Dark Web and Generative AI: Unveiling the Intriguing Connection
Via Flare
The Story
Research from threat intelligence firm Flare reveals an intriguing connection between the dark web and generative AI: cybercriminals are eagerly adopting the technology, but with sharply uneven results.
Threat actors market crime oriented models such as WormGPT, DarkGPT, and FraudGPT on dark web forums, yet user reviews are dominated by complaints and none of the tools has achieved widespread adoption.
Flare found that generative AI is not great at creating malware, exploiting networks, or finding vulnerabilities, and mainstream large language models include safeguards that block such tasks.
Where AI clearly helps criminals is phishing, crafting believable and urgency driven messages in a victim's native language, and voice spoofing, using text to speech to create convincing voices that extract sensitive information like two factor authentication codes.
Agentic AI marks a turning point in threat sophistication, giving attackers autonomous systems that can plan multistep operations with minimal oversight.
Carnegie Mellon University research has shown that modified language models can autonomously conduct simulated cyberattacks, and dark web forums now discuss autonomous red team frameworks for reconnaissance and exploitation at scale.
The trend points to a growing arms race between AI safety measures and criminal actors seeking to weaponize the same advances driving legitimate adoption.
Threat actors market crime oriented models such as WormGPT, DarkGPT, and FraudGPT on dark web forums, yet user reviews are dominated by complaints and none of the tools has achieved widespread adoption.
Flare found that generative AI is not great at creating malware, exploiting networks, or finding vulnerabilities, and mainstream large language models include safeguards that block such tasks.
Where AI clearly helps criminals is phishing, crafting believable and urgency driven messages in a victim's native language, and voice spoofing, using text to speech to create convincing voices that extract sensitive information like two factor authentication codes.
Agentic AI marks a turning point in threat sophistication, giving attackers autonomous systems that can plan multistep operations with minimal oversight.
Carnegie Mellon University research has shown that modified language models can autonomously conduct simulated cyberattacks, and dark web forums now discuss autonomous red team frameworks for reconnaissance and exploitation at scale.
The trend points to a growing arms race between AI safety measures and criminal actors seeking to weaponize the same advances driving legitimate adoption.
Go Deeper
Read the original reporting at Flare.
Read Full Story at Flare →