Cybercrime forums have sharply increased discussion and sales activity around malicious AI tools, with researchers reporting a 219% rise in mentions of dark AI tools and tactics and a 52% increase in references to jailbreaking mainstream platforms such as ChatGPT. These offerings include jailbroken versions of public generative AI services and customized tools built on open-source large language models, often sold as AI-as-a-Service to support phishing, business email compromise, deepfakes, fraud, vulnerability analysis, malware development, identity fraud, password attacks, credential stuffing, and DDoS operations.
Reporting on the underground market says well-known brands such as WormGPT and FraudGPT are only the most visible examples of a broader ecosystem of rebranded, resold, and short-lived criminal services. Analysts say the main effect of these tools is not breakthrough offensive capability but the removal of safety guardrails, making it easier for lower-skilled actors to generate convincing scam content and some malicious code; the market has also shifted toward repurposed open-source uncensored models, while scams targeting criminals and a reported leak of nearly 19,000 WormGPT user accounts highlight instability and risk inside the ecosystem itself.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The analysis cites a reported 2026 leak of nearly 19,000 WormGPT user accounts, highlighting operational risk within the criminal ecosystem itself. It presents the leak as an example of growing scrutiny and exposure affecting malicious AI services.
The malicious AI market shifted after 2023 toward repurposed open-source uncensored models, which the analysis says can deliver similar outputs without paid subscriptions. The article describes WormGPT and FraudGPT as part of a broader ecosystem of rebrands, resellers, and short-lived services rather than stable standalone products.
Kela reported that cybercrime-underground mentions of AI abuse rose sharply during 2024, including a 52% increase in mentions of jailbreaking tools such as ChatGPT and a 219% increase in mentions of malicious AI tools and tactics. The report said these tools were being used to scale phishing, deepfakes, fraud, vulnerability analysis, malware development, identity fraud, password attacks, credential stuffing, and DDoS activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.