Trellix researchers reported that criminal underground forums are selling malicious AI services that support cyberattacks across the attack lifecycle. One offering, APEX AI, can reportedly generate a detailed ransomware attack plan from a target domain and identify employees for potential spear-phishing campaigns.
The tools have moved beyond proof-of-concept discussions into commercial products with pricing tiers, update schedules, and customer reviews. Their automation may lower the expertise needed for sophisticated intrusions, accelerate reconnaissance and campaign preparation, and broaden the pool of actors capable of conducting ransomware and phishing operations.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
During the first half of 2026, Trellix researchers identified multiple malicious AI-related offerings on major criminal underground forums. The services supported functions including reconnaissance, exploit development, payload delivery, evasion, and post-compromise operations, and were marketed with commercial features such as pricing tiers, support, updates, and customer reviews.
APEX AI was advertised as a cyberattack tool that accepts a target domain and generates a step-by-step ransomware attack plan, including identification of employees for potential spear-phishing targeting.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.