Security researcher creates advanced malware with ChatGPT

April 13, 2023

A security researcher, Aaron Mulgrew has designed a highly sophisticated virus using ChatGPT.

Initially, the program was meant to prevent harmful usage by incorporating safeguards that prohibit the tool from writing code for the production of dangerous software. The researcher, however, was able to circumvent these precautions by instructing ChatGPT to generate malware function by function using simple commands.

This particular malware is a sophisticated data-stealing application that may go unnoticed on computers. It is the sort of zero-day assault used by nation-states in sophisticated attacks. The researcher used ChatGPT to accomplish this in a matter of hours, whereas it would take a team of hackers many weeks to construct such malware.

To escape detection, the virus enters a computer via a screen saver program and auto-executes after a brief pause. The virus then scans the target system for photos, PDFs, and Word documents, dividing them into smaller bits and disguising the data in the images using steganography. Finally, the photos containing the data fragments are transferred to a Google Drive folder, which likewise prevents discovery.

In a VirusTotal test, just five out of 69 antivirus software recognized the original version of the ChatGPT malware. However, the researcher was able to remove them all in a later edition. Only three antivirus programs detected the final “commercial” version, which operated from penetration through exfiltration.

The findings were obtained without the use of any code and just via the use of ChatGPT prompts. A team of five to ten malware developers, according to Mulgrew, would need many weeks to create an analogous assault without AI-based Chatbot support.

While Mulgrew’s malware is not expected to be released, the incident raises concerns about the potential misuse of ChatGPT by cybercriminals to create advanced malware attacks. This could result in significant damage to individuals, businesses, and even nation-states.

The sources for this piece include an article in BGR.

Top Stories

Related Articles

February 15, 2026 Ghost tapping scams are emerging as a new threat as tap-to-pay technology becomes more widespread. Unlike traditional more...

February 13, 2026 Cybersecurity researchers have uncovered a malicious Google Chrome extension designed to steal sensitive data from Meta Business more...

February 5, 2026 A security researcher at Koi named Oren Yomtov has uncovered a widespread malware operation embedded inside an more...

February 4, 2026 More than three million Fortinet devices have been exposed to a critical authentication-bypass vulnerability that is being more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn