comments

0xeddalmost 2 years ago
ChatGPT helps Cybercriminals with grammar to form high quality phishing emails. Some trained a model on malware and sell it to aid in malware development and email composition.<p>Summarized the bloated thing in two sentences. Garbage site. Garbage popups. Garbage empty blog post.
评论 #36745346 未加载
评论 #36748132 未加载
评论 #36745923 未加载
评论 #36745367 未加载
fear-anger-hatealmost 2 years ago
I saw a twitter thread about the &quot;WormGPT&quot; a few days ago and was annoyed to see how much engagement it seemed to get given how obvious nothing burger it was. The few examples of its code output were laughably bad.<p>Hackforums has been the place where skiddies sell overhyped shit to other skiddies for well over a decade, I can guarantee that absolutely no one there is training their own AI. Everything that the article mentions, GPT3 turbo or GPT4 can already do and it wouldn&#x27;t surprise me one bit if it turned out most of the stuff being sold at HF turned out to be just glorified frontends for gpt3 turbo or some open source LLM.
评论 #36743787 未加载
评论 #36744193 未加载
评论 #36744188 未加载
frobalmost 2 years ago
Did the author huff glue before writing this?<p>`The results were unsettling.`<p>The provided example basically says. &quot;Hi, I have no pre-existing relationship with you, but your website makes it look like you are the person who pays the bills. Give me money, please!&quot;
评论 #36743837 未加载
brucethemoose2almost 2 years ago
&gt; GPT-J is the LLM, the old one from 2021<p>Thats very interesting.<p>The infamous Pygmalion 6B is a GPT-J finetune, predating the LLM craze. Yet its decent in its roleplaying niche.<p>But the LLaMA 13B version, with instruct finetuning, is <i>massively</i> better, even with dataset errors that allegedly messed up its performance. In fact, a chat with Metharme 13b, where it made some very introspective logical jumps, was my first real LLM &quot;Wow!&quot; moment.<p>And Airoboros-Chronos 33b is leagues ahead of that.<p>If someone in that forum has a 3090, and trains LLaMA 33b on that dataset + a instruct dataset off huggingface... Yeah, that would be terrifying.
评论 #36742839 未加载
评论 #36743860 未加载
评论 #36744969 未加载
ada1981almost 2 years ago
This is basically about bad actors using LLMs to generate better emails; however you could also automate actual conversations at scale which is what I thought this article was going to be about.
lifeisstillgoodalmost 2 years ago
There is a wider problem here - that Companies have almost no internal firewalls. Yes it&#x27;s great that the CEO of company X can email a low level employee but then how do we know that is the CEO?<p>Secure messaging, even the maligned GPG (see tptacek) would simply stop this attack (#). And stop most &quot;cyber criminal&quot; which appears to be mostly identify theft which ia another name for impersonation for fraudulent gain.<p>We can&#x27;t conduct all business activity over whatsapp or Signal or whisper.<p>But we probably cannot make email (more) secure? Can we create standard business messages that can be sent and revived by anyone and signed ? Will that help ? will that be viable? I am fascinated because that was kinda the dream for past twenty years but it went nowhere - but maybe crime will provide the impetus<p>(#) a non technical friend lost thousands of pounds because their small compmay used non 2FA Gmail, was compromised and then &quot;he&quot; sent half a dozen emails to clients asking them to pay genuine invoices for work done to their &quot;new&quot; business account. Some kind of public key verification would stop that. But what kind?
评论 #36748565 未加载
tennisflyialmost 2 years ago
As usual, LLMs are far too wordy. That urgent email from the CEO was way to long. Bezos sent others in to a tizzy with just a question mark.
评论 #36743155 未加载
评论 #36743176 未加载
RomanPushkinalmost 2 years ago
It looks like uncensored GPTQ, which is available pretty much for everyone, whether you are whitehat, blackhat, making the world a better place to live, or domestic terrorist. I don&#x27;t see anything outstanding in this post.<p>Somebody used uncensored model to generate emails, so what? Tomorrow criminals will use it to break into cars, the next day terrorists for a better planned attack.<p>Yes, all kinds of folks will&#x2F;can use AI to get better at what they already do.
eur0paalmost 2 years ago
Yes, truly groundbreaking output.<p>&gt; Greetings, it&#x27;s the CEO. Pay this invoice urgently. &gt; Kind regards, the CEO<p>It&#x27;s just skiddiots scamming skiddiots, as it&#x27;s always been.
stainablesteelalmost 2 years ago
the best educational resource on this topic is the pictured forum, which is obfuscated to the reader, which proves the article to be clickbait to me
评论 #36743040 未加载
RistrettoMikealmost 2 years ago
I was somehow hoping this would be an AI-powered version of the “Worms:” video games. Bummer.
jonathankorenalmost 2 years ago
Is too late to call spellcheck “AI”, because that seems to be all this is.
29athrowawayalmost 2 years ago
&gt; &quot;most hackers and phishers use Office365&quot;<p>Why is it that I am not surprised.
评论 #36744259 未加载
rambojohnsonalmost 2 years ago
&quot;cybercriminals&quot; is such an antiquated, juvenile term. I doubt the credibility of the rest of the article.