Hackers Advertise Uncensored Luciferus AI Service on Underground Forums

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Hackers are advertising a new “uncensored” artificial intelligence service called Luciferus, positioning it as a subscription assistant willing to process malware-development requests that mainstream AI systems would reject.

Sophos Counter Threat Unit (CTU) researchers discovered the offering on August 24, 2026, on the Exploit underground forum. It targets criminal customers seeking fewer technical and operational constraints.

The advertisement was published by a forum persona named “Optimus_Prime,” whose profile carries a “coding / coder” activity label. The account joined Exploit on April 18 and had made 21 posts by September 4.

Hackers Advertise Luciferus AI Service

According to the promotional message, Luciferus operates without moral or ethical restrictions and uses a supposedly proprietary model containing 120 billion parameters.

Exploit forum listing (Image Source: Sophos)

CTU could not independently verify the architecture, parameter count, performance, privacy, or advertised capabilities. However, with low confidence, analysts assessed that the service may be built on Qwen, Alibaba’s family of large language models, according to Sophos.

Illicit AI operators often market products as original technology although they may rely on fine-tuned open-source models, custom prompts or orchestration layers.helpnetsecurity

The Exploit advertisement offers three monthly plans: Inquisitor for $35, “Archdeviel” for $55, and Prince of Darkness for $75.

An “Individual Embodiment” VIP package promises a separately deployed personal model, training on customer data, dedicated computing resources, and control over context and response temperature. Pricing for that tier reportedly depends on individual requirements.

However, the public-facing Luciferus website presents a different commercial structure. It lists Junior at $22, Middle at $34.75, and Pro at $47.14, while making no mention of the VIP package. Sophos gave no explanation for the discrepancy.

Subscription portal tiers (Image Source: Sophos)

More significantly, researchers tested whether Luciferus would respond to an explicit malware request. When prompted to produce a “simple RAT in python,” the Junior model returned a Russian-language description of a basic remote access trojan, outlined networking and command-execution functionality, and then supplied source code.

CTU did not execute the output or assess whether the code was complete or functional, so the test demonstrates willingness to assist rather than proven malware quality.

Luciferus differs from jailbroken versions of ChatGPT or Claude, which depend on bypassing safeguards that providers can update or restore. A locally operated or deliberately unrestricted model could give its controllers greater persistence, customization and independence from mainstream platform enforcement.

Still, the “proprietary” label should be treated cautiously because training a genuinely new foundation model demands substantial computing infrastructure, specialist expertise and large datasets.

The service follows WormGPT and FraudGPT, underground tools marketed for phishing emails, business email compromise lures, malicious scripts and malware code.

Sophos previously noted both proliferating GPT derivatives and criminal-forum skepticism that some products may be scams, wrappers or overhyped services.

Luciferus also reflects a shift from experimentation to structured commercialization. Trellix reported in August that criminal AI offerings increasingly resemble mature software businesses, with tiered pricing, support channels and maintained services spanning attack planning, payload evasion and access to stolen AI accounts.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Hackers Advertise Uncensored Luciferus AI Service on Underground Forums appeared first on Cyber Security News.