ChatGPT is being used to create malware — what you need to know

A hacker typing quickly on a keyboard
(Image credit: Shutterstock)

As ChatGPT, Bing Chat and Google Bard continue to take the world by storm, cybersecurity experts have voiced their concerns about potential threats posed by  AI

And it appears these concerns are increasingly valid as malware has already been created using ChatGPT. As reported by Infosecurity, WithSecure CEO Juhani Hintikka has confirmed to the news outlet that malware samples generated by ChatGPT have been spotted in the wild.

Just as ChatGPT can provide different answers to the same question, it can also generate variations on a piece of code. Apparently, this is what the hackers abusing the AI chatbot did to create malware.

By feeding ChatGPT existing malware samples, hackers can have it create new malware strains that are polymorphic. As WithSecure’s head of threat analysis Tim West pointed out to Infosecurity, this will make it particularly challenging to defend against these new threats.

While we now know that ChatGPT has been used to create malware, we don’t know much else on the matter yet, including how dangerous this malware is and whether or not it’s currently being used in cyberattacks.

Just another tool in a hacker’s toolbox

In order to bypass the defenses of Google, Microsoft and other tech giants, hackers often find clever ways to abuse legitimate tools. For instance, remote access tools are frequently used by hackers in their attacks, and it now appears like they too have jumped on the AI bandwagon. 

As Hintikka points out, AI has traditionally been used by antivirus companies and other defenders to fend off cyberattacks. However, this appears to be changing as cybercriminals now have more resources at their disposal.

Besides answering your most pressing questions, ChatGPT can be used for coding. In fact, the chatbot can write code for you which “lowers the barrier for entry for the threat actors to develop malware,” according to West. While hackers can currently buy pre-built and custom malware on the dark web, generative AI provides them with the tools they need to cut out the middleman and create new malware on their own.

At the same time, hackers are already using AI to craft their phishing emails. So far, humans have been able to identify these AI-crafted phishing attempts but as AI becomes more advanced, Hintikka warns that it will be much harder to identify what is suspicious and what isn’t going forward.

How to stay safe from malware

Best antivirus software

(Image credit: Shutterstock)

Malware created by AI is going to completely change the threat landscape but there are still several steps you can take to protect yourself.

First and foremost, you'll want to make sure that all of your devices are up to date with the latest software and security patches installed. This way, you can better protect both your devices and your data from falling into the hands of hackers.

Windows PCs and Macs both come with their own built-in malware protection in the form of Windows Defender and XProtect, respectively. However, for additional protection, you should consider installing one of the best antivirus software solutions on your PC, the best Mac antivirus software on your Mac and one of the best Android antivirus apps on your Android smartphone. If you need a more all-encompassing solution, the best internet security suites often throw in a VPN and a password manager in addition to malware protection.

Now that the cat is out of the bag when it comes to generative AI and AI chatbots, expect to hear similar stories about hackers abusing these types of services to create malware. Fortunately though, cybersecurity firms are likely already a step ahead as they’ve been using AI in their antivirus engines to detect new types of malware for years now.

More from Tom's Guide

TOPICS
Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
ChatGPT logo on a smart phone resting on a laptop keyboard, lit with a dark purple light
OpenAI has been actively banning users if they’re suspected of malicious activities
An image of a CAPTCHA
Hackers are using reCAPTCHA to trick users into infecting their own PCs with malware — how to stay safe
DeepSeek logo on phone
Is DeepSeek a national security threat? I asked ChatGPT, Gemini, Perplexity and DeepSeek itself
ChatGPT on iPhone
ChatGPT went down — full timeline as major outage hit users worldwide
ChatGPT on iPhone
ChatGPT was down — updates on quick outage
ChatGPT on phone with Google logo in background
New study reveals people are ditching Google for AI tools like ChatGPT search — here's why
Latest in ChatGPT
ChatGPT on iPhone
ChatGPT was down — updates on quick outage
ChatGPT app on iPhone
I just tested ChatGPT-4.5 with 5 prompts — the good, the bad and the weird
ChatGPT app icon on mobile device
ChatGPT 4.5 — 5 big upgrades you need to know
OpenAI logo
OpenAI ChatGPT-4.5 is here and it's the most human-like chatbot yet — here's how to try it
ChatGPT app icon on mobile device
ChatGPT Plus just got a huge deep research upgrade — here's how to try it now
A person logging into LinkedIn on their phone and laptop
Looking for a job? — 7 prompts to use ChatGPT o3-mini as a job search assistant
Latest in News
Apple Watch Ultra 2
Apple Watch Ultra 3 just tipped for two major upgrades
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
Titus Welliver in Bosch Legacy season 3
‘Bosch’ season 3 preview: 5 things to know before the final season on Prime Video
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options