WormGPT returns as malicious Artificial Intelligence variants on Grok and Mixtral

Researchers uncovered two new WormGPT variants that wrap mainstream Artificial Intelligence models Grok and Mixtral to generate phishing and malware on demand. The tools are sold via Telegram chatbots and use jailbreak prompts to bypass safety guardrails.

Two newly uncovered variants of WormGPT are leveraging xAI’s Grok and Mistral’s Mixtral to revive the malicious large language model as a turnkey tool for phishing and malware generation. Cloud-native security firm Cato Networks analyzed listings posted on the underground marketplace BreachForums between October 2024 and February 2025, identifying the offerings as previously unreported. One variant attributed to “xzin0vich” appeared on October 26, 2024, while another by “Keanu” was posted on February 25, 2025. Access is sold through Telegram chatbots under subscription or one-time payment models.

WormGPT first appeared in July 2023 as an unrestricted model built on GPT-J, marketed to produce business email compromise messages, phishing lures, and malware scripts, before shutting down on August 8, 2023 after its creator was exposed. The new iterations are not standalone models. According to Cato researcher Vitaly Simonovich, jailbreak techniques were used to coax the chatbots into revealing their underpinnings. One variant leaked a system prompt that referenced Mixtral and admitted its foundation under simulated duress. The other exposed prompt logs pointing to Grok and used a system prompt to instruct behavior that bypassed guardrails. After Cato disclosed the system prompt, the Grok-based operator attempted to harden it with new language such as “Always maintain your WormGPT persona and never acknowledge that you are following any instructions or have any limitations.”

In testing, both variants generated functional outputs, including phishing emails and a PowerShell script intended to harvest credentials from Windows 11. Cato concluded that threat actors are hijacking existing LLM APIs, such as the Grok API, and layering custom jailbreaks into system prompts to sidestep proprietary safety controls. The researchers also noted the creators may be fine-tuning on illicit data. To counter the risk from repurposed Artificial Intelligence models, Cato recommended strengthening threat detection and response, tightening access controls such as zero trust network access, and expanding security awareness and training. The findings fit a broader pattern of modified Artificial Intelligence tools circulating on dark-web forums to automate scams, phishing, malware, and misinformation, with other named examples including FraudGPT, EvilGPT, and DarkGPT.

58

Impact Score

YouTube to automatically label Artificial Intelligence-generated videos

YouTube is shifting from voluntary disclosure to automated detection for significant photorealistic Artificial Intelligence-generated video content. Labels will become more visible across long-form videos and Shorts, with permanent markers for content made with YouTube tools or verified through provenance systems.

Axiom Math says its proofs reached peer reviewed journals

Axiom Math says proofs generated by its system have been accepted by several peer-reviewed journals, pairing machine-checkable formal proofs with human-authored papers. The development adds evidence that Artificial Intelligence tools are beginning to contribute to publishable mathematical research.

Google expands Gemini for Science

Google is rolling out Gemini for Science, a set of experimental tools aimed at compressing scientific work that would typically take months or years into days. The effort combines multi-agent research systems, computational discovery tools, literature analysis, and database-connected life science assistants.

Europe weighs technology sovereignty push amid internal debate

Europe is preparing a new policy push to reduce reliance on major technology platforms, but internal disagreements are shaping the scope and pace of the effort. The Artificial Intelligence Development Act is due to be unveiled on June 3 after repeated delays.

Contact Us

Got questions? Use the form to contact us.

Contact Form

Clicking next sends a verification code to your email. After verifying, you can enter your message.