AI’s potential threat to humanity often makes top headlines, but is it’s threat to cyber being overblown by sensationalist reports?
SecureWork‘s 2023 State of the Threat report revealed some interesting trends concerning the pernicious nature of cybercriminals and new avenues of exploitation, as well as vulnerability mitigation.
While the news has often focused on the use of AI and its potential to improve the scope, scale, and effectiveness of threat actors, SecureWork’s analysis found that most uses of AI in the cyber threat landscape appear to be rather elementary.
So is the AI-hype something cybersecurity experts really need to be concerned about?
Afterall, Gartner did place generative AI at the apex of its “peak of inflated expectations” hype cycle, staring down the sharp descent to the “trough of disillusion.”
According to SecureWork’s report, the most common use of ChatGPT, the most prolific publicly available AI chatbot, has been as lures in phishing emails or malicious sites.
These sites typically used typos to impersonate ChatGPT and trick users into following malicious links.
SecureWorks also found that while threat actors are leveraging ChatGPT to create malware to evade defences and generate malicious code, they company says that these are not quite as threatening as they sound.
These models are based on user inputs on statistical analysis of existing texts, and “do not currently demonstrate the creativity and ingenuity of human coders when finding novel ways to circumvent security controls and discover new vulnerabilities,” the report said.
Threat actors are also selling access to Telegram bots that are based on AI models, which can allow users to request malicious scripts or phishing emails, and even find illegal goods on the dark web.
These bots may expand the amount of threat actors who can bypass ChatGPT’s ethical guardrails, despite a minimal skill set.
WormGPT is an alarming advent of AI, essentially offering the same service at ChatGPT but without legal or ethical restructures. Threat actors with low skillsets can use this service to draft malicious code or access dark web materials.
While SecureWorks says this has yet to make a significant impact in the cybersphere, the rate of AI’s development could change things.
Recommended reading
- AI: Cyber-friend or Cyber-foe?
- Top Cyber Threat Detections of 2023 Driven by AI Advancements
- Hackers: AI Unlikely to Replace Human Cybersecurity Skills
Sub-forums focusing on AI and machine learning (ML) on popular hacking and threat actor forums have begun to arise, meaning new developments could be well on their way.
By mid-2023, however, the main uses of AI in terms of cyber were still on phishing and Telegram bots, according to SecureWork’s report.
But perhaps the main concern with the rise of AI is how it makes malicious methods more accessible to less highly skilled threat actors.
Further, AI is beginning to outsmart humans and AI, with recent studies showing that AI bots are unable to identify AI-generated phishing emails as malicious.





