TL;DR: Malicious GPTs such as WormGPT and FraudGPT are lowering the barrier to entry for cybercriminals and helping AI-driven attacks move faster than legacy defenses can comfortably absorb, according to Abnormal AI. The governance issue is not just detection volume, but the way AI compresses attacker skill, speed, and scale into a narrower response window.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Worm, Fraud, Ghost... Oh My: A Deep Dive into Malicious GPTs”.
Key questions
A: Security teams should treat malicious GPTs as an acceleration layer for existing attack techniques, not as a separate threat class.
Q: Why are AI-powered attacks harder for legacy defenses to stop?
A: They change faster than controls built around repeated attacker patterns.
Practitioner guidance
- Map AI-assisted abuse scenarios to your current detection latency Measure how long it takes from first suspicious message or identity event to triage, containment, and user protection.
- Tune controls for content variation and behavioural signals Review whether your email, identity, and user-risk controls rely too heavily on repeated wording, static signatures, or known templates.
- Reduce analyst dependence on repetitive low-value triage Automate first-pass classification and enrichment so staff can focus on cases that show novel identity abuse, suspicious user interaction patterns, or coordinated campaign behaviour.
Bottom line: Malicious GPTs reduce the expertise needed to run cybercrime campaigns, which makes the attacker pool wider and harder to predict.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Malicious GPTs collapse the attacker-skill assumption that many legacy controls still rely on. Security programmes have long assumed that meaningful offensive capability requires time, expertise, and repetition. Tools like WormGPT and FraudGPT erode that assumption by making high-volume abuse accessible to lower-skill operators. The practitioner implication is that defender models built around the expected effort of the attacker are now systematically underestimating abuse risk.
A few things that frame the scale:
- Nearly 60% of companies reported that fraud losses were still increasing in 2025.
A question worth separating out:
Q: When should organisations prioritise behavioural detection over signature-based controls?
A: When attackers can generate large volumes of varied content on demand, behavioural detection becomes more reliable than signatures alone. It is the better choice when the main challenge is rapid iteration rather than a fixed exploit pattern.
👉 Read our full editorial: Malicious gpts are lowering the barrier for cybercriminals