Hackers have introduced a new artificial intelligence service named ‘Luciferus’ on underground forums, designed to assist in activities that mainstream AI systems typically reject. This service is being marketed as an uncensored AI capable of processing malware-related requests, thus attracting individuals involved in illegal activities.
Discovery by Sophos Researchers
On August 24, 2026, researchers from Sophos Counter Threat Unit (CTU) identified this AI service on the Exploit forum, a platform frequented by cybercriminals. The advertisement, attributed to a user known as ‘Optimus_Prime’, emphasizes Luciferus’s lack of ethical or moral restrictions, appealing to those seeking less regulated AI tools.
The forum user ‘Optimus_Prime’, identified with a ‘coding / coder’ activity label, had been a member since April 18 and had engaged with the community through 21 posts by early September. The AI is described as using a proprietary model with 120 billion parameters, although its exact specifications remain unverified.
Subscription Options and Testing
The service offers various subscription plans, including ‘Inquisitor’ for $35, ‘Archdeviel’ for $55, and ‘Prince of Darkness’ for $75 per month. An exclusive VIP package, termed ‘Individual Embodiment’, promises personalized models and training on user data, though pricing varies based on specific requirements.
Interestingly, the public Luciferus website lists different pricing tiers, namely Junior at $22, Middle at $34.75, and Pro at $47.14, with no mention of the VIP package. This discrepancy has not been explained by Sophos.
Sophos researchers tested Luciferus by requesting a simple remote access trojan (RAT) in Python. The Junior model provided a response in Russian, detailing the functionality and source code of a basic RAT, demonstrating the service’s willingness to comply with such requests.
Implications and Industry Context
Luciferus stands out from other AI tools like jailbroken ChatGPT versions by offering a model that doesn’t rely on bypassing safeguards. This potentially grants users greater control and independence from mainstream AI platform restrictions, though the authenticity of its ‘proprietary’ label is questioned, given the resources required to develop a truly novel AI model.
Following in the footsteps of tools like WormGPT and FraudGPT, which cater to phishing and malware development, Luciferus marks a shift towards more structured commercialization of criminal AI services. These services now mimic legitimate software businesses with tiered pricing and customer support, indicating a maturing underground market.
The emergence of Luciferus and similar AI tools underscores the growing sophistication of cybercriminal offerings, necessitating vigilance and adaptation in cybersecurity measures.
