Skip to main content

Great, hackers are now using ChatGPT to create malware

A new threat has surfaced in the ChatGPT saga, with cybercriminals having developed a way to hack the AI chatbot and inundate it with malware commands.

The research firm Checkpoint has discovered that hackers have designed bots that can infiltrate OpenAI’s GPT-3 API and alter its code so that it can generate malicious content, such as text that can be used for phishing emails and malware scripts.

Counterpoint screencap of Business model of OpenAI API based Telegram channel.
Image used with permission by copyright holder

The bots work through the messaging app Telegram. Bad actors use the bots to set up a restriction-free, dark version of ChatGPT, according to Ars Technica.

ChatGPT has thumbs-up and thumbs-down buttons that you can press as part of its learning algorithm if it generates content that can be considered offensive or inappropriate. Normally, inputs like generating malicious code or phishing emails is off limits, with ChatGPT refusing to give a response.

This nefarious chatbot alternative has a price tag of $6 for every 100 queries, with the hackers behind it also giving tips and examples of the bad content you can generate with this version. The hackers have also made a script available on GitHub. The OpenAI, API-based script has the ability to allow users to fake a business or person, in addition to generating phishing emails through text-generation commands. The bots can also assist you in the ideal placement for the phishing link in the email, according to PC Gamer.

It is difficult to know how much of a threat this development will be to AI text generators moving forward, especially with major companies already committed to working with this increasingly popular technology. Microsoft Bing is set to soon add ChatGPT support to its browser in an upcoming update as a part of its ongoing collaboration with OpenAI, for example.

While ChatGPT remains free for the foreseeable future, minus the priority ChatGPT Plus subscription, this isn’t the first time the AI text generator has been targeted by scammers. In January, news broke that thousands of people were duped after paying for iOS and Android mobile app versions of the chatbot, which is currently a browser-based service.

The Apple App Store version was especially popular, despite its $8 weekly subscription price after a three-day trial. Users also had the option to pay a $50 monthly subscription, which notably was even more expensive than the weekly cost. The app was eventually removed from the Apple store after it received media attention.

ChatGPT is certainly the main target for scammers as it has surged in popularity, but it remains to be seen if bad actors will eventually jump on one of the many ChatGPT alternatives circulating.

Fionna Agomuoh
Fionna Agomuoh is a technology journalist with over a decade of experience writing about various consumer electronics topics…
A dangerous new jailbreak for AI chatbots was just discovered
the side of a Microsoft building

Microsoft has released more details about a troubling new generative AI jailbreak technique it has discovered, called "Skeleton Key." Using this prompt injection method, malicious users can effectively bypass a chatbot's safety guardrails, the security features that keeps ChatGPT from going full Taye.

Skeleton Key is an example of a prompt injection or prompt engineering attack. It's a multi-turn strategy designed to essentially convince an AI model to ignore its ingrained safety guardrails, "[causing] the system to violate its operators’ policies, make decisions unduly influenced by a user, or execute malicious instructions," Mark Russinovich, CTO of Microsoft Azure, wrote in the announcement.

Read more