A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.
Social Engineering Examples·6 sources
In mid-2023, an actor using the alias "CanadianKingpin12" advertised "FraudGPT," billed as an unrestricted, ChatGPT-like AI chatbot for cybercriminals, on multiple dark-web marketplaces (Empire, WHM, Torrez, World, AlphaBay, Versus) and, after forum threads were repeatedly taken down, primarily via a Telegram channel created 2023-06-23. Netenrich's threat research team documented the listings publicly on 2023-07-25, noting the tool had circulated on Telegram since 2023-07-22, and described FraudGPT as marketed for writing spear-phishing/BEC emails, malicious code, "undetectable" malware, phishing pages and panels, scam letters, and for locating non-VBV bins, cardable sites, leaks and vulnerabilities, with 24/7 escrow support.
Subscriptions were priced at $200/month or $1,700/year, and the actor claimed over 3,000 confirmed sales. Netenrich explicitly framed FraudGPT as similar in kind to WormGPT (reported by SlashNext on 2023-07-13), and traced the operator to the email canadiankingpin12@gmail.com. SlashNext separately engaged the actor undercover and reported claims of two additional in-development bots, "DarkBART" and "DarkBERT," with internet access and image capabilities.
Neither Netenrich nor SlashNext reported any confirmed real-world attack tied to FraudGPT-generated content at the time. The story took a significant turn in 2025, when Cisco Talos published research describing its own attempt to purchase FraudGPT access: after extended negotiation with CanadianKingpin12 on Telegram, Talos received a username and password that did not work, and the actor then demanded cryptocurrency for a "crack" to the login page, a pattern Talos assessed, and multiple other scammed buyers corroborated, as proof the actor had no working AI product at all and was running an advance-fee cryptocurrency scam under the FraudGPT brand.
CanadianKingpin12 first tried to sell FraudGPT on lower-level clearnet cybercrime forums; threads were repeatedly removed, so the actor pivoted to a Telegram channel (created 2023-06-23) to distribute more resiliently, avoiding the exit-scam risk of dark-web markets like Empire, WHM, Torrez, World, AlphaBay and Versus where the actor claimed "verified vendor" status.
The Telegram/dark-web listings advertised a ChatGPT-style interface with no ethical guardrails, promoted with a features list (malicious code, undetectable malware, phishing pages/panels, scam letters, non-VBV bin lookup, cardable-site discovery, vulnerability/leak search, page hosting, code obfuscation, OTP-spoofing bots, CVV checking, and 24/7 escrow) and a claim of 3,000+ prior sales.
Netenrich's threat research team discovered and documented the listings on 2023-07-25, tracing the operator to the email canadiankingpin12@gmail.com. In 2025, Cisco Talos independently engaged CanadianKingpin12 on Telegram posing as a buyer; after prolonged negotiation the actor supplied a username/password for the FraudGPT site that did not work, then demanded cryptocurrency to purchase a "crack" for the login page, behavior Talos assessed, and other scammed buyers corroborated, as evidence the actor had no working AI product and was running a straightforward advance-fee/crypto scam under the FraudGPT brand.
Lure (to prospective cybercriminal buyers): a slick "exclusive bot" pitch positioning FraudGPT as a ChatGPT alternative "with no boundaries," backed by a long feature list and a claimed track record of 3,000+ sales/reviews: social proof and scarcity framing (limited licenses, per-month virtual-machine/page-hosting caps) designed to create urgency and legitimacy for buyers on cybercrime forums.
Tell/giveaway: when Cisco Talos actually attempted to purchase access, the promised login credentials simply did not work, and the actor pivoted immediately to demanding a further cryptocurrency payment for an unexplained "crack," a classic advance-fee-fraud pattern (moving the goalposts after initial payment) that other buyers on the same forums independently reported experiencing.
Netenrich's 2023-07-25 report made FraudGPT one of the most widely cited examples (alongside WormGPT) of the "malicious LLM-as-a-service" trend, driving broad vendor and media coverage (SC Media, SecureWorld, Security Boulevard, Varonis, etc.) through mid-to-late 2023, and prompted general law-enforcement commentary: FBI Director Christopher Wray publicly warned on 2023-07-26 that criminals were exploiting generative AI for malware and spearphishing, without naming FraudGPT specifically.
Netenrich stated as of its report date it knew of no confirmed active attacks carried out using FraudGPT-generated content. No public record of a specific victim organization or law-enforcement case tied to FraudGPT-produced phishing was identified. In 2025, Cisco Talos's own attempted purchase established that the offering was very likely a scam targeting cybercriminal buyers rather than a functioning AI weapon, undercutting the tool's own advertised capabilities, though the "FraudGPT" brand persisted in underground and vendor-report circulation into 2026 as a loosely-used label for copycat/rebranded "uncensored AI" offerings.
FraudGPT is one of the earliest and most-cited "malicious LLM-as-a-service" offerings, widely referenced in threat-intel literature (alongside WormGPT, GhostGPT, DarkGPT, DarkestGPT and others) as evidence that generative AI lowers the technical barrier to phishing and fraud. But the case is equally important as a caution against taking underground-market capability claims at face value: years of follow-on vendor research (Cisco Talos in 2025, echoed by Rapid7's 2026 criminal-AI-market analysis) found no verified working FraudGPT backend, and concluded the operator was very likely running a straightforward scam against fellow criminals rather than operating a functioning offensive AI tool.
For an educational audience, the incident illustrates two overlapping social-engineering layers: (1) the advertised threat, AI marketed to make phishing/BEC content more convincing and scalable, and (2) the demonstrated threat, that the "AI cybercrime tool" market itself is rife with advance-fee scams that use the same urgency, social-proof, and authority tactics found in consumer-facing fraud, just aimed at criminal buyers instead.
It's a useful corrective against uncritically amplifying vendor claims about "new AI attack tools" without independent verification.
Treat "blackhat AI" marketplace claims (FraudGPT, WormGPT, DarkGPT, GhostGPT, etc.) with the same skepticism as any other unverified cybercrime-forum product. Vendor threat intel repeatedly finds these are frequently non-functional or vastly oversold, so downstream defense should focus on the actual delivery mechanism (phishing emails/pages, BEC lures) rather than the AI branding.
Standard anti-phishing/anti-BEC controls remain the effective countermeasure regardless of whether AI generated the lure: DMARC/SPF/DKIM enforcement, execution-time link/attachment sandboxing, out-of-band verification for payment/wire-change requests, security awareness training that flags urgency+financial-request combinations, and behavioral/email-gateway detection tuned to the writing-quality and infrastructure patterns of BEC rather than to "AI-generated" as a distinct signature (AI-polished text is often indistinguishable from human-written text).
For organizations evaluating cyber-threat-intel vendor claims about new "AI crime tools," corroborate with a second independent source (as Talos/SlashNext/Netenrich did here) before treating capability claims as fact.
Social Engineering Examples. “FraudGPT Underground Chatbot”. Accessed 19 September 2026. https://socialengineeringexamples.com/fraudgpt-underground-chatbot-2023
Before contacting any buyer, CanadianKingpin12 built a dark-web storefront and marketing materials for FraudGPT, positioning it as an unrestricted, jailbroken-style ChatGPT alternative, and initially posted it on multiple clearnet cybercrime forums before pivoting to a more resilient Telegram channel (created 2023-06-23) once forum threads were repeatedly removed, per SlashNext and Netenrich.
Attacker-controlled marketing infrastructure on dark-web forums and Telegram is largely outside a defender's reach to remove; the realistic control is threat-intelligence monitoring of these channels (as Netenrich and SlashNext did) to get early warning of new 'AI cybercrime tool' claims so downstream anti-phishing controls can be validated rather than the tool itself chased.
The actor claimed 'verified vendor' status on several named dark-web marketplaces and an unverified '3,000+ confirmed sales/reviews' track record, manufacturing trust signals for prospective cybercriminal buyers before any transaction took place.
Treat 'verified vendor' badges and bulk sales-count claims on cybercrime forums as unverifiable marketing rather than evidence of legitimacy or capability; require independent corroboration from a second source before treating any such claim as fact.
FraudGPT was advertised with a detailed capability list (phishing pages/panels, BEC email drafting, malware generation, CVV/carding tools, 24/7 escrow) at $200/month or $1,700/year, giving prospective buyers a concrete, appealing value proposition to act on.
Evaluate advertised capabilities against actual observed samples or independent testing rather than a feature list, and remember that standard anti-phishing and anti-BEC controls (DMARC/SPF/DKIM, link sandboxing, awareness training) work the same regardless of whether a lure claims AI origin.
The actor engaged interested buyers, including Cisco Talos researchers posing undercover in 2025, one-on-one over Telegram, with prolonged back-and-forth negotiation that built apparent rapport and momentum toward a purchase.
Build a structured verification step, proof of function before payment, into any acquisition process, and treat a seller's urgency or relationship-building pressure as a caution flag rather than a reason to move faster; this applies equally to a legitimate buyer being scammed as it does to phishing targets in general.
After negotiation concluded, the actor supplied a username and password for the FraudGPT site, but per Talos the credentials did not work, creating a plausible-sounding technical snag rather than an outright refusal to deliver.
A broken or non-functioning deliverable that follows a completed negotiation is a hallmark advance-fee-fraud indicator; the practical control is to walk away at this point rather than troubleshoot alongside the seller.
CanadianKingpin12 then asked the buyer to send additional cryptocurrency to purchase a 'crack' to fix the broken login, exploiting the buyer's sunk cost and momentum from the earlier negotiation to extract further payment.
Any request for a further payment to 'unlock,' 'crack,' or 'activate' something already paid for should be treated as a stop signal; legitimate vendors do not require serial follow-up payments to deliver access already sold.
Talos and multiple other corroborating victims found that paying this second demand did not yield a working product either, completing an advance-fee cryptocurrency fraud against the tool's own prospective criminal customers rather than delivering any functioning AI capability.
Once cryptocurrency is sent, recovery is rarely practical because the payment is irreversible; the only effective control is preventing the payment at Stages 4 through 6, which is why verification has to happen before funds move, not after.
Browse by what this case has in common with others in the library.
Ghanaian social-media personality Frederick Kumi ("Abu Trica") and co-defendant Daniel Yussif were federally indicted for leading a romance-fraud network.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked its Hong Kong finance controller into wiring $46.7M abroad.
The FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.
Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.
A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously…
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that…
A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
A low-skill UK-based cybercriminal used Claude to write the encryption, evasion, and anti-recovery code it could not build itself.
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
Toronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona…