Analysis · curated 6 Oct 2026

The Dual-Use Dilemma of AI: Malicious LLMs

Coverage timeline

discovered paloaltonetworks.com primary 6 Oct 2026arsen.co

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Dark LLMs like WormGPT and FraudGPT lower the barrier for scalable, convincing social-engineering attacks, meaning defenders can no longer rely on grammatical or stylistic tells to spot phishing and must retrain staff against AI-driven lures.

The Arsen blog analyzes the rise of "Dark LLMs" — malicious models such as WormGPT, FraudGPT and KawaiiGPT sold on Telegram and dark web forums without safeguards — drawing on Palo Alto Networks Unit 42 research to describe how attackers use them to automate phishing, BEC, malware generation and AI-generated voice/face impersonation. It cites a CrowdStrike-reported 134% rise in vishing intrusions between 2024 and 2025 and argues traditional cues like bad grammar no longer detect AI-crafted lures.