Site icon eDiscovery Today by Doug Austin

5 Ways Hackers Will Use ChatGPT for Cyberattacks: Cybersecurity Trends

5 Ways Hackers

Found this terrific article on ChatGPT and cyber to share and the title says it all: 5 Ways Hackers Will Use ChatGPT for Cyberattacks!

The article, from Dotan Nahum at Information Security Buzz, discusses (wait for it!) 5 ways hackers will use ChatGPT for cyberattacks. Here are the 5 ways he identified:

Malware Obfuscation: Threat actors use obfuscation techniques to evolve malware signatures that bypass traditional signature-based security controls. Each time researchers at CyberArk interacted with ChatGPT, a distinct code was provided, capable of generating various iterations of the identical malware application. Therefore, hackers could use ChatGPT to generate a virtually infinite number of malware variants that would be difficult for traditional signature-based security controls to detect.

Advertisement

Phishing and Social Engineering: Phishing attempts were often easy to spot in the past due to poor grammatical and spelling errors. However, with ChatGPT, cybercriminals can create convincing and accurate phishing messages that are almost indistinguishable from legitimate ones, making it easier to trick unsuspecting individuals.

Ransomware and Financial Fraud: With its ability to generate human-like responses and understand natural language, hackers can use ChatGPT to craft spear-phishing emails that are more convincing and tailored to their targets, increasing the chances of success. For example, it can facilitate fraudulent investment opportunities and CEO fraud. Hackers can use it to generate fake investment pitches or emails impersonating CEOs or other high-level executives, tricking unsuspecting victims into sending money or sensitive information.

Telegram OpenAI Bot: Telegram OpenAI bot as a service has been a subject of interest for developers and hackers alike. Recently, Check Point Research discovered that hackers had found a way to bypass restrictions and are using it to sell illicit services in underground crime forums. The hackers’ technique involves using the application programming interface (API) for OpenAI’s text-DaVinci-003 model instead of the ChatGPT variant of the GPT-3 models designed explicitly for chatbot applications. The API versions do not enforce restrictions on malicious content. As a result, the hackers have found that they can use the current version of OpenAI’s API to create malicious content, such as phishing emails and malware code, without the barriers OpenAI has set.

Spreading Misinformation: The recent discovery of a fake ChatGPT Chrome browser extension that hijacks Facebook accounts and creates rogue admin accounts is just one example of how cybercriminals exploit the popularity of OpenAI’s ChatGPT to distribute malware and spread misinformation.

Advertisement

There’s a lot more to the article than just this brief summary of 5 ways hackers will use ChatGPT for cyberattacks, so check it out via the link above!

So, what do you think? Is the net impact of ChatGPT positive or negative when it comes to cyber risk for organizations? Please share any comments you might have or if you’d like to know more about a particular topic.

Disclaimer: The views represented herein are exclusively the views of the author, and do not necessarily represent the views held by my employer, my partners or my clients. eDiscovery Today is made available solely for educational purposes to provide general information about general eDiscovery principles and not to provide specific legal advice applicable to any particular circumstance. eDiscovery Today should not be used as a substitute for competent legal advice from a lawyer you have retained and who has agreed to represent you.

Exit mobile version