‘DarkBERT’ GPT-Based Malware Trains Up on the Entire Dark Web

Share:

The DarkBART and DarkBERT cybercriminal chatbots, based on Google Bard, represent a major leap ahead for adversarial AI, including Google Lens integration for images and instant access to the whole of the cyber-underground knowledge base.

The developer behind the FraudGPT malicious chatbot is readying even more sophisticated adversarial tools based on generative AI and Google’s Bard technology — one of which will leverage a large language model (LLM) that uses as its knowledge base the entirety of the Dark Web itself.

An ethical hacker who already had discovered another AI-based hacker tool, WormGPT, tipped off the researchers that the FraudGPT inventor — known on hacker forums as “CanadianKingpin12” — has more AI-based malicious chatbots in the works, according to SlashNext.

The forthcoming bots — dubbed DarkBART and DarkBERT — will arm threat actors with ChatGPT-like AI capabilities that go much further than existing cybercriminal genAI offerings, according to SlashNext. In a blog post published Aug. 1, the firm warned that the AIs will potentially lower the barrier of entry for would-be cybercriminals to develop sophisticated business email compromise (BEC) phishing campaigns, find and exploit zero-day vulnerabilities, probe for critical infrastructure weaknesses, create and distribute malware, and much more.

“The rapid progression from WormGPT to FraudGPT and now ‘DarkBERT’ in under a month underscores the significant influence of malicious AI on the cybersecurity and cybercrime landscape,” SlashNext researcher Daniel Kelley wrote in the post..

DarkBART & DarkBERT: A New AI Generation

In terms of functionality, DarkBART will be a dark version of the Google BART AI, and the hackers said it will be based on a large language model (LLM) known as DarkBERT, which was created by South Korean data-intelligence firm S2W with the goal of actually fighting cybercrime. It’s currently limited to academic researchers, which would make malicious access to it notable.

“The threat actor … claims to have gained access to DarkBERT,” Kelley said, adding that when contacted via Telegram, CanadianKingpin12 shared a video demonstrating that his version of DarkBERT “underwent specialized training on a vast corpus of text from the Dark Web,” Kelley wrote.

The malicious developer also claims his new bot … can be integrated with Google Lens,” Kelley added. “This integration enables the ability to send text accompanied by images.” That’s notable given that so far, ChatGPT-like offerings have been text-only.

The second adversarial tool, confusingly also named DarkBERT (but wholly separate from the Korean AI), will go even further by using the entire Dark Web as its LLM, giving threat actors access to the hive mind of the hacker underground for carrying out cyber threats. It will also have Google Lens integration, CanadianKingpin12 claims.

Rapidly Evolving Dark Web Generative AI

Kelley noted that the developers of adversarial AI tools, like their more benevolent counterparts, likely will soon offer application programming interface (API) access to the chatbots, which will allow for more seamless integration into cybercriminals’ workflows and code and lower the barriers to entry for the cybercrime game.

“Such progress raises significant concerns about potential consequences, as the use cases for this type of technology will likely become increasingly intricate,” Kelley wrote.

This rapid progression also means that defense against the threats will require a proactive approach. In addition to typical training provided to enterprise employees to identify phishing attacks, organizations also should provide BEC-specific training to educate employees on the nature of these attacks and the role of AI, the researchers said. Moreover, enterprises also should enhance email verification measures to combat AI-driven threats, adding strict process and keyword-flagging to measures already in place.

“As cyber threats evolve, cybersecurity strategies must continually adapt to counter emerging threats,” Kelley wrote. “A proactive and educated approach will be our most potent weapon against AI-driven cybercrime.”

 

(c) Dark Reading

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:11 pm, May 31, 2025
weather icon 19°C
L: 18° | H: 20°
overcast clouds
Humidity: 75 %
Pressure: 1014 mb
Wind: 9 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 99%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:49 am
Sunset: 9:06 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
18° | 20°°C 0.2 mm 20% 15 mph 82 % 1015 mb 0 mm/h
Mon Jun 02 10:00 pm
weather icon
11° | 21°°C 0 mm 0% 12 mph 82 % 1019 mb 0 mm/h
Tue Jun 03 10:00 pm
weather icon
11° | 18°°C 1 mm 100% 15 mph 93 % 1013 mb 0 mm/h
Wed Jun 04 10:00 pm
weather icon
9° | 18°°C 0.48 mm 48% 12 mph 81 % 1011 mb 0 mm/h
Thu Jun 05 10:00 pm
weather icon
11° | 15°°C 1 mm 100% 16 mph 94 % 1011 mb 0 mm/h
Tomorrow 1:00 am
weather icon
15° | 18°°C 0 mm 0% 8 mph 76 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
13° | 15°°C 0 mm 0% 8 mph 82 % 1015 mb 0 mm/h
Tomorrow 7:00 am
weather icon
13° | 13°°C 0 mm 0% 10 mph 75 % 1015 mb 0 mm/h
Tomorrow 10:00 am
weather icon
17° | 17°°C 0 mm 0% 11 mph 45 % 1015 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
20° | 20°°C 0 mm 0% 12 mph 37 % 1014 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
20° | 20°°C 0 mm 0% 15 mph 39 % 1013 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
18° | 18°°C 0.2 mm 20% 11 mph 57 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 15°°C 0 mm 0% 8 mph 72 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,377.75
0.13%
Ethereum(ETH)
€2,242.07
-1.37%
Tether(USDT)
€0.88
0.02%
XRP(XRP)
€1.94
0.19%
Solana(SOL)
€138.80
-1.70%
USDC(USDC)
€0.88
-0.01%
Dogecoin(DOGE)
€0.171447
-2.63%
Shiba Inu(SHIB)
€0.000011
-2.02%
Pepe(PEPE)
€0.000011
-7.84%
Peanut the Squirrel(PNUT)
€0.231575
-0.92%
Scroll to Top