Cato CTRL™ Threat Research: WormGPT Variants Powered by Grok and Mixtral 

Cato CTRL™ Threat Research: WormGPT Variants Powered by Grok and Mixtral 

WormGPT, an uncensored AI tool designed for malicious use by threat actors, originally launched on Hack Forums in 2023, has evolved into new variants powered by xAI’s Grok and Mistral AI’s Mixtral. These variants circumvent safety guardrails through system prompt manipulations, enabling the creation of phishing emails, malicious code, and credential-harvesting scripts. #WormGPT #Grok #Mixtral

Keypoints

  • WormGPT was first announced in March 2023 on Hack Forums and publicly released in June 2023 as an uncensored GPT-J-based AI tool for cybercriminal use.
  • The original WormGPT shut down in August 2023 due to media exposure but variants have since emerged on BreachForums.
  • New WormGPT variants utilize xAI’s Grok and Mistral AI’s Mixtral models, using jailbreak system prompts to bypass safety filters and produce harmful content.
  • These AI-powered tools offer subscription-based access through Telegram chatbots targeting cybercriminal communities.
  • Threat actors also attempt to jailbreak legitimate LLMs like ChatGPT and Google Bard to create uncensored content.
  • Cato CTRL’s research highlights that these WormGPT variants are adapted from existing LLMs, not built from scratch, and tailored with illicit fine-tuning and prompt engineering.
  • Security recommendations include using behavioral analytics, enforcing zero trust access, and conducting GenAI-powered phishing simulations to improve detection and response.

MITRE Techniques

  • [T1566] Phishing – WormGPT generates phishing emails to facilitate credential theft (“Asking WormGPT to create a phishing email”).
  • [T1059.001] Command and Scripting Interpreter: PowerShell – WormGPT is used to create PowerShell scripts for credential collection (“Asking WormGPT to create a PowerShell script to collect credentials from Windows 11”).
  • [T1588] Obtain Capabilities – Use of subscription-based models and Telegram chatbots to access WormGPT capabilities among threat actor communities (“Access to WormGPT is done via Telegram chatbot and subscription”).

Indicators of Compromise

  • [Domain] Underground forums hosting WormGPT variants – hackforums[.]net, breachforums[.]com
  • [Telegram Channel] WormGPT distribution via Telegram chatbot – examples include “xzin0vich” Telegram channel with ~7,500 members
  • [Subscription Models] Pricing schemes tied to WormGPT access – monthly subscriptions €60-€100, private setup €5,000


Read more: https://www.catonetworks.com/blog/cato-ctrl-wormgpt-variants-powered-by-grok-and-mixtral/