AI Service Available on Criminal Forums

31268055462?profile=RESIZE_400xThe Counter Threat Unit at Sophos has published original research detailing Luciferus, an uncensored artificial intelligence subscription service being advertised on the Exploit underground forum.  The tool is marketed as able to answer requests without moral or ethical limitations, raising new concerns about how criminal groups are adapting generative AI for illicit purposes.  The findings point to a broader shift within the cybercriminal economy, as threat actors move beyond traditional offerings such as malware kits, phishing tools, and ransomware to commercialize AI itself as a service.  Rather than developing criminal tools from scratch, buyers can now subscribe to AI systems specifically stripped of safety guardrails.[1]

According to Sophos researchers, a persona operating under the name Optimus Prime began advertising Luciferus on the Exploit forum on 24 August 2026. The advertisement presents the service as an AI system that will respond to any request without the moral or ethical constraints typically built into mainstream commercial AI products.

The seller claims the model is built on a proprietary architecture containing "120 billion parameters", a scale intended to suggest sophisticated capability comparable to leading commercial systems. However, Sophos analysts assessed with low confidence that Luciferus is more likely based on Qwen, a family of large language models developed by the Chinese technology firm Alibaba, rather than a genuine creation.

This practice of taking an existing open-source or commercially available model and stripping away its safety features before reselling it appears to reflect a growing trend among threat actors.  Rather than investing significant resources into training entirely new models, criminal groups can achieve similar results more cheaply by modifying established systems and packaging them for sale.

The emergence of services such as Luciferus illustrates how quickly the underground economy is adapting to advances in AI technology. Where cybercriminal forums have traditionally traded in stolen data, exploit kits, and access credentials, uncensored AI tools now sit alongside these offerings as a distinct and apparently lucrative product category.

By removing the ethical restrictions built into consumer-facing AI platforms, services like Luciferus could potentially be used to generate malicious code, craft convincing phishing messages, or assist with other harmful activities that mainstream AI providers actively work to prevent.

Sophos researchers noted that this subscription-based model mirrors the "as-a-Service" structure already common in the criminal underworld, where tools such as ransomware are rented out to affiliates rather than sold outright. Applying this same commercial approach to AI suggests threat actors see sustained demand for these capabilities.

Sophos' key message to security professionals is that threat intelligence teams must keep pace with how uncensored AI services are being packaged, marketed and sold on underground forums.  Understanding these developments is essential to track AI-enabled abuse and respond effectively as criminal groups continue to experiment with generative AI technology.

 

This AI-created article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments, or assistance, please contact the office directly at 1-844-492-7225 or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/7855487668891299929

 

[1] https://www.cybersecurityintelligence.com/blog/unregulated-ai-service-available-on-criminal-forums-9744.html

You need to be a member of Red Sky Alliance to add comments!