Researchers at Resecurity have uncovered DIG AI, a powerful and uncensored artificial intelligence tool hosted on the darknet, which is being actively used by cybercriminals to automate sophisticated cyberattacks, generate illicit content, and bypass the ethical safeguards present in mainstream AI models. The tool, first detected in late September 2025, has rapidly gained popularity among threat actors, particularly during the winter holiday season, and is promoted by a darknet actor known as "Pitch." DIG AI offers a suite of specialized models, including an unrestricted text/code generator and an image model for deepfakes, all accessible anonymously via the Tor network without registration requirements. Investigators demonstrated the tool's ability to generate obfuscated malicious code, such as JavaScript backdoors, highlighting its potential to lower the barrier for launching advanced attacks.
The emergence of DIG AI marks a significant escalation in the criminal use of artificial intelligence, raising concerns about the increased automation and sophistication of cyber threats. Security experts warn that the tool's capabilities could be leveraged to target major global events in 2026, such as the Winter Olympics and FIFA World Cup, and that its existence signals a broader trend toward the "criminalization of AI." The tool's promotion alongside other illicit goods on underground forums further underscores the convergence of AI and cybercrime, presenting new challenges for defenders and law enforcement agencies worldwide.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Cyber Security News reported Resecurity's findings that DIG AI enables cybercriminals to automate attacks, generate malicious code, create deepfakes, and bypass mainstream AI safety controls. The report described the tool as a major escalation in criminal AI use and a growing risk ahead of major events in 2026.
Security Affairs included the emergence of DIG AI among major late-2025 cybersecurity developments in its newsletter roundup. The report highlighted the tool as part of broader criminal and threat-actor activity observed during the period.
Resecurity researchers first detected the darknet-hosted AI tool DIG AI in late September 2025. The tool was promoted by a threat actor known as "Pitch" and offered uncensored AI capabilities for malicious use via Tor.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.