The AI black market has been discovered. What is sold there, and what is it capable of?
The AI black market is no longer just a collection of experimental “malicious chatbots.” An entire industry has emerged on these underground platforms: specialized AI systems, unrestricted access to models, tools for automating cyberattacks, and services capable of performing certain tasks in place of humans are all sold here. We decided to take a look inside this market to see exactly what’s available for purchase today, how much it costs, and whether these tools can actually deliver on the promises made by their sellers.
Researchers at Trellix have discovered an entire marketplace for specialized AI tools on major underground forums. These forums sell systems for reconnaissance, vulnerability scanning, attack planning, bypassing antivirus software, and handling stolen data. They offer subscriptions, technical support, updates, and customer reviews.
But we decided to look into a more interesting question.
Is it already possible to just buy an AI hacker today?
From Chatbots to Black-Box SaaS
In the first half of 2026, researchers at Trellix monitored major underground markets and identified seven distinct uses of AI—ranging from reconnaissance and vulnerability hunting to bypassing security measures and handling stolen data.
Vendors have started packaging AI the same way traditional tech companies package SaaS: subscriptions, pricing plans, support, updates, and feature demos.
One of the most telling examples is APEX AI.
On DarkForums, it was advertised as a self-hosted, uncensored, and offensive AI for planning APT-level attacks.
The user specifies the target domain. The system promises to gather available information, identify potential entry points, and map out a prioritized attack path leading all the way to ransomware.
It is advertised as integrating with the OSINT sources Shodan and DeHashed.
There are two modes: one builds an attack chain for a specific target, and the other is designed for penetration testing.
The price is $100 per month.
Even the creators of APEX warn buyers: you won't be able to carry out a serious attack with just one team. For complex tasks, you'll still need someone who knows how to work with the system.
There's MessiahGPT.
It is being sold on BreachForums as a standalone, uncensored AI service. The seller claims that the model was trained without RLHF or Constitutional AI and is designed for queries that are prohibited by mainstream models. There are 50 free requests, followed by pricing starting at $8 per month, with payment in cryptocurrency and no KYC required. However, Trellix specifically emphasizes that the seller’s claims about the model and its architecture cannot be independently verified.
But there is already some evidence of its effectiveness
The APEX ad showcased an example of an analysis of a specific infrastructure: the system allegedly detected a Jenkins instance with exposed AWS credentials, a vulnerable VPN, and a potential target for spear-phishing.
A proof-of-concept (PoC) for the WinRAR vulnerability CVE-2025-8088 was posted on the Exploit forum; according to the author, it was created by APEX AI. Researchers obtained the executable file and analyzed it using VirusTotal.
Metamorphic Crypter is being sold on Exploit—a service designed to modify malicious files in a way that makes them harder for security tools to detect.
The concept of polymorphic and metamorphic malware has been around for decades. What’s new here is automation.
For each build, the service creates a modified version using AI-driven variation. As a result, a signature created to detect one instance may prove ineffective against the next.
Trellix monitored product updates, customer feedback, technical support, and even a dispute between a customer and a developer over the course of five weeks.
According to the researchers, the seller refused to accept incompatible payloads rather than sell a build that he knew would not work.
This seems less like an experiment and more like a typical commercial development. The only difference is that the product is intended for criminals.
Even access to ordinary AI is being sold on the black market
Criminals don't necessarily have to create their own "DarkGPT."
For example, Exploit used to offer an automated service for purchasing session cookies called Claude. The price depended on the subscription tier and the remaining quota.
Instead of creating their own powerful AI, a criminal might try to gain access to an existing model through a stolen account, an intermediary, or a modified interface.
And this is confirmed by another study.
NordLayer found that discussion of well-known specialized products such as WormGPT and FraudGPT has virtually stopped growing: 155 related posts were recorded for the entire year of 2025, and 93 for the first five months of 2026.
Researchers suggest a simple explanation:
The jailbroken version of a modern, high-end model often proves to be more powerful than a specially designed “criminal AI.”
So, was DarkGPT just a flash in the pan?
Many of the so-called “criminal AIs” being sold aren’t new models at all. They are wrappers around commercial services, jailbreaks, fine-tuned open-weight models, Telegram bots, or combinations of existing technologies.
Some of them are actually useful.
Others are repackaged public models.
Some services disappear quickly, change their names, or turn out to be scams targeting the criminals themselves.
Therefore, the mere existence of a post on an underground forum does not necessarily mean that a revolutionary technology exists.
Google has already seen AI used to create zero-day exploits
In May 2026, the Google Threat Intelligence Group published much more serious findings.
Researchers have, for the first time, identified cybercriminals who used a zero-day exploit that they believe, with a high degree of certainty, was developed using AI.
The vulnerability allowed two-factor authentication to be bypassed in a popular open-source system administration tool.
The criminals were planning large-scale exploitation.
Google reported the vulnerability to the developer, and the operation was thwarted before it could be exploited on a large scale.
AI no longer just writes emails; it helps address previously unknown vulnerabilities.
Google also observed thousands of repetitive queries from operators linked to state-sponsored groups who were using AI to analyze CVEs and test proof-of-concepts.
Other systems have experimented with AI agents and test environments in an effort to improve the reliability of the exploits they generate.
Malicious code begins to make decisions on its own
Another threat category identified by Google is malware capable of interacting with AI while it is running.
Researchers describe PROMPTSPY as an example of a shift toward a more autonomous attack model: the AI analyzes the state of the compromised system and helps generate further commands.
In the past, an attacker would program a set of actions in advance; now it is possible to build a system:
saw the situation → assessed it → decided on the next course of action.
It is precisely this capability that potentially distinguishes ordinary automation from a true AI agent.
832 real accounts showed why hackers need AI
Anthropic analyzed the use of AI in real-world cyber operations.
Of the 832 cybercriminals studied, 560—67.3%—used AI to develop malware.
54 operators used AI during lateral movement—after they had initially penetrated the system.
In other words, AI is gradually moving from the attack perimeter directly into the compromised infrastructure.
Anthropic also detected a change in the threat level.
In the first half of the period under review, 33% of the operators identified were classified as at least medium-risk.
In the second half, the figure was already 56%.
Researchers have reached an unsettling conclusion: a person's technical skill level is becoming an increasingly unreliable indicator of how dangerous their attack is.
AI is capable of doing some of the difficult work for him.
And now, Taiwan
This is where theory meets reality.
In July 2026, Taiwan's government systems were hit by an unusual cyberattack.
On August 13, Taiwan's Ministry of Digital Affairs confirmed the incident.
According to authorities, a hybrid approach was used: conventional operator activities were combined with attacks carried out by AI agents, including OpenClaw.
A separate investigation by the Israeli company Dream revealed an even more interesting picture.
A group of AI agents carried out various tasks simultaneously as part of a single operation. Over the course of four days, the attackers stole credentials, gained access to personnel information at the Ministry of Justice, and scanned the infrastructure of the nuclear security agency.
According to the investigation, more than 85 accounts were compromised and more than 2,500 personnel records were stolen.
And this has happened before
Back in 2025, Anthropic uncovered a major cyberespionage campaign that it linked to a Chinese state-sponsored group.
The attackers exploited Claude Code and attempted to infiltrate approximately 30 organizations—including technology companies, financial institutions, chemical companies, and government agencies.
In several cases, the attacks were successful.
Anthropic called it the first documented case of a large-scale cyberattack carried out without significant human intervention.
In other words, the journey from AI assistant to AI operator has already begun.
So, can AI hack?
After checking it out, the result wasn't as impressive as the Dark Web ad had led me to believe.
Yes—but not quite the way they're selling it.
Today, AI is already capable of helping to identify vulnerabilities, create and adapt code, analyze infrastructure, process stolen data, conduct reconnaissance, operate within a compromised network, and coordinate multiple stages of an operation.
In some cases, AI agents are already carrying out a significant portion of the attack with minimal operator intervention.
However, there is still no evidence of the existence of a fully autonomous system accessible to anyone—one that you could simply tell to “hack this company,” after which it would independently carry out the entire operation, from selecting the method to the final compromise.
Conclusion KLJO
If you look at all this from a slightly different angle—that of the black market—it may not be necessary at all for the black market to develop its own “super-AI.” Why spend huge amounts of money and resources on it when the world’s largest companies are already developing the best models?
All that's left is to find a way to remove the restrictions, gain unauthorized access, or connect a ready-made model to the necessary tools.
And this leads to a rather amusing paradox: it isn't necessary at all to deliberately create "malicious AI."
All you have to do is lift the restrictions on the good guy—and he'll be the one to do all the dirty work.
Sources
Trellix Advanced Research Center — Weaponized AI: The Commoditization of Cybercrime, August 2026.
Google Threat Intelligence Group — Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access, May 2026.
Anthropic — What We Learned from Mapping a Year’s Worth of AI-Enabled Cyber Threats, June 2026.
Anthropic — Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign, November 2025.
Rapid7 — Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime, June 2026.
NordLayer / NordStellar — Dark Web AI Trends 2026, July 2026.
Ministry of Digital Affairs, Taiwan — Statement on an AI-assisted cyberattack, August 13, 2026.
Genians — Kimsuky AI Infrastructure Research, August 2026.
