Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Luciferus Markets Subscription AI for Malware Development on Criminal Forums
Luciferus Markets Subscription AI for Malware Development on Criminal Forums
Read Time:3 Minute, 14 Second

Criminal forum users are promoting an artificial intelligence service named Luciferus as an “uncensored” assistant willing to handle malware-development requests. The subscription offering reflects a growing effort to package generative AI for cybercrime, but researchers caution that many of its most impressive technical and commercial claims have not been independently verified.

Underground marketing targets malware developers

Sophos Counter Threat Unit researchers found the advertisement on the Exploit forum on August 24, 2026. A persona using the name “Optimus_Prime” promoted the product to customers who want fewer ethical and operational restrictions than mainstream services impose. The account was relatively new and had only a small posting history when analysts reviewed it.

The seller claims Luciferus uses a proprietary model with 120 billion parameters and has no moral restrictions. Sophos could not validate the architecture, size, privacy guarantees or performance. Analysts assessed with low confidence that it may rely on Alibaba’s Qwen model family. That uncertainty matters because underground vendors frequently label customized open-source models, prompt wrappers or orchestration layers as original foundation models.

Tiered pricing resembles legitimate software

The forum advertisement described three monthly plans priced at $35, $55 and $75, plus a bespoke tier with a separately deployed model, customer-specific training, dedicated computing resources and adjustable response settings. The public website showed a different set of names and lower prices, ranging from $22 to $47.14, without mentioning the bespoke package.

The inconsistent offers could reflect changing marketing, separate sales channels or simple unreliability. Buyers in criminal markets face the same fraud risk they create for others: a polished subscription page does not prove that the promised model, infrastructure or confidentiality exists. Data submitted for customization may itself be harvested or resold.

A test produced remote-access-trojan code

Researchers asked the entry-level model for a simple remote access trojan written in Python. It responded in Russian with an outline of networking and command-execution features and then generated source code. Sophos did not run the output or determine whether it was complete and functional. The test therefore confirms willingness to assist with an explicitly malicious request, not that Luciferus can produce dependable malware.

This distinction is important when assessing risk. Generative systems can lower the effort needed to draft scripts, explain techniques and revise code, but generated malware may be buggy, recognizable or unsafe for its operator. Skilled attackers already possess better tools. The more immediate effect may be acceleration of low-quality campaigns and assistance for less experienced criminals.

Why locally controlled models change enforcement

Jailbroken mainstream chatbots depend on bypassing safeguards that providers can strengthen. A locally operated or deliberately unrestricted model gives its controller more persistence and customization and reduces reliance on an account that can be suspended. Open models can also be fine-tuned or surrounded with tooling designed specifically for phishing, code modification and attack planning.

Luciferus follows earlier brands such as WormGPT and FraudGPT, which were advertised for malicious email, business-email compromise and code generation. The pattern increasingly resembles conventional software-as-a-service: several price points, maintained interfaces, support channels and promises of dedicated deployments. Some offerings will be scams, but the commercialization trend is real even when an individual vendor’s claims are inflated.

Defensive implications

  • Do not treat AI-generated malware as a unique family; detect behavior and infrastructure instead.
  • Expect faster variation in scripts, lures and commodity payloads.
  • Monitor criminal-market claims but validate them before changing risk assessments.
  • Protect source code, credentials and incident data from being submitted to untrusted AI services.

Security teams should focus on resilient controls: strong identity protection, endpoint behavioral monitoring, restricted scripting, rapid isolation and tested response procedures. The Luciferus advertisement shows that cybercriminals see market value in removing AI safeguards. It does not prove a breakthrough model, but it does show how readily established AI technology can be repackaged for an illicit audience.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Luciferus Markets Subscription AI for Malware Development on Criminal Forums, use the discussion on Forum.

>> forum community

Comments

Leave a Reply