From ChatGPT to GhostGPT: dark side of generative AI in cybercrime
GhostGPT is an uncensored generative AI chatbot, and is being used by cybercriminals for creating malware and phishing scams
Generative AI, which marks the future of artificial intelligence (AI), is unfortunately becoming an unprecedented threat to cybersecurity. The primary reason for this is the emergence of GhostGPT, a generative AI tool specifically designed for criminal activity.
The malicious chatbot was developed in late 2024 and empowers cybercrime activity by creating malware, crafting phishing emails, BEC scams and more. With its advanced offensive capabilities, even low-skilled criminals can cause bigger cybersecurity threats.
What is GhostGPT?
In simple words, this is a tool built for crime. Unlike mainstream AI models, such as ChatGPT, which are restricted by ethical safeguards, GhostGPT operates without any restrictions. Security analysts consider it either a jailbroken large language model (LLM) or an open-source AI stripped of safety protocols. This enables it to generate:
- Personalized phishing emails that mimic corporate tones and individual writing styles
- Realistic fake login pages to steal credentials
- Polymorphic malware that evolves to evade detection
- Step-by-step guides for attackers to manipulate vulnerabilities
- Doesn’t log interactions making attribution nearly impossible, enabling cybercriminals a dangerous layer of anonymity.
Supercharging phishing and malware
The top cyber threat is phishing with 84% of UK businesses affected by it in 2024 only. GhostGPT aggravates this by producing highly convincing scams in seconds without minimal effort.
In addition, the tools also lower barriers to sophisticated attacks. Previously, it took expertise skills and time to create polymorphic malware. However, novice hackers can now generate malicious code with the help of simple prompts.
A 2023 IBM study confirmed that LLMs are capable of producing functional malware with minimal input.
Future of cybercrime
While GhostGPT poses a severe challenge, its risks can be mitigated by regular patching, multi-factor authentication (MFA), and advanced employee training.
In addition, endpoint detection and response (EDR) and extended detection and response (XDR) can be deployed to identify anomalies. Leveraging threat intelligence can also be utilised for real-time monitoring of emerging attack methods.
-
Dubai becomes millionaire hotspot after 102% wealth surge: Report finds
-
‘It's time to say goodbye’: Gary Stevenson pauses YouTube channel amid mental health struggles
-
Lamine Yamal strongly warned about romance with girlfriend Ines Garcia
-
Lamine Yamal’s girlfriend Ines Garcia hits 4 Instagram followers after Spain’s World Cup win
-
US sports betting nears $300 billion as experts warn of addiction risks
-
Are we closer to a real-life ‘genie’ that grants any wish: Here's what Sam Altman thinks
-
Elon Musk’s recent claim about Bill Gates sparks fresh online controversy
-
Watch: Kaitlan Collins’ reaction to Trump’s remarks
-
Max Verstappen slams ‘broken’ Red Bull after Hungary shocking qualifying disaster
-
Trump reacts to Ferran Torres' viral 'Make Spain Great Again' hat
-
Ferran Torres, Marcos Llorente become target of false claims after Ibiza photos go viral
-
Typhoon Noul nears Southern China, prompting high alerts and public transport suspensions