Mahvash Ikram
A technology expert is warning internet users about a new artificial intelligence tool launched on the dark web which is designed to defraud consumers, spread misinformation and run interference in war zones.
The release of Dark GPT comes as 63 million passwords were recently leaked on the dark web.
Describing the tool as “terrifying and sinister”, Lloyd Gallagher, managing partner of Gallagher & Co Consultants and convenor of The Law Association’s Technology & Law Committee, says it uses “standard scraping technology” to obtain information and then creates fraudulent websites that look legitimate.
“They will then send those links out via e-mail or text and people are clicking on them, thinking it’s the real thing.”
Gallagher said information about Dark GPT is still coming to light but his preliminary investigation indicates the threat is significant. It was also concerning that the tool had been released amid an unprecedent rise in cyberattacks in the wake of the unrest between Iran and the US.
“It is currently being used to manipulate and influence the attacking regime that has seen military as well as non-military sites in the US being taken down or information being misused or controlled and leaked further into the dark web.”
This had led to the development of another branch of the tool, coded to “disrupt, interrupt and deliberately hack or break security systems”. While cybersecurity is on its tail, companies that had been breached were lagging behind in mitigating the risk, Gallagher said.
“We’ve seen attacks against law firms, against major corporations. We’ve seen Microsoft fall over. I’ve seen Google fall over. At the moment, there are significant concerns over the Chrome browser, with significant attacks going on, both in the front end and back end of that browser.”
Internet users needed to be wary of any links sent via text or e-mail. “Don’t click on them. Type them in manually and be cautious when using any of your browsers or password protectors within browsers.”
Gallagher said he’s been “freaking out” about the security threat Dark GPT poses. Currently, there is no way of finding or prosecuting the offenders. “There’s not any knowledge as to who’s hosting the damn thing,” he said. But the nature and quantity of misinformation being distributed meant nothing on the web could be trusted any more.
He added that New Zealand was already lagging in legislation to address the rise of artificial intelligence. There were significant dangers with the “wait and see” approach, he said.
AI technologies are believed to have first been used by cyber criminals and hackers in 2023 – just months after Chat GPT was launched. And the launch of Dark GPT follows similar AI tools that are used for cybercrime activities, such as Ghost GPT, Worm GPT and Fraud GPT.
According to the South China Morning Post, an employee at a Hong Kong multinational was scammed out of NZ$47 million last year by an attacker posing as the company’s chief financial officer on an AI-generated deepfake conference call.
The rise of AI-powered attacks means organisations and individuals must develop strategies to counter the threat, Gallagher said. The first step is to stop saving passwords in a browser.
“I know a lot of people still use Google as a password save. It’s something that I’ve frowned on for a very long time and I still frown on. With the recent breach that’s happened, most of the people who have had passwords saved in the browsers have now lost those passwords to the dark web and they’re being advised to change them.”
He says people should use Multi-Factor Authentication (MFA) as a minimum.

0 Comments