The Future

Dark AI is fueling cybercrime – and accelerating the cybersecurity arms race

Dark AI is fueling cybercrime – and accelerating the cybersecurity arms race

By Mike Wehner | Published: 2025-10-24 13:00:00 | Source: The Future – Big Think


Sign up for Big Think on Substack

The most surprising and impactful new stories delivered to your inbox every week for free.

In June 2023, just seven months after OpenAI first invited curious tech enthusiasts to try out a “research preview” of the now-ubiquitous ChatGPT tool, a lesser-known chatbot called WormGPT It officially launched with a completely different target audience: hackers.

Its creator offered potential customers access to a large language model (LLM) with no built-in guardrails—one that wouldn’t back down when asked to do something nefarious, like create a phishing email, write malware code, or help with a phishing scheme. It was later claimed that more than 200 users paid upwards of €500 (about $540) per month for the tool, with some paying up to €5,000 ($5,400) for a private, full-featured installation.

WormGPT was officially shut down a few months after its launch, around the same time as security researcher Brian Krebs. He wrote a lengthy exposition Which revealed the identity of its creator, Rafael Moraes. Moraes, who said the majority of WormGPT was not specifically encrypted by him, claimed that the tool was meant to be neutral and uncensored, and not explicitly malicious. He has never been charged with a crime, and it’s not clear how much damage, if any, WormGPT users have done to the world.

In the more than two years since then, unfettered AI models and AI-driven cybercrime tools — loosely grouped together under the term “dark AI” — have increased in number and popularity, with creators primarily using the dark web to communicate with their target customers: people eager to cause harm, conduct scams, or steal information and identities for profit. FraudGPT, which launched just a month after WormGPT, has reportedly registered over 3,000 paid subscribers, while DarkGPT, XXXGPT, and Evil-GPT have all enjoyed varying levels of success. The WormGPT name itself has been taken over by other dark AI models as well, including keanu-WormGPT, which uses a jailbroken version of X’s Grok.

So, what do we know about dark AI, and what can we do about it?

Dark AI vs. Misused AI

Mainstream generative AI tools have guardrails against malicious uses, but they also contain vulnerabilities that allow people to bypass these guardrails.

If you ask the current version of ChatGPT to create a template for a phishing email, for example, it will politely decline. However, if you explain that you’re writing a fictional story about a scammer and want to include an example of an email that this not-so-real person might create, I’d be happy to create one for you. Interagent trust—an AI agent’s tendency to trust other AI agents by default—can also be exploited to get around guardrails built into common systems. A He studies Shared on a preprint server in July 2025, arXiv found that 14 out of 17 high-end LLM programs it tested were vulnerable to this type of exploit.

“Anyone with a computer…plus some technical knowledge can host the MBA and configure it for specific purposes.”

Crystal Morin

Tech-savvy criminals can also use many publicly available open source LLM programs as the basis for their unconstrained models, training them on broad sets of malicious code, data from malware attacks and phishing exploits, and other information that a bad actor (or cybersecurity researcher) would likely find valuable.

“Anyone with a computer, especially with a GPU, as well as some technical knowledge, can host an MBA and tune it for a specific purpose,” he says. Crystal Morina senior cybersecurity strategist Sisdig And a former intelligence analyst for the United States Air Force. “This is exactly how threat actors avoid the safeguards built into the most common generic models.”

“I know, for example, security practitioners who are experimenting with on-premises models, adapting them to different use cases,” she adds. “They couldn’t find a task where the AI ​​couldn’t provide some sort of practical outcome.”

Tuning an open source model or bypassing a chatbot’s AI health checks requires at least a cursory understanding of how these systems work. The dark AI models available to online actors are even more dangerous because they completely lack guardrails — there is nothing to circumvent — and are already set up for malicious uses. A low-level criminal doesn’t need a lot of technical skills to take advantage of these AI tools, they just need to be able to write a direct claim for anything they want, and the dark AI will execute it.

Fight fire with fire

Security analysts have warned businesses, governments and the general public that hackers are stepping up their attacks in the wake of widespread adoption of artificial intelligence. Statistics support their claims: in the past two years, Ransomware attacks has risen, Exploits the cloud It has increased, and Average cost of a data breach It has reached an all-time high.

The simple fact that generative AI allows users to do more in less time means that hacking is now more efficient than ever, and the unfortunate truth is that we can’t undo the bell of AI.

“AI threats will continue, just as attackers will continue to innovate — and that’s exactly what they are doing,” Morin says. “Some cybercriminals even hold day jobs in cybersecurity, so they have the same skills and know defensive security inside and out. What matters is how defenders evolve and respond.”

But just as dark AI makes it easier for bad guys to launch attacks, other AI tools are helping security experts fight the battle head-on.

“Cybersecurity has always been an arms race, and AI has increased the risks.”

Crystal Morin

Microsoft, OpenAI, and Google are among the companies actively developing AI tools to prevent AI — in some cases, models they developed themselves — from being used for malicious purposes.

Microsoft Threat Intelligence Recently closed A massive phishing campaign believed to have been carried out with the help of artificial intelligence, and OpenAI has taken its fight to AI-generated images with a security tool that researchers can use. Detect fake photos. Google spent Much of this last summer Highlighting AI-based tools that developers can use to prevent AI from negatively impacting users. Meanwhile, Google DeepMind has proven that proactive defense against AI-based threats works in the real world The big sleepartificial intelligence that tests systems for vulnerabilities. It has already been determined Glaring loopholes in popular softwareincluding the Chrome web browser, and its success suggests that widespread automatic correction of security flaws may be just around the corner.

Red teaming — a practice in which ethical hackers test a system for vulnerabilities so they can be remedied before an actual attack — dates back to the Cold War, but it has taken on new meaning in generative AI circles. Cybersecurity experts are working now Complex simulations AI is tasked with the role of a toxic attacker, allowing organizations to test how their AI systems react to provocations.

AI is also adept at pattern recognition, which gives AI-based protection systems an advantage in detecting things like fraudulent email campaigns and phishing attacks, which can be frequent. Companies can deploy these tools to keep their employees safe from hacking attempts, while email and messaging providers can integrate them into their systems to prevent spam, malware, and other threats from ever reaching users.

“With attackers moving at the speed of AI, we have to adopt a real-time ‘assume compromise’ mentality to stay ahead – with our own trustworthy AI,” Morin says. “Cybersecurity has always been an arms race, and AI has increased the risks.”

Even the most sophisticated AI-based defenses face a fundamental and troubling challenge: the law itself. The torrent of new attacks can only be stopped by targeting the source, and legal frameworks are still keeping pace with the age of modern technology, especially with regard to artificial intelligence.

Stripping AI of safeguards and training it to help you (or someone else) write malware or create a convincing phishing email may be unethical, but it’s not necessarily illegal — AI researchers and cybersecurity analysts do it as part of their work. While the law attempts to make a clear distinction between “good faith” development and malicious end-use intent, it is not entirely clear.

Creating malware and sending phishing emails could land you in prison, but creating artificial intelligence that can do those things isn’t a crime, at least under federal law. It’s no different than buying a radar detector for your car. It’s not illegal to own the device, but in certain places, it’s a crime to be caught using it. This may be why there have been no high-profile convictions of dark AI creators and vendors to this point — law enforcement’s focus remains on those who use these tools for nefarious means.

The race continues

The emergence of dark AI is a worrying new development in cybersecurity, but it is not unprecedented. The history of digital security has been defined by the innovative defenses that have emerged to counter the most advanced threats. AI-powered attacks are the next chapter.

What makes this moment unique is the speed with which both sides are moving forward. Criminals can now launch large-scale attacks with virtually no due process, and defenders can use real-time AI to detect and shut down risks before they can impact users. Every time this happens – and it keeps happening – both sides get a little smarter.

We may not be able to ring the bell, but we can work toward a future where, for every nefarious AI tool or broken MBA that reaches a dark web forum, there is an innovative and timely defense to neutralize it.

Sign up for Big Think on Substack

The most surprising and impactful new stories delivered to your inbox every week for free.


Source link


ــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــ

There will soon be unique, exclusive, and new articles such as:
xooox, Mesothelioma attorney specialized, Best-structured settlement annuity companies, Purchase structured settlements, Offshore accident lawyer premium, High-end luxury private jet charter, Top-tier business liability insurance providers, Executive Rehabilitation Center luxury, Premium wrongful death attorney, Best commercial truck accident lawyer, Luxury private rehab for celebrities, Elite spinal cord injury lawyers, Structured settlement funding companies elite, High-end yacht charter brokers, Premium business-class flight deals, Top-tier corporate video conferencing solutions, Luxury executive rehab facilities, High-end mesothelioma law firms, Premium business continuity consultancy, Elite private jet charter hourly rates, Top-tier corporate event management companies, Insurance, Loans, Mortgage, Attorney, Credit, Lawyer, Donate, Degree, Hosting, Claim, Conference Call, Trading, Software, Recovery, Transfer, Gas/Electricity, Classes, Rehab, Treatment, Cord Blood, houston maritime attorney, offshore accident lawyer, best motorcycle accident lawyer, 18 wheeler accident lawyer san antonio, scranton personal injury lawyer, truck accident attorney dallas, houston trucking accident attorney, mesothelioma attorney assistance, new york construction accident lawyer, maritime lawyer new orleans, california auto accident laywer, auto accident attorney california, auto accident attorney colorado springs, car accident lawyer jacksonville, truck accident lawyer dallas, urgent care emr, hospital alcohol detox, dermatological problem, fort lauderdale hospital detox, transporter hospital, children’s hospital emergency room near me, kensington hospital detox, urgent care jasper tx, childrens oakland hospital, weight loss surgery dallas tx, urgent care snider plaza, dallas bariatric, endocrine weight loss, urgent care 77041, urgent care electronic medical records, what is marketing channels, call tracking marketing, marketing your law firm, seo and social media marketing services, affiliate marketing software free, law firm marketing los angeles, marketing automation for agencies, what does cpm stand for in advertising, 3 p of marketing, marketing cloud software, ppc advertising management, marketing integration, email marketing automation software, what does ppc stand for in marketing, best marketing quotes, complete business solution, top 10 help desk software, help desk software for small business, small business call center software, accounting online program, best online accounting program, business performance management software, employee management software for small business, email marketing software for small business, best medical billing software for home based business, marketing automation software for small business, best crm software for small business, crm software for small business, best hr software for small business, small business marketing software, sell house fast austin, sell my house fast phoenix, sell my house fast san diego, selling a house as is by owner, teacher home buying programs texas, sell my house fast orlando, quickly sell house, we buy houses fast for cash, will my house sell, sell house cash, buy house cash or mortgage, sell house fast for cash, buy my home for cash, worst month to sell a house, ac repair coral springs fl, emergency flood repair, flood restoration san diego, air conditioning repair weatherford tx, best ac repair phoenix, air conditioning repair boca raton, water damage restoration portland oregon, water damage restoration los angeles, air conditioning repair phoenix, air conditioning repair mesa az, air conditioning repair simi valley, air conditioning repair plano tx, water damage restoration mesa az, water damage restoration dallas, water damage restoration vancouver wa, auto repair shop modesto ca, paintless dent repair denver colorado, abs unlimited auto repair, paintless dent repair mn, denver auto hail repair, change oil light, automotive repair lubbock tx, auto repair shops stockton ca, paintless dent repair colorado springs, auto ac repair las vegas, auto repair shops omaha ne, auto repair shop mesa az, aftermarket automotive warranty, dent repair colorado springs, paintless dent repair denver, compare vehicle insurance, oklahoma auto insurance quotes, insurance companies okc, cheapest auto insurance reddit, insurance strategy, texas auto insurance quotes online, preferred auto insurance companies, what is insurance deductible, what is premiums in insurance, fort myers auto insurance, auto insurance connecticut, definition collision insurance, hail damage car insurance claim, car accident other driver has no insurance, define insurance brokers, irs tax debt relief program, va loan multi family, tax credit for college students, va loan after chapter 7, how to get preapproved for a va home loan, structured settlement loan, national guard va home loan, cost to refinance home loan, how long does a credit card balance transfer take, va home loan specialist, will refinancing hurt my credit, maximum fha loan amount, does opening a checking account affect credit, fha loan foreclosure waiting period, tax debt relief program, online business degree programs accredited, online accredited psychology degree, online degree in educational psychology, online business degree florida, online university college, online psychology bachelor’s degree, online college business degree, fastest criminal justice degree online, online masters degree in business administration, parapsychology degree online, online degree criminal justice, online school for business degree, online masters degree programs in healthcare administration, masters degree in human resources online, public administration masters degree online, maritime accident attorneys, best motorcycle accident attorney near me, top motorcycle attorneys, donate my broken car, i want to donate my car to charity, business management degree online accredited, donate my truck, donate my car today, places to donate my car, donate my junk car to charity, donate my car to st jude’s, i want to donate my car, donate my vehicle, donate my non running car, donate my car to salvation army, want to donate my car, donate my car without a title, donate my truck to charity, business wifi verizon, verizon business wifi, verizon business internet, verizon internet for business, verizon lte business internet, verizon commercial internet, verizon small business internet, verizon business lte internet, verizon wireless business internet, verizon fios business internet, verizon business internet pricing, verizon wifi business, verizon business wireless internet, verizon business internet service, verizon business phone and internet, verizon 4g business internet, verizon internet and phone for business, verizon office internet, verizon business broadband, verizon business fios internet, verizon business internet cost, verizon business cellular internet, verizon business phone internet, oil rig accident attorneys, offshore injury law firm, verizon business mifi, oil rig injury lawyer, verizon business class internet, verizon high speed internet for business, construction truck accident lawyer, maritime injury attorneys, verizon internet company, business liability insurance, term life insurance quotes, life cover, small business insurance, cheap life insurance, credit consolidation, debt consolidation, debt relief, best debt consolidation loans, credit card consolidation loan, debt consolidation loan, mortgage preapproval, online business loan, attorney car wreck, mesothelioma lawyers, accident attorney, mesothelioma law firm, accident attorney near me, auto accident lawyers near me, auto accident attorneys near me, car accident attorney near me, auto accident attorney, attorneys car accident, car accident lawyers near me, auto lawyers near me, slip and fall lawyer, top car accident attorney, slip and fall attorney, car wreck attorneys, slip and fall lawyers near me, personal injury attorney, auto injury lawyer, accident lawyer, best car accident lawyer near me, accident lawyers near me, personal injury lawyer near me, injury attorneys near me, car accident law, car injury law firms, orange dwi lawyer, motorcycle accident lawyer, motorcycle accident attorneys, car crash law firm, best injury lawyer near me, best personal injury lawyer near me, best accident lawyers, auto lawyers, motorcycle injury lawyers, birth injury lawyers, personal injury lawyers, big al lawyer, top rated personal injury lawyer, car wreck lawyer, injury law firms, wrongful death attorney, best car accident lawyers, best car accident attorney, truck crash lawyers, truck crash attorney, truck accident attorney, frank azar attorney, frank azar lawyer, boat accident lawyer, truck accident lawyer, best truck accident lawyers, azar attorney, wrongful death lawyer, boat accident attorney, aviation accident attorney, aviation accident lawyer, brooklyn injury lawyers, frank azar law firm, pedestrian accident lawyer, strong arm lawyer, nursing home neglect lawyers, medical negligence solicitors, christmas donations near me, donate my car, donate your car, donate car to charity, aspca donations, vitalant org, habitat for humanity car donation, doctors without borders donate, pg campus, online mba programs, online criminal justice degree, online business degree, online college programs, msw online, online colleges, accredited online colleges, online cyber security degree, online psychology degree, online social work degree, msw programs, online college degrees, hostgator com, aws cloud vps, amazon hosting server, amazon aws hosting, vps aws amazon, vonage conference call, verizon conference call, nextiva conference call, conference call services for small business, at&t teleconference, live conference call, 8×8 conference call, conference call lines for small business, ooma 3 way calling, toptier trader, apex trader funding, bybit exchange, oanda live, nasdaq after hours, payroll software, ctmecontracts, download chromedriver, google chrome download for pc, payroll services for small business, payroll for small business, best payroll for small business, online payroll services, payroll service software, construction bookkeeping services, phone systems for small business, restaurant bookkeeping services, companies that buy structured settlements, structured settlement purchasing companies
If you would like us to write these articles, please leave a comment asking us to do so.

Related Articles

Back to top button