Skip to main content
  1. Home
  2. Computing
  3. News

ChatGPT just created malware, and that’s seriously scary

Add as a preferred source on Google

A self-professed novice has reportedly created a powerful data-mining malware using just ChatGPT prompts, all within a span of a few hours.

Aaron Mulgrew, a Forcepoint security researcher, recently shared how he created zero-day malware exclusively on OpenAI’s generative chatbot. While OpenAI has protections against anyone attempting to ask ChatGPT to write malicious code, Mulgrew found a loophole by prompting the chatbot to create separate lines of the malicious code, function by function.

Recommended Videos

After compiling the individual functions, Mulgrew had created a nigh undetectable data-stealing executable on his hands. And this was not your garden variety malware either — the malware was as sophisticated as any nation-state attacks, able to evade all detection-based vendors.

Just as crucially, how Mulgrew’s malware defers from “regular” nation-state iterations in that it doesn’t require teams of hackers (and a fraction of the time and resources) to build. Mulgrew, who didn’t do any of the coding himself, had the executable ready in just hours as opposed to the weeks usually needed.

The Mulgrew malware (it has a nice ring to it, doesn’t it?) disguises itself as a screensaver app (SCR extension), which then auto-launches on Windows. The software will then sieve through files (such as images, Word docs, and PDFs) for data to steal. The impressive part is the malware (through steganography) will break down the stolen data into smaller pieces and hide them within images on the computer. These images are then uploaded to a Google Drive folder, a procedure that avoids detection.

Equally impressive is that Mulgrew was able to refine and strengthen his code against detection using simple prompts on ChatGPT, really raising the question of how safe ChatGPT is to use. Running early VirusTotal tests had the malware detected by five out of 69 detection products. A later version of his code was subsequently detected by none of the products.

Note that the malware Mulgrew created was a test and is not publicly available. Nonetheless, his research has shown how easily users with little to no advanced coding experience can bypass ChatGPT’s weak protections to easily create dangerous malware without even entering a single line of code.

But here’s the scary part of all this: These kinds of code usually take a larger team weeks to compile. We wouldn’t be surprised if nefarious hackers are already developing similar malware through ChatGPT as we speak.

Aaron Leong
Former Computing Writer
Aaron enjoys all manner of tech - from mobile (phones/smartwear), audio (headphones/earbuds), computing (gaming/Chromebooks)…
AI fitness coach senses the muscle mechanics as you exercise and prevents rookie injuries
Most fitness apps offer encouragement dressed up as coaching, but BioCoach offers anatomy-specific corrections, and I could see it becoming a smartphone app real soon.
Woman exercises with her Apple Watch and Dexcom G7.

During the pandemic, the US Consumer Product Safety Commission recorded a 48% spike in at-home exercise injuries. You might think that the culprit was bad equipment, but it was bad form. People had no coach around to correct it.  

Researchers at Drexel University and Michigan State University have built a prototype that addresses exactly that problem, in real time, using your phone camera, and there’s real potential for it to become a legitimate fitness app in future (via Tech Xplore).

Read more
China is moving beyond super-apps to embrace AI agents that do it all for you
Alibaba’s Qwen and Tencent’s WeChat are racing to make chat the new home for food orders, shopping, travel, and payments.
Electronics, Mobile Phone, Phone

Alibaba wants Qwen to handle the everyday app chores people usually do by tapping through menus, from ordering fried chicken to planning flights.

China’s super-app model has trained users to keep more of their digital lives inside one giant mobile hub. WeChat is the clearest example, with messaging, payments, shopping, food orders, ride-hailing, travel bookings, content, and mini-programs packed into a familiar daily flow.

Read more
You can literally save the planet by being less polite to AI bots like ChatGPT and Gemini
Every "please" you type to ChatGPT is quietly costing the planet.
Image showing a big footprint

Here is something that will make you think twice before typing a long, detailed prompt to ChatGPT or Gemini. Every word you type costs energy, and a lot more than you would think.

A recent report by the United Nations University Institute for Water, Environment and Health paints a pretty alarming picture of AI's environmental footprint. The numbers are staggering and will make you pause next time you want to make a request to your favorite AI chatbot. 

Read more