5 AI Tools Hackers Are Using Right Now (And How to Defend Against Them)

There’s a quiet assumption a lot of people still make about hackers: that they’re lone geniuses hunched over a keyboard, painstakingly writing custom code line by line. That image is outdated. Today’s attackers are increasingly just… prompting.

AI hasn’t just changed how businesses work — it’s changed how attackers work too. The same tools helping marketers write copy and developers debug code are being repurposed, jailbroken, or replaced entirely with underground versions built specifically for cybercrime. Here are five AI tools actually being used in real attacks right now, and what you can do about each one.

1. WormGPT — The “No Rules” Chatbot

WormGPT is marketed openly on underground forums as an AI assistant with zero ethical restrictions. Unlike ChatGPT, it won’t refuse to write phishing emails, malware, or scam scripts, that’s its entire selling point. It’s often built on older open-source language models with the safety training stripped out, then rented out for a monthly fee.

How it’s used: Writing convincing phishing emails, generating malware code snippets, and drafting business email compromise (BEC) scams that read like they came from a real executive.

How to defend against it: Since WormGPT-generated content no longer has the broken grammar that used to flag phishing emails, train your team to verify requests, not writing quality. Any email asking for money, credentials, or urgent action should be confirmed through a separate channel, every time.

2. FraudGPT — Built for Scams at Scale

FraudGPT works similarly to WormGPT but leans specifically into fraud: generating fake invoices, crafting convincing scam landing pages, and even writing “carding” tutorials for stolen credit card data. It’s sold as a subscription service, sometimes for as little as $200/month.

How it’s used: Mass-producing convincing scam pages, fake login portals, and fraudulent billing emails that mimic real companies almost perfectly.

How to defend against it: Bookmark your actual login pages rather than clicking links from emails. Enable multi-factor authentication everywhere it’s offered, it stops most scams even if someone does enter their password on a fake page.

3. AI Voice Cloning Tools

Legitimate AI voice cloning tools, built for things like audiobook narration or accessibility, are being repurposed by scammers to clone the voices of executives, family members, and public figures. Some only need a few seconds of audio to produce a convincing clone.

How it’s used: Fake “urgent” phone calls from a cloned CEO voice authorizing a wire transfer, or a cloned “family member” voice claiming to be in an emergency and asking for money.

How to defend against it: Set up a private verification phrase with your team or family for high-stakes requests. If a call feels off, hang up and call the person back on a number you already have saved.

4. AI-Powered Reconnaissance Tools

Before attacking a target, hackers research it, employees, systems, vendors, even internal jargon. AI tools can now scrape and summarize a company’s public digital footprint in minutes, work that used to take a skilled attacker hours or days.

How it’s used: Quickly building detailed profiles of employees (job titles, reporting structure, social media activity) to craft highly targeted phishing or social engineering attacks.

How to defend against it: Audit what’s publicly available about your company and employees. Limit oversharing on LinkedIn about internal processes, org charts, and vendor relationships — the less there is to scrape, the harder targeted attacks become.

5. AI Code Assistants (Jailbroken or Misused)

Legitimate AI coding tools are incredibly useful, and that’s exactly the problem. With the right prompting tricks, attackers can get mainstream AI coding assistants to generate functional exploit code, obfuscation scripts, or malware variants by disguising the request as “research” or breaking it into smaller, less obviously malicious pieces.

How it’s used: Speeding up the creation of new malware variants that can slip past antivirus tools built to recognize older, known versions.

How to defend against it: Rely on behavior-based security tools rather than ones that only catch known malware signatures. Behavior-based detection watches for suspicious actions (like a program trying to access files it shouldn’t) rather than matching against a list of known threats, making it far more effective against brand-new variants.

The Bigger Picture

None of these tools are doing something entirely new. Phishing, malware, and scams have existed for decades. What’s changed is the speed and accessibility,  tasks that used to require real technical skill are now available as a monthly subscription, in plain English, to anyone willing to pay for it.

That means more attackers, more attempts, and less time to catch mistakes. The good news: the fundamentals of good security, verification, multi-factor authentication, limiting your public footprint, and behavior-based detection, still work. They just matter more than ever.

Frequently Asked Questions

Are WormGPT and FraudGPT illegal to use? Using them to commit fraud, write malware, or conduct cyberattacks is illegal in most jurisdictions, though the tools themselves often operate in legal gray areas depending on how they’re marketed and hosted.

Can regular antivirus software catch AI-generated malware? Traditional signature-based antivirus can struggle with new AI-generated variants. Behavior-based and AI-assisted detection tools tend to perform better against this newer wave of threats.

How can I tell if a phishing email was AI-written? It’s getting much harder, AI removes the grammar mistakes that used to be a reliable red flag. Focus instead on verifying the request itself through a separate, trusted channel.

Is it safe to use AI coding assistants for my own work? Yes, the tools themselves aren’t inherently dangerous. The risk comes from how they can be misused by bad actors, not from using them for legitimate development work.

Attackers aren’t getting smarter overnight — they’re getting faster and cheaper to scale. The businesses that adapt their basic defenses now will be far better positioned than the ones waiting to see how bad it gets.

Leave a Reply

Your email address will not be published. Required fields are marked *