WormGPT 4
WormGPT 4 is a malicious large language model (LLM) marketed for cybercrime and described by Palo Alto Networks Unit 42 as an unrestricted or “dark LLM.” It is presented as a successor to the original WormGPT that emerged in 2023 and advertises itself as “your key to an AI without boundaries.” According to the reporting, WormGPT 4 began being advertised around September 27 on Telegram and underground forums including DarknetArmy, with subscription pricing of $50 per month or $220 for lifetime access with source code.
High-confidence reporting states that threat actors use WormGPT 4 to generate convincing phishing lures and ransomware code, lowering the barrier to entry for cybercriminal operations and enabling AI-assisted malware development without normal safety restrictions. Unit 42 tested the tool and found it could generate Windows ransomware in PowerShell that encrypted PDF files, dropped a ransom note with a 72-hour payment deadline, used AES-256 encryption, allowed configurable targeting such as file extension and search path with defaults covering the C:\ drive, and included an option for Tor-based data exfiltration. Researchers assessed that the generated output could potentially be used in real-world attacks, but still required human modification to evade traditional security protections.
The content associates WormGPT 4 with phishing and ransomware use cases rather than a specific intrusion set, and describes it as being actively used in the threat landscape by attackers. Targeting is broad and opportunistic based on the described capabilities, with specific tested support for Windows hosts. No concrete file hashes, domains, or other traditional indicators of compromise are provided in the source content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
Initial Access
2 techniques
Initial Access
Execution
1 technique
Execution
Exfiltration
3 techniques
Exfiltration
Sellers tout benefits such as functional ransomware code with AES-256 encryption and Tor-based exfiltration within 30 seconds... WormGPT 4 instantly generated a functional PowerShell script for PDF encryption with AES-256... plus optional Tor-based data exfiltration.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WormGPT 4 is a large language model released by threat actors to enable the creation of AI-powered malware, bypassing ethical safeguards.
Malicious AI language model used to generate convincing phishing lures and ransomware code, lowering the barrier for cybercriminals to launch sophisticated attacks.
Unrestricted/malicious LLM referenced as being used by attackers to support cybercrime workflows (e.g., content generation and operational assistance).
A guardrail-less commercial malicious LLM marketed for cybercrime use. The content says it can generate phishing messages, code snippets, ransomware code, and scripts with options such as data exfiltration via Tor.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.