Researchers: cybercriminals have started using ChatGPT to create hacking tools and AI-generated malware code, and are testing the tool for dating scam chatbots
some with little or no coding experience—were using it to write software and emails that could be used for espionage, ransomware, malicious spam, and other malicious tasks.” https://research.checkpoint.com/ ... Aaron Levie / @levie : Tech has always been about increasing abundance: information, productivity, entertainment, communication, commerce, and more. The big potential of AI is it's a turbocharger of abundance by eventually lowering the cost and increasing the speed of everything. Julian / @julianmoncadany : @mhdempsey I think they could contribute to solving a bunch of problems like Google presumably does, but delivering products might be tough given the specialization required to navigate regulation and the time / investment it takes to produce them Julian / @julianmoncadany : @mhdempsey in a vacuum meta has the cash to do this sure, but would they really want to do this while they could be spending the money and shareholder goodwill on even more ambitious metaverse projects instead? idk Thomas Brewster / @iblametom : How long until we see sextortion scams powered by ChatGPT? Given the rise in teenage boy deaths in the last year as a result of financially-motivated sextortion, this should be a real concern. https://twitter.com/... Kyle Russell / @kylebrussell : heading to an Elon/Zuck reputation flippening https://twitter.com/... Taylor Berg / @taylorannberg : sarcasm: nobody expected this, wow what a shock https://twitter.com/... Thomas Brewster / @iblametom : NEW - Cybercriminals are finally catching onto ChatGPT. They're having the viral AI chatbot build fake female bots for dating scams. And, of course, they're building malware and file encryption (possibly for future ransomware). https://www.forbes.com/...
Context & Ripple Effects
This report lands weeks after ChatGPT's public launch and extends an existing pattern: researchers had already documented cybercriminals running malware operations through automation features inside Discord and Telegram. What changes here is the actor profile — people with little or no coding experience can now generate working exploit code, ransomware components, phishing emails, and convincing fake female personas for dating scams from a consumer chatbot.
First-order effects
- The technical barrier to entry for espionage tooling, ransomware, and malicious spam collapses for low-skill actors, expanding the pool of capable attackers beyond traditional developer-criminals.
- OpenAI inherits an immediate abuse-monitoring problem: its product is being tested both as a malware code generator and as a scripted romance-scam chatbot engine.
Second-order effects
- Once mainstream models tighten restrictions, demand migrates to purpose-built underground alternatives — a trajectory that materialized within months in the WormGPT, FraudGPT, and DarkBERT ecosystem of chatbots explicitly trained for phishing and malware.
- Law enforcement and regulators formalize the threat: Europol follows with a detailed assessment of how LLMs fuel fraud, cybercrime, and terrorism, citing already-occurring illegal use of ChatGPT.
Third-order effects
- Abuse monitoring becomes a core lab function rather than a trust-and-safety afterthought — by 2025 Anthropic is publishing threat intelligence reports on Claude being weaponized for extortion schemes, institutionalizing what this early research exposed.
- The malware economy restructures around AI-generated code supply, pushing defenders to shift detection from signature-based identification of known binaries toward identifying machine-authored attack patterns.
The trend: Generative AI misuse is evolving from ad hoc experimentation on consumer chatbots into a dedicated criminal tooling ecosystem, forcing model developers to stand up threat intelligence as a permanent operational discipline.