HomeSecurityHow hackers train AI chatbots for phishing attacks

How hackers train AI chatbots for phishing attacks

Following the emergence of WormGPT, a clone of the AI ​​chatbot ChatGPT that is trained for phishing, a new AI tool called FraudGPT has been introduced. In addition, another tool that appears to be based on Google's AI venture, Bard.

See also: Meta: Its open-source AI is being used for sex chatbots
AI chatbots

Both AI bots appear to be the creation of the same person. From phishing and social engineering, to exploiting vulnerabilities and creating malware, they appear to specialize in malicious purposes.

FraudGPT was released on July 25th and has been posted on various hacking forums by a user named CanadianKingpin12. He claims that the tool is intended for scammers, hackers, and spammers.

An investigation by researchers at cybersecurity firm SlashNext reveals that CanadianKingpin12 is training new AI chatbots using extensive datasets from the dark web or based on sophisticated language models developed to combat cybercrime.

In a private conversation, CanadianKingpin12 mentioned that he is working on DarkBART – a “dark version” of the artificial intelligence chatbot that creates conversations similar to those of Google.

The researchers also discovered that the malicious user had access to another advanced language model called DarkBERT. This model was developed by researchers in South Korea and trained on data from the dark web. However, the purpose of DarkBERT is to fight cybercrime.

DarkBERT is available to academics via associated email addresses, but SlashNext points out that this benchmark is far from a challenge for hackers or malicious software developers. They can gain access to an email address from an academic institution for around $3.

See also: In the sanctuaries of AI: Chatbots can become dangerous

phishing

SlashNext researchers shared that CanadianKingpin12 said the DarkBERT bot is “a top-of-the-line bot specifically trained on the dark web.” The malicious version is configured to:

  • Creating sophisticated phishing campaigns that target people's passwords and credit card information
  • Performing advanced social engineering attacks to obtain sensitive information or gain unauthorized access to systems and networks.
  • Exploitation of vulnerabilities in computer systems, software and networks.
  • Creation and distribution of malicious software.
  • Exploiting zero-days for financial gain or system disruption.

As CanadianKingpin12 mentioned in private messages to the researchers, both DarkBART and DarkBERT will have full internet and can be seamlessly integrated with Google Lens for image processing. It is unclear whether CanadianKingpin12 modified the code in the legitimate version of DarkBERT or simply gained access to the model and used it for malicious purposes.

Regardless of the origins of DarkBERT and the validity of CanadianKingpin12’s claims, AI chatbots are on the rise and their adoption rate is likely to increase further. This is because they can provide an easy solution for individuals who lack sufficient knowledge or skills as threat actors but wish to expand their activities into other areas.

See also: A new attack significantly affects AI chatbots

With hackers already having access to two such tools that can help execute advanced social engineering attacks and deploying them in less than a month, it “highlights the significant influence of malicious AI on cybersecurity and the cybercrime landscape,” SlashNext researchers believe.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS