An actor using the handle Optimus_Prime advertised the subscription-based Luciferus AI service on the Exploit hacking forum as an unrestricted alternative to jailbreaking mainstream models such as ChatGPT and Claude. The service claims to run a proprietary 120-billion-parameter model, though Sophos Counter Threat Unit researchers assessed with low confidence that it may instead use Alibaba’s open-source Qwen model family. Its advertised tiers and pricing differ between the forum post and associated website.
Luciferus offers paid access ranging from a Junior tier to bespoke VIP deployments with isolated infrastructure, customer-data training, dedicated compute, and configurable settings. When researchers asked the Junior tier for a Python remote-access trojan, it generated a Russian-language explanation and code for networking and command execution; the researchers did not execute or validate the output. The offering reflects the growing commercialization of minimally restricted AI services that can lower barriers for phishing, business-email compromise, malicious scripting, and malware development.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Optimus_Prime advertised Luciferus as a paid AI service that would answer requests without moral or ethical restrictions. The advertisement claimed a proprietary 120-billion-parameter model and offered subscription tiers plus an isolated, customer-trained VIP deployment option.
The persona later advertising Luciferus, Optimus_Prime, joined the Exploit forum and was labeled as a coding/coder account.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.