A new uncensored AI assistant known as DIG AI has emerged on darknet forums, rapidly gaining popularity among cybercriminals and organized crime groups. Security researchers observed a significant increase in the use of DIG AI during Q4 2025, particularly over the Winter Holidays, coinciding with a global surge in illegal activity. DIG AI, along with other "dark LLMs" such as FraudGPT and WormGPT, enables threat actors to automate and scale malicious operations, including cybercrime, extremism, privacy violations, and the spread of misinformation. These tools are often jailbroken or custom-built large language models with safety restrictions removed, making them attractive for illicit purposes.
DIG AI is accessible via the Tor network, making it difficult for law enforcement to detect and disrupt its use. The tool can generate instructions for a range of illegal activities, from explosive device manufacturing to the creation of child sexual abuse material (CSAM), including hyper-realistic synthetic content. The rise of such AI-powered tools presents new challenges for security professionals and legislators, especially with major global events like the 2026 Winter Olympics and FIFA World Cup on the horizon, as criminals may exploit these technologies to bypass content protection and scale their operations.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
On December 18, 2025, Resecurity publicly warned that the spread of dark LLMs, jailbroken models, and emerging criminal AI infrastructure could dramatically escalate AI-enabled cyber threats in 2026. The warning highlighted expected risks around major global events and the growing challenge for law enforcement and defenders.
By December 2025, Resecurity documented DIG AI being actively promoted on dark web marketplaces and used to generate malware, fraud content, criminal guidance, and highly realistic synthetic CSAM. The reporting also noted that the platform bypassed standard AI safety and moderation controls and was based on ChatGPT Turbo.
In Q4 2025, Resecurity observed a significant increase in the use of DIG AI, an uncensored AI assistant accessible via the Tor network without registration. The tool was being adopted by cybercriminals, organized crime groups, and terrorists to support illicit activity at scale.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.