How WormGPT Makes Business Email Scams More Convincing

WormGPT is an AI model shared on cybercrime forums and designed to support malicious activity, including convincing phishing and Business Email Compromise emails. Researcher Daniely Kelley says clear, polished messages can make scams harder to spot, so organizations should train staff and strengthen email verification.

WTF Index TERMINATOR
◄ Terminator 4 Idiocracy 1 ►

WormGPT helps criminals create more convincing phishing and payment scams, making AI a more capable tool for harm.

How WormGPT Makes Business Email Scams More Convincing

Fraudulent business emails can now be written with the help of tools built for cybercrime. Researcher Daniely Kelley says WormGPT can produce persuasive messages for phishing and Business Email Compromise (BEC), including attempts to trick employees into approving bogus payments.

AI can help scammers sound convincing

Kelley, a British computer hacker researching WormGPT, says he has observed a new wave of convincing fake emails on underground forums. Generative AI tools can produce grammatically correct messages, which may avoid some of the clues employees have traditionally associated with phishing.

The tools may also widen access to these attacks. Someone who is not fluent in a particular language can use AI to create a persuasive email in it. Kelley says this makes attackers more capable of producing phishing and BEC messages.

Some cybercriminals also exchange prompts called “jailbreaks” that seek to manipulate models such as ChatGPT. These prompts may aim to elicit sensitive information or malicious code. The broader concern is that readily available AI can lower the effort required to create plausible scam messages.

What WormGPT is designed to do

WormGPT is an AI model intended for criminal and malicious activity. It is shared on popular cybercrime forums and promoted as a “blackhat” alternative to official GPT models, with claims around privacy protection and “fast money.”

Like ChatGPT, it can generate convincing, strategically written emails. Kelley describes it as ChatGPT with “no ethical boundaries or restrictions.” That makes it potentially useful to criminals trying to impersonate a manager, supplier, or other trusted business contact.

The model is based on the open-source GPT-J model, which approaches the performance of GPT-3. It can handle text tasks similar to ChatGPT and write or format simple code. WormGPT is said to have been trained with additional malware datasets, but its author has not disclosed what those datasets are.

A bogus bill tests the risk

To examine how the tool might be used, Kelley tested it with a phishing scenario: an email designed to persuade a customer service representative to pay an urgent, fake bill. The message was framed as coming from the targeted company’s CEO.

Kelley called the result “unsettling” and described the generated email as “remarkably persuasive, but also strategically cunning.” The example shows how a familiar business request can be turned into a convincing payment demand. A polished message may give a recipient fewer obvious reasons to pause, especially when it appears to come from someone with authority.

Kelley warns that even inexperienced cybercriminals could pose a significant threat with a tool like WormGPT. The concern is not limited to one model: as AI tools spread, other ways of using them in attacks may emerge.

Prevention needs clear checks

Kelley argues that prevention is essential for organizations facing AI-assisted BEC attacks. Staff training should address the specific tactics used in business email compromise, while email verification processes should make it harder for a convincing message alone to trigger a payment.

Organizations can also use alerts to draw attention to messages that appear to come from outside the company while impersonating managers or suppliers. Systems may flag terms associated with BEC attempts, including “urgent,” “sensitive,” or “wire transfer.” These signals can help prompt closer review of a message.

AI can make fraudulent emails more polished, but organizations can still build safeguards around how requests are checked. Training employees to recognize suspicious payment requests and verifying the sender through established measures can reduce reliance on the message’s wording or apparent authority.