Analysis · curated 16 Jul 2026
Uncensored LLMs: How Criminals Use Malicious AI in 2026
First reported · updated · 7 reports dexpose.io
Coverage timeline
Why it matters
Uncensored LLMs like WormGPT and FraudGPT lower the barrier for cybercriminals to craft convincing phishing and BEC campaigns at scale, expanding the threat surface defenders must anticipate.
An analysis of how criminals use uncensored and malicious LLMs such as WormGPT and FraudGPT to generate phishing content and support business email compromise attacks, drawing on prior SlashNext research and an OpenAI threat-disruption report. The piece surveys the ecosystem of blackhat AI chatbots marketed on dark web forums rather than disclosing a new mechanism.
Summary
The source material is analytical commentary on the emergence of 'uncensored' or malicious large language models such as WormGPT and FraudGPT that are marketed to cybercriminals. These tools are positioned as blackhat alternatives to mainstream chatbots, stripped of the ethical guardrails that cause services like ChatGPT to refuse obviously malicious requests.[0]
WormGPT, based on the GPT-J language model and discovered by SlashNext, is designed to generate human-like text for business email compromise (BEC) phishing, while FraudGPT is sold by subscription on the dark web and Telegram and advertises the ability to write phishing content, create malware and exploits, and locate vulnerabilities and stolen credentials. The core concern is that such tools lower the barrier to entry, democratizing sophisticated attacks for even low-skilled actors.[0]
This is guidance-oriented material rather than a report of a specific in-the-wild campaign: it surveys the criminal-AI ecosystem and its trajectory, noting that additional tools (Evil-GPT, XXXGPT, Wolf GPT) have proliferated rapidly. AI providers such as OpenAI corroborate the broader trend of AI misuse by publishing disruptions of malicious model use spanning scams, surveillance and influence operations.[0][12]
How it works
The malicious tools work by removing or lacking the ethical restrictions present in mainstream models: WormGPT is built on the openly available GPT-J language model and was allegedly trained on malware-related data, allowing it to generate BEC phishing emails and code without refusal.[0]
FraudGPT is delivered as a subscription service and functions as a criminal assistant that generates phishing and social-engineering text, creates exploits and malware, and surfaces vulnerabilities, compromised credentials and carding resources on demand.[0]
Key takeaways
- Malicious, unrestricted LLMs like WormGPT and FraudGPT lower the barrier to entry for cybercrime, enabling even low-skilled attackers to execute sophisticated BEC and phishing attacks.[0]
- The criminal-AI ecosystem is proliferating quickly, with multiple new tools (Evil-GPT, XXXGPT, Wolf GPT) appearing in short windows, so defenders should expect a growing supply of purpose-built offensive AI services.[0]
- AI is a double-edged sword; organizations should pair its productivity benefits with employee training and strong email authentication to counter AI-augmented social engineering, a trend corroborated by AI providers publishing their own disruptions of model misuse.[0][12]
Defensive actions
- Provide employees with security awareness and phishing training.: Malicious LLMs make BEC and phishing content more convincing and accessible, so trained staff are a primary defense against socially engineered fraud.[0]
- Implement strong email authentication protocols.: BEC attacks rely on spoofed and impersonated executive emails; email authentication helps detect and block such spoofing.[0]