Analysis · curated 6 Oct 2026
The Dual-Use Dilemma of AI: Malicious LLMs
First reported paloaltonetworks.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
Dark LLMs like WormGPT and FraudGPT lower the barrier for scalable, convincing social-engineering attacks, meaning defenders can no longer rely on grammatical or stylistic tells to spot phishing and must retrain staff against AI-driven lures.
The Arsen blog analyzes the rise of "Dark LLMs" — malicious models such as WormGPT, FraudGPT and KawaiiGPT sold on Telegram and dark web forums without safeguards — drawing on Palo Alto Networks Unit 42 research to describe how attackers use them to automate phishing, BEC, malware generation and AI-generated voice/face impersonation. It cites a CrowdStrike-reported 134% rise in vishing intrusions between 2024 and 2025 and argues traditional cues like bad grammar no longer detect AI-crafted lures.