Case Library / Agentic AI Attacks (AI-Powered Social Engineering) / FraudGPT Underground Chatbot

FraudGPT Underground Chatbot

A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures, but when Cisco Talos tried to buy access, operator "CanadianKingpin12" supplied dead credentials and then demanded crypto for a "crack," revealing it as a scam with no working AI product behind the marketing.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In mid-2023, an actor using the alias "CanadianKingpin12" advertised "FraudGPT," billed as an unrestricted, ChatGPT-like AI chatbot for cybercriminals, on multiple dark-web marketplaces (Empire, WHM, Torrez, World, AlphaBay, Versus) and, after forum threads were repeatedly taken down, primarily via a Telegram channel created 2023-06-23. Netenrich's threat research team documented the listings publicly on 2023-07-25, noting the tool had circulated on Telegram since 2023-07-22, and described FraudGPT as marketed for writing spear-phishing/BEC emails, malicious code, "undetectable" malware, phishing pages and panels, scam letters, and for locating non-VBV bins, cardable sites, leaks and vulnerabilities, with 24/7 escrow support. Subscriptions were priced at $200/month or $1,700/year, and the actor claimed over 3,000 confirmed sales. Netenrich explicitly framed FraudGPT as similar in kind to WormGPT (reported by SlashNext on 2023-07-13), and traced the operator to the email canadiankingpin12@gmail.com. SlashNext separately engaged the actor undercover and reported claims of two additional in-development bots, "DarkBART" and "DarkBERT," with internet access and image capabilities. Neither Netenrich nor SlashNext reported any confirmed real-world attack tied to FraudGPT-generated content at the time. The story took a significant turn in 2025, when Cisco Talos published research describing its own attempt to purchase FraudGPT access: after extended negotiation with CanadianKingpin12 on Telegram, Talos received a username and password that did not work, and the actor then demanded cryptocurrency for a "crack" to the login page, a pattern Talos assessed, and multiple other scammed buyers corroborated, as proof the actor had no working AI product at all and was running an advance-fee cryptocurrency scam under the FraudGPT brand.

How the Attack Worked

CanadianKingpin12 first tried to sell FraudGPT on lower-level clearnet cybercrime forums; threads were repeatedly removed, so the actor pivoted to a Telegram channel (created 2023-06-23) to distribute more resiliently, avoiding the exit-scam risk of dark-web markets like Empire, WHM, Torrez, World, AlphaBay and Versus where the actor claimed "verified vendor" status. The Telegram/dark-web listings advertised a ChatGPT-style interface with no ethical guardrails, promoted with a features list (malicious code, undetectable malware, phishing pages/panels, scam letters, non-VBV bin lookup, cardable-site discovery, vulnerability/leak search, page hosting, code obfuscation, OTP-spoofing bots, CVV checking, and 24/7 escrow) and a claim of 3,000+ prior sales. Netenrich's threat research team discovered and documented the listings on 2023-07-25, tracing the operator to the email canadiankingpin12@gmail.com. In 2025, Cisco Talos independently engaged CanadianKingpin12 on Telegram posing as a buyer; after prolonged negotiation the actor supplied a username/password for the FraudGPT site that did not work, then demanded cryptocurrency to purchase a "crack" for the login page, behavior Talos assessed, and other scammed buyers corroborated, as evidence the actor had no working AI product and was running a straightforward advance-fee/crypto scam under the FraudGPT brand.

The Lure & the Tell

Lure (to prospective cybercriminal buyers): a slick "exclusive bot" pitch positioning FraudGPT as a ChatGPT alternative "with no boundaries," backed by a long feature list and a claimed track record of 3,000+ sales/reviews: social proof and scarcity framing (limited licenses, per-month virtual-machine/page-hosting caps) designed to create urgency and legitimacy for buyers on cybercrime forums. Tell/giveaway: when Cisco Talos actually attempted to purchase access, the promised login credentials simply did not work, and the actor pivoted immediately to demanding a further cryptocurrency payment for an unexplained "crack," a classic advance-fee-fraud pattern (moving the goalposts after initial payment) that other buyers on the same forums independently reported experiencing.

Outcome

Netenrich's 2023-07-25 report made FraudGPT one of the most widely cited examples (alongside WormGPT) of the "malicious LLM-as-a-service" trend, driving broad vendor and media coverage (SC Media, SecureWorld, Security Boulevard, Varonis, etc.) through mid-to-late 2023, and prompted general law-enforcement commentary: FBI Director Christopher Wray publicly warned on 2023-07-26 that criminals were exploiting generative AI for malware and spearphishing, without naming FraudGPT specifically. Netenrich stated as of its report date it knew of no confirmed active attacks carried out using FraudGPT-generated content. No public record of a specific victim organization or law-enforcement case tied to FraudGPT-produced phishing was identified. In 2025, Cisco Talos's own attempted purchase established that the offering was very likely a scam targeting cybercriminal buyers rather than a functioning AI weapon, undercutting the tool's own advertised capabilities, though the "FraudGPT" brand persisted in underground and vendor-report circulation into 2026 as a loosely-used label for copycat/rebranded "uncensored AI" offerings.

Why It Matters

FraudGPT is one of the earliest and most-cited "malicious LLM-as-a-service" offerings, widely referenced in threat-intel literature (alongside WormGPT, GhostGPT, DarkGPT, DarkestGPT and others) as evidence that generative AI lowers the technical barrier to phishing and fraud. But the case is equally important as a caution against taking underground-market capability claims at face value: years of follow-on vendor research (Cisco Talos in 2025, echoed by Rapid7's 2026 criminal-AI-market analysis) found no verified working FraudGPT backend, and concluded the operator was very likely running a straightforward scam against fellow criminals rather than operating a functioning offensive AI tool. For an educational audience, the incident illustrates two overlapping social-engineering layers: (1) the advertised threat, AI marketed to make phishing/BEC content more convincing and scalable, and (2) the demonstrated threat, that the "AI cybercrime tool" market itself is rife with advance-fee scams that use the same urgency, social-proof, and authority tactics found in consumer-facing fraud, just aimed at criminal buyers instead. It's a useful corrective against uncritically amplifying vendor claims about "new AI attack tools" without independent verification.

Defenses

Treat "blackhat AI" marketplace claims (FraudGPT, WormGPT, DarkGPT, GhostGPT, etc.) with the same skepticism as any other unverified cybercrime-forum product. Vendor threat intel repeatedly finds these are frequently non-functional or vastly oversold, so downstream defense should focus on the actual delivery mechanism (phishing emails/pages, BEC lures) rather than the AI branding. Standard anti-phishing/anti-BEC controls remain the effective countermeasure regardless of whether AI generated the lure: DMARC/SPF/DKIM enforcement, execution-time link/attachment sandboxing, out-of-band verification for payment/wire-change requests, security awareness training that flags urgency+financial-request combinations, and behavioral/email-gateway detection tuned to the writing-quality and infrastructure patterns of BEC rather than to "AI-generated" as a distinct signature (AI-polished text is often indistinguishable from human-written text). For organizations evaluating cyber-threat-intel vendor claims about new "AI crime tools," corroborate with a second independent source (as Talos/SlashNext/Netenrich did here) before treating capability claims as fact.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Brand and infrastructure setup: Before contacting any buyer, CanadianKingpin12 built a dark-web storefront and marketing materials for FraudGPT, positioning it as an unrestricted, jailbroken-style ChatGPT alternative, and initially posted it on multiple clearnet cybercrime forums before pivoting to a more resilient Telegram channel (created 2023-06-23) once forum threads were repeatedly removed, per SlashNext and Netenrich.
Countering Stage 1: Attacker-controlled marketing infrastructure on dark-web forums and Telegram is largely outside a defender's reach to remove; the realistic control is threat-intelligence monitoring of these channels (as Netenrich and SlashNext did) to get early warning of new 'AI cybercrime tool' claims so downstream anti-phishing controls can be validated rather than the tool itself chased.
2
Fabricated social proof: The actor claimed 'verified vendor' status on several named dark-web marketplaces and an unverified '3,000+ confirmed sales/reviews' track record, manufacturing trust signals for prospective cybercriminal buyers before any transaction took place.
Countering Stage 2: Treat 'verified vendor' badges and bulk sales-count claims on cybercrime forums as unverifiable marketing rather than evidence of legitimacy or capability; require independent corroboration from a second source before treating any such claim as fact.
3
Feature-list lure and pricing pitch: FraudGPT was advertised with a detailed capability list (phishing pages/panels, BEC email drafting, malware generation, CVV/carding tools, 24/7 escrow) at $200/month or $1,700/year, giving prospective buyers a concrete, appealing value proposition to act on.
Countering Stage 3: Evaluate advertised capabilities against actual observed samples or independent testing rather than a feature list, and remember that standard anti-phishing and anti-BEC controls (DMARC/SPF/DKIM, link sandboxing, awareness training) work the same regardless of whether a lure claims AI origin.
4
Direct negotiation with a prospective buyer: The actor engaged interested buyers, including Cisco Talos researchers posing undercover in 2025, one-on-one over Telegram, with prolonged back-and-forth negotiation that built apparent rapport and momentum toward a purchase.
Countering Stage 4: Build a structured verification step, proof of function before payment, into any acquisition process, and treat a seller's urgency or relationship-building pressure as a caution flag rather than a reason to move faster; this applies equally to a legitimate buyer being scammed as it does to phishing targets in general.
5
Partial, non-functioning delivery: After negotiation concluded, the actor supplied a username and password for the FraudGPT site, but per Talos the credentials did not work, creating a plausible-sounding technical snag rather than an outright refusal to deliver.
Countering Stage 5: A broken or non-functioning deliverable that follows a completed negotiation is a hallmark advance-fee-fraud indicator; the practical control is to walk away at this point rather than troubleshoot alongside the seller.
6
Advance-fee escalation: CanadianKingpin12 then asked the buyer to send additional cryptocurrency to purchase a 'crack' to fix the broken login, exploiting the buyer's sunk cost and momentum from the earlier negotiation to extract further payment.
Countering Stage 6: Any request for a further payment to 'unlock,' 'crack,' or 'activate' something already paid for should be treated as a stop signal; legitimate vendors do not require serial follow-up payments to deliver access already sold.
7
Payout and objective completion: Talos and multiple other corroborating victims found that paying this second demand did not yield a working product either, completing an advance-fee cryptocurrency fraud against the tool's own prospective criminal customers rather than delivering any functioning AI capability.
Countering Stage 7: Once cryptocurrency is sent, recovery is rarely practical because the payment is irreversible; the only effective control is preventing the payment at Stages 4 through 6, which is why verification has to happen before funds move, not after.
Quick Facts
Victim
Primary claimed victim class (per the advertised product): general phishing/BEC/carding targets that would be victimized by buyers using FraudGPT-generated content. No specific confirmed victim organization or individual identified in the public record. Secondary, independently documented victims: cybercrime-forum buyers themselves, who Cisco Talos found were defrauded of cryptocurrency by CanadianKingpin12 after being sold access to a product that did not function.
Location
Global, advertised on Telegram and multinational dark-web marketplaces; actor uses a "Canadian" alias but true identity/location unconfirmed
Date
2023-06-23 (Telegram channel created) through 2023-07-22/25 (public circulation and first vendor report); ongoing advertising into later 2023; Cisco Talos published a follow-up confirming the scam finding in 2025-06
Impact
Advertised subscription: $200/month or $1,700/year (per Netenrich's original post); some secondary coverage adds an unverified $1,000/6-month tier. The seller claimed "3,000+ confirmed sales/reviews," an unverified vendor/advertiser claim. No aggregate financial loss to downstream phishing/BEC victims has been publicly documented or attributed specifically to FraudGPT-generated content. Separately, Cisco Talos documented that the actor CanadianKingpin12 defrauded prospective buyers directly: after negotiation, Talos was given non-working login credentials and then asked to pay in cryptocurrency for a "crack" to unlock the site, which Talos and other would-be buyers concluded meant there was no working product at all. No specific dollar figure for buyer losses was disclosed.
Status
Confirmed
Case Type
Real-World Incident
Sector
Cross-Sector / Multiple Industries, Cybersecurity Industry, Technology & Software
Threat Actor
Unaffiliated Individual
Related

Related Cases

Abu Trica AI Romance Scam Network (Kumi & Yussif) - $8M+ Elder Fraud, Northern District of Ohio

Ghanaian social-media personality Frederick Kumi ("Abu Trica") and co-defendant Daniel Yussif were federally indicted for leading a romance-fraud network that…

Incident 2023Read →

WPP Deepfake CEO Scam Attempt

Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…

Incident 2024Read →

UAC-0050 ClickFix Fake-reCAPTCHA Campaign Deploys 'Lucky Volunteer' Infostealer Against Ukrainian Organizations

A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…

Incident 2024Read →