Hackers Offer Uncensored Luciferus AI Service on Dark Web Forums
Key Takeaways A new “uncensored” AI service named Luciferus is being advertised on dark web forums, specifically targeting cybercriminals. The service claims to assist with malware...
Key Takeaways
- A new “uncensored” AI service named Luciferus is being advertised on dark web forums, specifically targeting cybercriminals.
- The service claims to assist with malware development and other illicit activities, bypassing ethical restrictions present in mainstream AI models.
- Sophos researchers discovered the offering and, with low confidence, suggest it may be based on Alibaba’s Qwen large language model.
- Luciferus is offered through various subscription tiers, demonstrating the increasing commercialization of AI tools for cybercrime.
- A test showed the AI was willing to generate Python code for a remote access trojan, highlighting its potential misuse.
Cybersecurity researchers have uncovered a new “uncensored” artificial intelligence service, dubbed Luciferus, being promoted on dark web forums. This subscription-based AI assistant is explicitly marketed to cybercriminals, offering to fulfill requests for malware development and other illicit tasks that conventional AI systems would refuse.
Table Of Content
Discovery and Operation
The Sophos Counter Threat Unit (CTU) first identified the Luciferus offering on August 24, 2026, on the Exploit underground forum. The service is aimed at a criminal clientele seeking to bypass the technical and operational limitations typically found in legitimate AI platforms, according to Sophos.
The advertisement was posted by a forum user named “Optimus_Prime,” whose profile indicates an activity label of “coding / coder.” This account joined Exploit on April 18 and had accumulated 21 posts by September 4.
Luciferus is promoted as operating without moral or ethical constraints, leveraging a purportedly proprietary model with 120 billion parameters. However, the CTU was unable to independently verify these claims regarding its architecture, parameter count, performance, privacy, or advertised capabilities. Nevertheless, analysts assessed with low confidence that the service might be built on Qwen, Alibaba’s family of large language models, according to Sophos.
It is common for illicit AI operators to market their products as original technology, even when they may rely on fine-tuned open-source models, custom prompts, or orchestration layers.
Subscription Tiers and Discrepancies
The Exploit forum advertisement details three monthly subscription plans: Inquisitor at $35, “Archdeviel” at $55, and Prince of Darkness at $75. A premium “Individual Embodiment” VIP package is also advertised, promising a separately deployed personal model, training on customer data, dedicated computing resources, and control over context and response temperature. Pricing for this top-tier option is reportedly customized based on individual requirements.
Interestingly, the public-facing Luciferus website presents a different commercial structure. It lists Junior at $22, Middle at $34.75, and Pro at $47.14, and makes no mention of the VIP package. Sophos did not provide an explanation for this pricing discrepancy.
Malware Generation Capabilities
Crucially, researchers conducted a test to determine Luciferus’s willingness to respond to an explicit malware request. When prompted to generate a “simple RAT in python,” the Junior model produced a Russian-language description of a basic remote access trojan, detailing networking and command-execution functionalities, and subsequently provided the corresponding source code.
The CTU did not execute the generated code or assess its completeness or functionality. Therefore, this test primarily demonstrates the AI’s readiness to assist in malicious activities rather than proving the quality or operational effectiveness of the generated malware.
Luciferus distinguishes itself from jailbroken versions of mainstream AI models like ChatGPT or Claude, which rely on bypassing safeguards that can be updated or restored by providers. A locally operated or deliberately unrestricted model offers its controllers greater persistence, customization, and independence from mainstream platform enforcement. However, the claim of a “proprietary” model should be approached with caution, as training a truly new foundational model requires significant computing infrastructure, specialized expertise, and extensive datasets.
The Evolving Landscape of Criminal AI
The emergence of Luciferus follows other underground tools like WormGPT and FraudGPT, which have been marketed for generating phishing emails, business email compromise lures, malicious scripts, and malware code. Sophos has previously observed both the proliferation of GPT derivatives and skepticism within criminal forums regarding whether some products are scams, simple wrappers, or overhyped services.
Luciferus also signifies a broader trend in the cybercrime ecosystem, moving from experimental tools to structured commercialization. Trellix reported in August that criminal AI offerings are increasingly adopting characteristics of mature software businesses, featuring tiered pricing, dedicated support channels, and maintained services that cover aspects like attack planning, payload evasion, and access to stolen AI accounts.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.