Archive for July 15, 2023

WormGPT: It Spits Out Convincing BEC Emails

Posted in Commentary with tags on July 15, 2023 by itnerd

A recent article published by SC Magazine reported that cybercriminals have developed a generative AI tool called WormGPT which is designed to help grammatically challenged criminals craft convincing business email compromise (BEC) emails.

WormGPT promoters claim their product has zero ethical constraints and can spit out AI-created BEC content for urgently soliciting funds from targeted victims and also whip up customizable malware code, which makes it extremely nefarious.

Dan Shiebler, Head of Machine Learning at Abnormal Security had this comment:

“The most common Generative AI tools like ChatGPT, Google Bard, and Claude have explicit checks built in to prevent abuse and malicious use by threat actors. These checks cannot be avoided, because the tools work by sending users’ prompts to OpenAI (for ChatGPT), Google (for Bard) and Anthropic (for Claude), who then run the prompts through a series of checks in their models, before sending the output back to the user. Attackers can trick these checks, but it’s fairly difficult to do.Tools like WormGPT, on the other hand, use open source models like LLAMA and GPTJ. Users run these models by downloading them to their own computers, which allows them to remove the check process entirely – they don’t need to be particularly savvy or do any work to trick the checks, like they would with a tool like ChatGPT. This means there are no limits on the kind of content it could produce.GPTJ, which is what WormGPT is built on, has been around since 2021, so cybercriminals have likely already been using it for years.”

One of the ways that I teach people to spot BEC or phishing emails is to look out for the grammar. Or lack of it more precisely. With a tool like this, spotting BEC or phishing emails is going to get far harder. Which means that the success of these emails will go up which is bad for all of us.

Ransomware Costs Of $32.3 Billion Spread Over Just 225 Organizations 

Posted in Commentary with tags on July 15, 2023 by itnerd

In a study of 225 global financial services organizations, researchers with Comparitech found that ransomware attacks cost them in excess of $32.3 billion in downtime alone, over the past five years. Comparitech head of data research, Rebecca Moody explained that researchers used a 2017 study to calculate downtime costs of $8,662 per minute, noting however an ITIC 2017 study put estimated that figure in the millions per minute for the banking sector which would raise the estimate to over $581 billion.

  • 225 confirmed ransomware attacks on financial organizations
  • Ransom demands varied from $180,000 to $40 million w/ an average demand of $6.9 million
  • Over 32.3 million individual records were breached
  • Downtime varied from one day to 52 days – average downtime 10 to 14 days
  • Insurance companies saw the highest number of attacks (65)

“If no specific figures were given for downtime, i.e. ‘several days,’ ‘one month’ or ‘back to 80% after 6 weeks’ were quoted, we created estimates from these figures based on the lowest figure they could be,” explained Moody.

Morten Gammelgard, EMEA, co-founder, BullWall had this comment:  

“It’s never just the amount of the ransom, but the overall cost of downtime and reputational loss that make ransomware so costly. Forewarned is forearmed and the expense of maintaining a solid cyber defense pales in comparison to the after-action cost of the entire event, whether the ransom is paid or not.  

“Data loss is one of the worst consequences of Ransomware and it is rare that companies are able to restore 100% of the data encrypted. This can lead to serious problems for businesses, such as the loss of customer data or confidential company information.”

The bottom line is that Ransomware is expensive. And the best way to not have to bear that expense is to pay whatever you have to to make sure that you have defences that mitigate the possibility that you will be the victim of ransomware.