Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Warns of 17 Active Directory Attack Techniques
September 15, 2026
New Tactics: Malware Uses Rotating Infrastructure to Evade Detection
September 15, 2026
Apple Patches 273 Flaws Across iOS, macOS, watchOS, and tvOS
September 15, 2026
Home/CyberSecurity News/Hackers Offer Uncensored Luciferus AI Service on Dark Web Forums
CyberSecurity News

Hackers Offer Uncensored Luciferus AI Service on Dark Web Forums

Key Takeaways A new “uncensored” AI service named Luciferus is being advertised on dark web forums, specifically targeting cybercriminals. The service claims to assist with malware...

Marcus Rodriguez
Marcus Rodriguez
September 15, 2026 3 Min Read
3 0

Key Takeaways

  • A new “uncensored” AI service named Luciferus is being advertised on dark web forums, specifically targeting cybercriminals.
  • The service claims to assist with malware development and other illicit activities, bypassing ethical restrictions present in mainstream AI models.
  • Sophos researchers discovered the offering and, with low confidence, suggest it may be based on Alibaba’s Qwen large language model.
  • Luciferus is offered through various subscription tiers, demonstrating the increasing commercialization of AI tools for cybercrime.
  • A test showed the AI was willing to generate Python code for a remote access trojan, highlighting its potential misuse.

Cybersecurity researchers have uncovered a new “uncensored” artificial intelligence service, dubbed Luciferus, being promoted on dark web forums. This subscription-based AI assistant is explicitly marketed to cybercriminals, offering to fulfill requests for malware development and other illicit tasks that conventional AI systems would refuse.

Table Of Content

  • Key Takeaways
  • Discovery and Operation
  • Subscription Tiers and Discrepancies
  • Malware Generation Capabilities
  • The Evolving Landscape of Criminal AI

Discovery and Operation

The Sophos Counter Threat Unit (CTU) first identified the Luciferus offering on August 24, 2026, on the Exploit underground forum. The service is aimed at a criminal clientele seeking to bypass the technical and operational limitations typically found in legitimate AI platforms, according to Sophos.

The advertisement was posted by a forum user named “Optimus_Prime,” whose profile indicates an activity label of “coding / coder.” This account joined Exploit on April 18 and had accumulated 21 posts by September 4.

Luciferus is promoted as operating without moral or ethical constraints, leveraging a purportedly proprietary model with 120 billion parameters. However, the CTU was unable to independently verify these claims regarding its architecture, parameter count, performance, privacy, or advertised capabilities. Nevertheless, analysts assessed with low confidence that the service might be built on Qwen, Alibaba’s family of large language models, according to Sophos.

It is common for illicit AI operators to market their products as original technology, even when they may rely on fine-tuned open-source models, custom prompts, or orchestration layers.

Subscription Tiers and Discrepancies

The Exploit forum advertisement details three monthly subscription plans: Inquisitor at $35, “Archdeviel” at $55, and Prince of Darkness at $75. A premium “Individual Embodiment” VIP package is also advertised, promising a separately deployed personal model, training on customer data, dedicated computing resources, and control over context and response temperature. Pricing for this top-tier option is reportedly customized based on individual requirements.

Interestingly, the public-facing Luciferus website presents a different commercial structure. It lists Junior at $22, Middle at $34.75, and Pro at $47.14, and makes no mention of the VIP package. Sophos did not provide an explanation for this pricing discrepancy.

Malware Generation Capabilities

Crucially, researchers conducted a test to determine Luciferus’s willingness to respond to an explicit malware request. When prompted to generate a “simple RAT in python,” the Junior model produced a Russian-language description of a basic remote access trojan, detailing networking and command-execution functionalities, and subsequently provided the corresponding source code.

The CTU did not execute the generated code or assess its completeness or functionality. Therefore, this test primarily demonstrates the AI’s readiness to assist in malicious activities rather than proving the quality or operational effectiveness of the generated malware.

Luciferus distinguishes itself from jailbroken versions of mainstream AI models like ChatGPT or Claude, which rely on bypassing safeguards that can be updated or restored by providers. A locally operated or deliberately unrestricted model offers its controllers greater persistence, customization, and independence from mainstream platform enforcement. However, the claim of a “proprietary” model should be approached with caution, as training a truly new foundational model requires significant computing infrastructure, specialized expertise, and extensive datasets.

The Evolving Landscape of Criminal AI

The emergence of Luciferus follows other underground tools like WormGPT and FraudGPT, which have been marketed for generating phishing emails, business email compromise lures, malicious scripts, and malware code. Sophos has previously observed both the proliferation of GPT derivatives and skepticism within criminal forums regarding whether some products are scams, simple wrappers, or overhyped services.

Luciferus also signifies a broader trend in the cybercrime ecosystem, moving from experimental tools to structured commercialization. Trellix reported in August that criminal AI offerings are increasingly adopting characteristics of mature software businesses, featuring tiered pricing, dedicated support channels, and maintained services that cover aspects like attack planning, payload evasion, and access to stolen AI accounts.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Cisco Secure Email Gateway Critical Zero-Day Actively Exploited, CISA Warns

Next Post

Japan Digital Agency Breach Exposes 240K+ User Records

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Offer Uncensored Luciferus AI Service on Dark Web Forums
September 15, 2026
Cisco Secure Email Gateway Critical Zero-Day Actively Exploited, CISA Warns
September 15, 2026
Critical cPanel LiteSpeed Web Server Flaw Lets Users Gain Root Access
September 15, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us