Underground AI Supercharges Phishing Attacks On Employers

Cybersecurity researchers have identified underground AI models that are marketed to cybercriminals on dark web and hacker forums.

These models are described as jailbroken or customized versions of generative AI that remove safety filters and enable users to generate malicious content.

Malicious capabilities include drafting highly convincing phishing emails, writing or modifying malware code, helping identify vulnerabilities, and automating parts of cyberattacks. Tools with names such as WormGPT, FraudGPT, and similar "blackhat" models are promoted as ways to assist even low-skilled attackers with business email compromise and other fraud schemes.

Researchers note that these AI models can help attackers personalize messages, correct spelling and grammar, and adjust content to different languages or targets, increasing the likelihood that phishing messages will be opened and acted upon.

The use of these underground AI tools is viewed as a growing trend that expands the scale and sophistication of phishing and malware campaigns against organizations.

Source: https://cybernews.com/ai-news/hackers-use-underground-ai-models-malware-phishing-attacks/

Commentary

In the above matter, underground AI tools are being used by attackers to generate malware and create highly polished phishing messages, which raises the risk that employees will fall for scams that look authentic and personal. For employers and IT personnel, this development means defenses built around spotting clumsy language or obvious mistakes in emails are no longer sufficient.

AI-generated phishing changes the economics of attacks. Criminals can now produce large volumes of customized, well-written messages, tailored to specific roles, companies, and ongoing projects.

At the same time, these tools can help modify malicious code and obfuscate payloads, making traditional signature-based defenses less reliable. Organizations must assume that some phishing messages will look as professional as internal communications and design controls accordingly.

Employers and IT personnel should consider the following steps to reduce the risk:

  • Update security awareness training to include examples of AI-crafted phishing and deepfake content, emphasizing that flawless grammar is no longer reassuring
  • Run regular phishing simulations that mirror AI-generated attacks, including targeted business email compromise scenarios against executives and finance teams
  • Implement email authentication controls and tune secure email gateways for impersonation and anomaly detection
  • Require out-of-band verification for high-risk requests such as wire transfers, payroll changes, or credential resets, using a second trusted channel
  • Utilize phishing-resistant multi-factor authentication and enforce least-privilege access so that one compromised account cannot unlock the entire environment
  • Monitor for newly-registered or look-alike domains and brand misuse that can be used to support AI-driven phishing campaigns
  • Maintain and test an incident response plan that includes rapid containment of compromised accounts and clear internal reporting channels.

The final takeaway is that underground AI models give attackers professional-grade writing skills and faster malware development. In response, employers should combine stronger technical controls, disciplined identity management, and modernized user training to reduce the risk.



Finally, your opinion is important to us. Please complete the opinion survey:

Product

Articles

Underground AI Supercharges Phishing Attacks On Employers

Security researchers report that cybercriminals are using underground and jailbroken AI models to write sophisticated malware and phishing messages. We comment on how employers can respond.

Timing Mistakes: Termination After Accommodation Requests

A termination's timing brings litigation after a medical facility fires a worker soon after her request for an accommodation. We examine and discuss the termination risks for healthcare employers.

How Should Organizations Respond To "Cyber Responder" Betrayal?

Two American cybersecurity professionals pled guilty to conspiring with the ALPHV/BlackCat ransomware group to attack multiple U.S. organizations they were hired to protect. We comment.

Avoiding ADA Retaliation Traps In Healthcare Leave And Reassignment Decisions

Geisinger Health entities agreed to pay $450,000 and be subject to injunctive relief to resolve an EEOC lawsuit containing allegations of systemic denial of reasonable accommodations and discriminatory return to work practices under the ADA. We comment.

Employee Discounts Leading To Fraud: Lessons For Employers

A former machinist was indicted on federal wire fraud and firearms charges. We comment.