logo

The Dual-Use Dilemma of AI: Malicious LLMs

ID: 59c8efb6-8959-5cdc-98ed-8361f047fc57

STIX ID: report--59c8efb6-8959-5cdc-98ed-8361f047fc57

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2025-11-25

Date Updated: 2026-04-28

Author: Unit 42

...
...

This Unit 42 report analyzes two malicious LLMs—WormGPT 4 (commercial/subscription) and KawaiiGPT (free/open-source)—showing they intentionally remove safety controls to produce high-quality phishing/BEC content, ready-to-run ransomware PowerShell scripts, data-exfiltration and lateral-movement code, and ransom notes; the models are distributed via Telegram, underground forums and GitHub, dramatically lowering the skill and cost barriers for cybercriminals and accelerating the scale and speed of attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.