Watch out - ChatGPT is being used to create malware

An abstract image of digital security.
(Image credit: Shutterstock) (Image credit: Shutterstock)

The world's most popular chatbot, ChatGPT, is having its powers harnessed by threat actors to create new strains of malware.

Cybersecurity firm WithSecure has confirmed that it found examples of malware created by the notorious AI writer in the wild. What makes ChatGPT particularly dangerous is that it can generate countless variations of malware, which makes them difficult to detect. 

Bad actors can simply give ChatGPT examples of existing malware code, and instruct it to make new strains based on them, making it possible to perpetuate malware without requiring nearly the same level of time, effort and expertise as before. 

For good and for evil

The news comes as talk of regulating AI abounds, to prevent it from being used for malicious purposes. There was essentially no regulation governing ChatGPT's use when it launched to a frenzy in November last year, and within a month, it was already hijacked to write malicioius emails and files

There are certain safeguards in place internally within the model that are meant to stop nefarious prompts from being carried out, but there are ways threat actors can bypass these.

Juhani Hintikka, CEO at WithSecure, told Infosecurity that AI has usually been used by cybersecurity defenders to find and weed out malware created manually by threat actors. 

It seems that now, however, with the free availability of powerful AI tools like ChatGPT, the tables are turning. Remote access tools have been used for illicit purposes, and now so too is AI. 

Tim West, head of threat intelligence at WithSecure added that “ChatGPT will support software engineering for good and bad and it is an enabler and lowers the barrier for entry for the threat actors to develop malware.”

And the phishing emails that ChatGPT can pen are usually spotted by humans, as LLMs become more advanced, it may become more difficult to prevent falling for such scams in the neat future, according to Hintikka.

What's more, with the success of ransomware attacks increasing at a worrying rate, threat actors are reinvesting and becoming more organized, expanding operations by outsourcing and further developing their understanding of AI to launch more successful attacks.

Hintikka concluded that, looking at the cybersecurity landscape ahead, "This will be a game of good AI versus bad AI."

TOPICS
Lewis Maddison
Reviews Writer

Lewis Maddison is a Reviews Writer for TechRadar. He previously worked as a Staff Writer for our business section, TechRadar Pro, where he had experience with productivity-enhancing hardware, ranging from keyboards to standing desks. His area of expertise lies in computer peripherals and audio hardware, having spent over a decade exploring the murky depths of both PC building and music production. He also revels in picking up on the finest details and niggles that ultimately make a big difference to the user experience.

Read more
DDoS attack
ChatGPT security flaw could open the gate for devastating cyberattack, expert warns
Sam Altman and OpenAI
Open AI bans multiple accounts found to be misusing ChatGPT
DeepSeek
Experts warn DeepSeek is 11 times more dangerous than other AI chatbots
A person using DeepSeek on their smartphone
DeepSeek ‘incredibly vulnerable’ to attacks, research claims
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough