Security1 publisher2 min readPublished
Recorded Future singles out deepfakes as the AI phishing tactic existing controls fail to stop
Recorded Future says filtering, verification and training still blunt most AI phishing, with deepfaked voice and video the exception. Its advice is to stop treating a familiar face or voice on a call as proof of identity.
The Watch · Security desk

What happened
- Recorded Future says deepfakes and voice alteration weaken the audio, visual and biometric signals that people and identity systems have treated as evidence of identity.
- WormGPT4, a malicious model identified in September 2025, generates phishing messages, harmful code, data-theft tools and ransom notes.
- Proofpoint reported in August 2025 that attackers used Lovable, a legitimate AI website builder, to create phishing pages and malware.
- Z.ai released the open-weight GLM-5.2 in June 2026, and users can run it privately and alter its behavior outside the developer's systems.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Payment approvals and help-desk resets that end when an employee recognizes the caller need a confirmation step that does not run through the same call.
- exposure Automated identity systems that score a face, voice or document image face the same forgery as the employee on the phone.
- capability Subscription pricing gives unrestricted phishing generators to buyers who could not build or jailbreak a model themselves.
- constraint Open-weight releases like GLM-5.2 give the developer less visibility into misuse, so abuse monitoring by the model provider covers less of the threat.
Rated by exploitability, the two halves of Recorded Future's analysis are different problems. Most of the AI use it catalogues improves the lure. That covers target research, translation, analysis of stolen inboxes, and automated follow-ups in job, customer-service and business email compromise scams [14]. These tools make known techniques cheaper to run at scale [2]. The lure still arrives at controls built to inspect it. The company's caveat is that those controls need adjusting for the volume and sophistication [3].
A deepfaked call attacks the check itself [4]. If verification means one employee recognizing another's voice or face, the forgery is built to pass that step. Recorded Future cites research finding that people and detection systems both struggle to identify deepfakes reliably, especially outside controlled settings [5]. It concludes that defenses relying on a familiar voice, face or identity document are often insufficient on their own [6].
The company also warns that treating every AI-enabled threat as equivalent gives organizations a false sense of security. It also leaves them open to the attacks that existing controls fail to prevent [7].
The supply side is sold on consumer terms. WormGPT4 comes in multiple pricing tiers, including a lifetime access plan [15]. Recorded Future names eight malicious models, WormGPT and FraudGPT among them, that let users get around the safeguards in commercial LLMs [8]. It names four more services, Nytheon, Xanthorox, GhostGPT and SheByte, that sell existing tools on subscription without safety restrictions [10]. That makes 12 named offerings [1].
Attackers use legitimate builders too. Lovable has been used to create tens of thousands of malicious websites, including pages impersonating Microsoft, UPS and HR and financial-services platforms [12].
Across these reports, the pattern is off-the-shelf tooling sold to anyone who subscribes [10][15]. The post does not attribute the activity to a named group.
What to watch
- Published success or loss rates for deepfake-led fraud against organizations that already require callback verification.
- Changes by identity-verification providers to face and document checks in response to synthetic media.
- Reporting that ties GLM-5.2 to phishing infrastructure, as Proofpoint's August 2025 report did for Lovable.