News chronological

Latest News

AXIOS (Sam Sabin) - AI tools flood into underground cybercrime markets

Hackers in underground cybercriminal forums are on shopping sprees for new AI tools , according to research shared first with Axios. Why it matters: AI is making once-specialized hacking capabilities cheaper and easier to buy, potentially transforming far more criminals into dangerous hackers. By the numbers: Advertisements for AI tools on underground forums and platforms surged from fewer than 50 per month in late 2025 to more than 1,400 by February, according to a report from Halcyon's Ransomware Research Center. - Sellers offered access to ChatGPT Plus accounts for as little as 10 cents and jailbreak prompts to trick models into breaking their safeguards for 32 cents, per the research. - Halcyon studied nearly 4,000 posts across 77 Telegram channels, 20 dark web forums and five specialized underground markets between October and May. Threat level: Companies are already losing millions of dollars to the types of cyberattacks enabled by the tools found on these underground markets. - "It really goes to show you how cheap it is to conduct these activities ... which should be scary for organizations," Cynthia Kaiser, head of Halcyon's Ransomware Research Center and former deputy director of FBI Cyber, told Axios. The big picture: Cybercriminals have completely commercialized the sale and creation of these tools, often modeling software-as-a-service subscription models and online storefronts, per the report. - Some sellers are now offering AI tools they tested and promoted on traditional dark web forums through easier-to-manage storefronts hosted on Telegram. - "It shouldn't have been shocking to me," Kaiser said. "But what we should take away from this is also how much cybercriminals have learned throughout the years about how to sell and package — and they applied this really quickly to the AI models." Zoom in: Hackers are selling four types of AI tools: - Jailbroken and stolen AI services, including prompts that allow users to strip the safety guardrails from mainstream models for as little as $10. - Identity fraud and phishing tools that make impersonating real people quick and easy. - Access to models trained on malicious data to aid cybercrime, such as the popular WormGPT that's designed to write phishing emails and malware. - AI-augmented malware and infrastructure, including a system that can call as many as 120 people at once as part of a scam operation. Flashback: In 2023, hackers could only tap a handful of one-off tools. Now, there's a robust marketplace. - Still, AI is largely helping criminals perform discrete elements of existing attacks more cheaply and efficiently, Kaiser said. - "What you're not seeing for sale is an agent that does it all for you and has this amazing success rate," she said. What to watch: Halcyon didn't find evidence of criminals selling AI systems capable of running fully autonomous cyberattacks. - Even in AI-enabled malware and infrastructure, Kaiser said, much of what researchers are seeing involves coding assistance, infrastructure and other individual tasks rather than AI creating and deploying malware on its own. Go deeper: Rogue AI agents expose internet's frail foundation

What methodology did Halcyon's Ransomware Research Center use to gather data on the underground AI marketplace?
Halcyon studied nearly 4,000 posts across 77 Telegram channels, 20 dark web forums, and five specialized underground markets between the months of October and May.
Q&A ID 5e6ea3af-123e-4dc7-9ea0-2bcc3150abee
What specific costs were associated with various AI-related illicit items found in the underground markets studied by Halcyon?
Sellers offered access to ChatGPT Plus accounts for as little as 10 cents and jailbreak prompts designed to trick models into breaking their safeguards for as little as 32 cents. These low costs make it significantly cheaper for a wider range of individuals to acquire hacking capabilities.
Q&A ID 7685d0a9-a467-4227-bf39-7f0fdef20279
What did Halcyon's Ransomware Research Center find regarding the autonomy of AI systems currently being sold by cybercriminals?
The research did not find evidence of criminals selling AI systems capable of running fully autonomous cyberattacks. Instead, the AI is currently being used to perform discrete elements of existing attacks more cheaply and efficiently, such as providing coding assistance, infrastructure, and individual tasks, rather than creating and deploying malware entirely on its own.
Q&A ID 0c0fb4d1-2960-44fb-89b8-45aedd10e607
How have cybercriminals changed their methods for selling and distributing AI-related cybercrime tools?
Cybercriminals have completely commercialized the sale and creation of these tools, often utilizing software-as-a-service (SaaS) subscription models and online storefronts. Many sellers have moved from traditional dark web forums to easier-to-manage storefronts hosted on Telegram to promote and offer tools they have tested.
Q&A ID 993b5ade-2fe0-4d53-bf15-c79f32d22f97
What specific types of AI tools are currently being sold in underground cybercrime markets, and what are some examples of these tools?
Hackers are selling four primary types of AI tools: 1) Jailbroken and stolen AI services, including prompts to strip safety guardrails from mainstream models for as little as $10; 2) Identity fraud and phishing tools for impersonating real people; 3) Models trained on malicious data to aid cybercrime, such as WormGPT, which is designed to write malware and phishing emails; and 4) AI-augmented malware and infrastructure, including systems capable of calling up to 120 people at once for scam operations.
Q&A ID db576ce6-e2fb-4ee6-b746-1ca0e832fe4c

Related article: AXIOS (Sam Sabin): Rogue AI agents expose internet's frail foundation •

Related article: AXIOS (Sam Sabin): AI is making critical infrastructure easier to attack •

Related article: AXIOS (Sam Sabin): China's AI advances collide with U.S. safety debate •

Related article: AXIOS (Sam Sabin): AI's imminent hacking threat is hiding in plain sight •

Related article: NPR (Huo Jingnan): How AI is getting better at finding security holes •

Latest News