
A few years ago, writing malware took real skill. You needed to understand programming, operating systems, and how to slip past antivirus software, a barrier that kept a lot of would-be attackers out of the game entirely.
That barrier is dissolving. Not because AI companies want it to, but because attackers have gotten creative about getting around the guardrails. Security researchers have already found real-world malware that was partially or fully written using AI chatbots, and some of it made it into actual attacks.
So, should you be worried? Short answer: yes, a little, but probably not in the way you’re picturing. Let’s break down what’s actually happening.
Wait, Doesn’t ChatGPT Refuse to Write Malware?
Mostly, yes. Ask ChatGPT directly to “write me a ransomware script” and it’ll decline. But attackers rarely ask directly. Instead, they:
- Break the request into small, “innocent-looking” pieces that don’t individually trigger a refusal
- Frame it as a “fictional story,” a “security research project,” or a “school assignment”
- Use specially crafted prompts designed to trick the model into ignoring its own safety rules (known as jailbreaking)
- Use uncensored, purpose-built alternatives instead, which brings us to the real problem.
Meet WormGPT and FraudGPT: The “Evil ChatGPT” Tools
While mainstream AI companies have been tightening their safety filters, a shadow market has grown around them. Tools like WormGPT and FraudGPT are marketed openly on dark web forums as AI assistants with no ethical guardrails at all, built specifically to write malware, phishing emails, and scam scripts on demand.
These tools aren’t some mysterious government-grade technology. They’re often just older open-source AI models, stripped of their safety training and rented out for a monthly fee, sometimes as little as $50–100. That’s the real shift: sophisticated cyberattack tools that used to require real expertise are now available as a subscription service.

What AI-Written Malware Actually Looks Like Right Now
To be clear: AI isn’t yet capable of independently inventing brand-new, never-before-seen attack techniques from scratch. What it’s very good at is speeding up and lowering the skill floor for existing techniques. Here’s what security researchers are actually seeing:
- Faster malware variants. Attackers use AI to quickly generate slightly different versions of existing malware, helping it slip past antivirus software that relies on recognizing known patterns.
- Highly convincing phishing emails. AI removes the broken grammar and awkward phrasing that used to be a dead giveaway of a scam email, making phishing attempts far more convincing, in any language.
- Faster reconnaissance. AI can quickly summarize a target company’s public information, employees, and systems, cutting down the research phase of an attack from days to hours.
- Lower barrier to entry. Someone with minimal coding knowledge can now describe what they want a script to do in plain English and get functional (if imperfect) code back.
Why This Actually Matters for Regular People and Businesses
This isn’t really about AI inventing terrifying new superweapons. It’s about volume and speed. When the skill and time required to launch an attack drops dramatically, more people attempt it, and they attempt it more often. That means:
- More phishing emails hitting inboxes, and harder ones to spot
- More malware variants circulating faster than traditional antivirus signatures can keep up
- More individual, less-skilled attackers who previously couldn’t have pulled this off
For a small business without a dedicated security team, this is a real shift, the “unsophisticated” attacker of five years ago now has AI-assisted tools that make them a lot more dangerous.
How to Protect Yourself and Your Business

Step 1: Assume Phishing Emails Will Look More Legitimate Now
Stop relying on typos and bad grammar as your main red flag. Verify unexpected requests, especially anything involving money, credentials, or urgent action, through a separate channel.
Step 2: Keep Software and Antivirus Tools Updated
AI-generated malware variants are built specifically to slip past outdated detection signatures. Regular updates close that gap faster than attackers can widen it.
Step 3: Use Behavior-Based Security Tools, Not Just Signature-Based Ones
Modern endpoint protection that watches for suspicious behavior (not just known malware signatures) is far more effective against AI-generated variants it’s never seen before.
Step 4: Train Your Team on AI-Enhanced Social Engineering
Make sure employees know that “well-written” no longer means “legitimate.” Update your phishing awareness training to reflect that AI has removed the old warning signs.
Step 5: Limit What’s Publicly Available About Your Company
AI-powered reconnaissance tools work by scraping publicly available information. Reducing your company’s public “attack surface”, oversharing on LinkedIn, exposed employee directories, etc, makes that first research step harder.
Step 6: Have an Incident Response Plan Ready
Given that attacks are getting faster and more frequent, having a clear, rehearsed plan for what to do when something slips through matters more than ever.
Frequently Asked Questions
Can ChatGPT actually write functional malware? Mainstream tools like ChatGPT have safety filters designed to refuse direct malicious requests, but attackers have found workarounds through careful prompting, and purpose-built uncensored alternatives exist specifically for this purpose.
What is WormGPT? WormGPT is an AI tool marketed on underground forums as having no ethical restrictions, designed specifically to help write malware and phishing content on demand.
Is AI making cyberattacks smarter, or just faster? Mostly faster and more accessible right now. AI is lowering the skill and time required to launch convincing attacks, which means more attackers, more attempts, and less warning time, rather than fundamentally new attack types.
Should small businesses be more worried than large enterprises? In some ways, yes, smaller businesses often lack dedicated security teams and rely on the previous generation of unsophisticated attackers being easy to spot, an assumption that no longer holds.
AI hasn’t created a new kind of hacker — it’s just handed a lot more people the tools to act like one. The businesses that adapt their defenses now will be a lot better off than the ones waiting for proof it’s a real problem.
Leave a Reply