Criminals Use Their Own Language Models Daily, Underworld Survey Shows

Criminals Use Their Own Language Models Daily, Underworld Survey Shows

Ondřej Barták
Ondřej Barták
Entrepreneur and Programmer
20. 8. 2026
5 minutes reading
Listen to the article
Audio version of the article
Criminals Use Their Own Language Models Daily, Underworld Survey Shows

Artificial intelligence has moved from the experimental stage into everyday use in the criminal underworld. This follows from a half-year threat report by security company Flashpoint, which mapped the first half of this year, as well as an analysis by Japanese company Trend Micro. Both findings point in the same direction. Attackers are no longer wondering whether artificial intelligence will be useful to them. They are figuring out how to get as much as possible from it for as little money as possible. 

Custom models

Flashpoint analysts examined nearly four petabytes of material. Most of it came from specialized forums, encrypted channels, and servers belonging to attackers. Criminal tools using artificial intelligence appeared in more than twenty-two million posts. 

Many of these tools have disappeared from publicly accessible locations. This is because groups have begun operating their own language models with safety guardrails removed on infrastructure they control themselves. They use them to identify potential victims, write scripts that bypass antivirus software, prepare fraudulent emails, and create code that exploits vulnerabilities in programs. Such activity is almost invisible from the outside, and security teams have therefore lost some of the visibility they previously had. 

The situation is getting worse

Over six months, malware designed to steal login credentials infected 7.4 million computers worldwide. This resulted in 1.7 billion stolen passwords and other data linked to users' identities. Malicious software from the Vidar, StealC, and Lumma families was the most active. These programs are sold by subscription and secretly collect active login tokens from browsers on infected computers. An attacker with such a token does not need the victim's password at all.

The exploitation of software vulnerabilities has accelerated in a similar way. More than twenty-one thousand were disclosed over the six-month period, and nearly one in five came with working exploit code from the outset. Such code was freely available for 4,015 of them. More than 34 percent of the vulnerabilities were rated critical or high severity. According to Flashpoint, security teams can therefore no longer prioritize patches based solely on severity, because they simply cannot handle such a volume in time. 

Extortion attacks increased. The number of verified victims rose by 45 percent to more than six thousand, with approximately 2,700 cases occurring in the US. Manufacturing companies were the most frequent targets, accounting for 18 percent of cases. The Qilin group was responsible for the largest number of victims, with 901 attacks, followed by the Akira, 0APT, The Gentlemen, and Dragon Force organizations. The five largest gangs were responsible for 44 percent of all attacks.

Total cryptocurrency ransom payments fell by approximately eight percent to $820 million, while the proportion of victims who paid declined to 28 percent, potentially the lowest figure on record. Access to compromised networks also became cheaper. Automated tools drove the average price of sold access down by 69 percent to $439. 

Jailbreak as a service

Trend Micro examined the same phenomenon from the other side, specifically the supply of goods and services among criminals themselves. Its research team analyzed underground services, malicious code samples, and ongoing attack campaigns from the end of last year. It concluded that attackers' attention had shifted from experimentation to reliability and low cost. 

This trend is most apparent in services that bypass the restrictions of commercial chatbots. Offers of uncensored tools using artificial intelligence continue to appear on forums, but most of them quickly disappear. Those who succeed do not build their own models but can reliably break through the protections of major platforms. In effect, they are piggybacking on the multibillion-dollar investments of commercial companies. Trend Micro has introduced the term jailbreak as a service for this model and notes that buyers no longer need any special knowledge to use it.

Malware and deepfakes

Researchers also recorded the first samples of malicious code that send queries to a language model while running and modify themselves based on the response. Each infection can therefore look slightly different. For now, this is more of an indication than a widespread practice, because such samples face numerous limitations and no one is deploying them on a large scale. However, they show the direction in which their authors are thinking. Instead of building everything directly into the program, they use artificial intelligence as an external service that they call as needed. 

The misuse of synthetic images and audio has advanced the furthest. Tools for face swapping, voice cloning, and photo manipulation are now inexpensive or completely free, including applications that turn an ordinary image into a nude figure. Fraudsters use them to pass off someone else's identity as their own, infiltrate companies, steal business information, or call families in an attempt to extort them.

Trend Micro adds that this is putting the very basis of identity verification under pressure. Companies will have to reconsider how they confirm communications and payments, because neither voice nor image proves anything on its own anymore.

Flashpoint's report links military operations in the Middle East to an increase in state-sponsored attacks. Supply chains, banks, and industrial control systems have become targets. Analysts discovered several types of destructive malware in these campaigns that do not encrypt data for ransom but destroy it outright.

Defenders still have the upper hand

David Sancho, who conducts threat research at the company, described the outlook for this year as gradual rather than catastrophic. According to him, there will be no sudden explosion of chaos driven by artificial intelligence. Instead, he expects slow and steady improvements to tools that already exist. Yet this is precisely how the underworld is becoming resilient to police intervention. Security companies still maintain an advantage in detection, threat intelligence, and automated incident investigation. However, this lead is shrinking because attackers are using the same technology more systematically than before, while protective measures sometimes lag behind the pace at which artificial intelligence is being adopted on the other side.

Sources: siliconangle.com and securitybrief.co.uk

Category:AI
Did you enjoy this article?
Discover more interesting posts on our blog
Back to blog

Related posts

Public Attitudes Toward AI in 2026: Asia Is Enthusiastic, Europe and America AnxiousPublic Attitudes Toward AI in 2026: Asia Is Enthusiastic, Europe and America Anxious
New data shows that AI is dividing the world: enthusiasm prevails in Asia, while Europe and America are gripped by anxiety. Even so, people expect it to have an ever-greater impact on life and work.
6 min read
21. 8. 2026
AI in IT Support Saves Hours, Yet Workloads Have IncreasedAI in IT Support Saves Hours, Yet Workloads Have Increased
AI in IT support demonstrably saves time, but also creates more work maintaining, monitoring, and fine-tuning systems. What matters is whether companies measure activity or actual impact.
3 min read
21. 8. 2026
Stripe Tells Investors It Is Buying OpenRouter and the Singularity Has BegunStripe Tells Investors It Is Buying OpenRouter and the Singularity Has Begun
Stripe is acquiring OpenRouter for billions to accelerate AI deployment. It also surprised investors by claiming that the technological singularity has already begun.
5 min read
21. 8. 2026
Přihlaste se k odběru našeho newsletteru
Zůstaňte informováni o nejnovějších příspěvcích, exkluzivních nabídkách, a aktualizacích.
CodedTrip

Operated by CodedTrip LLC, USA.

YouTube
TikTok