Sophos, Exploit and Alibaba: Luciferus Uncensored AI Advertised on Hacker Forums for Malware and RAT Development

Sophos, Exploit and Alibaba: Luciferus Uncensored AI Advertised on Hacker Forums for Malware and RAT Development

New "Uncensored" AI Service *Luciferus* Emerges as Malware-as-a-Service Threat

On August 24, 2026, researchers from Sophos’ Counter Threat Unit (CTU) uncovered a new AI-driven cybercriminal service, Luciferus, advertised on the Exploit underground forum. Marketed as an "uncensored" alternative to mainstream AI platforms, the subscription-based tool is designed to generate malicious code, attack guidance, and other cybercriminal resources without ethical or operational restrictions.

The service was promoted by a forum user under the alias Optimus_Prime, whose account created on April 18, 2026 had posted 21 times by September 4. The advertisement claims Luciferus operates on a proprietary 120-billion-parameter model, though Sophos could not independently verify its architecture, performance, or privacy safeguards. Researchers suspect it may rely on Alibaba’s Qwen large language models, a common tactic among illicit AI services that rebrand fine-tuned open-source models as proprietary.

Luciferus offers multiple subscription tiers, with forum pricing ranging from $35 to $75 per month, including a VIP "Individual Embodiment" package promising a dedicated, customer-trained model. However, the public-facing website displays different pricing ($22–$47.14) and omits the VIP option, leaving discrepancies in advertised features.

During testing, Sophos researchers requested a "simple RAT in Python" from the Junior tier, which returned a Russian-language description and source code for a basic remote access trojan. While the code’s functionality was not validated, the test confirmed the model’s willingness to assist in malware development.

Unlike jailbroken versions of mainstream AI tools which vendors can patch Luciferus and similar services (e.g., WormGPT, FraudGPT) provide cybercriminals with persistent, unrestricted access to AI-driven attack tools. The emergence of Luciferus underscores the growing commercialization of criminal AI ecosystems, where tiered subscriptions and dedicated support mirror legitimate SaaS models.

Source: https://cyberpress.org/cybercriminals-advertise-uncensored-luciferus-ai/

The Exploit Database cybersecurity rating report: https://www.rankiteo.com/company/the-exploit-database

Sophos cybersecurity rating report: https://www.rankiteo.com/company/sophos

Tongyi Lab cybersecurity rating report: https://www.rankiteo.com/company/alibaba-tongyi-lab

"id": "THESOPALI1789539835",
"linkid": "the-exploit-database, sophos, alibaba-tongyi-lab",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'industry': 'Cybersecurity',
                        'name': 'Sophos (research entity)',
                        'type': 'Cybersecurity Firm'},
                       {'industry': 'Technology/AI',
                        'name': 'Alibaba (suspected model source)',
                        'type': 'Technology Company'},
                       {'name': 'Potential victims of *Luciferus*-generated '
                                'malware',
                        'type': 'General Public/Organizations'}],
 'attack_vector': 'AI-driven malicious code generation, underground forum '
                  'advertisement',
 'date_detected': '2026-08-24',
 'date_publicly_disclosed': '2026-08-24',
 'description': 'Researchers from Sophos’ Counter Threat Unit (CTU) uncovered '
                'a new AI-driven cybercriminal service, *Luciferus*, '
                'advertised on the Exploit underground forum. Marketed as an '
                "'uncensored' alternative to mainstream AI platforms, the "
                'subscription-based tool is designed to generate malicious '
                'code, attack guidance, and other cybercriminal resources '
                'without ethical or operational restrictions.',
 'investigation_status': 'Ongoing',
 'lessons_learned': 'The emergence of *Luciferus* highlights the growing '
                    'commercialization of criminal AI ecosystems, where tiered '
                    'subscriptions and dedicated support mirror legitimate '
                    'SaaS models. It underscores the need for vigilance '
                    'against AI-driven cybercriminal tools and the persistence '
                    'of unrestricted access to such services.',
 'motivation': 'Financial gain, provision of cybercriminal tools',
 'post_incident_analysis': {'root_causes': 'Rebranding and fine-tuning of '
                                           'open-source AI models (e.g., '
                                           'Alibaba’s *Qwen*) for malicious '
                                           'purposes, lack of ethical '
                                           'restrictions in AI-driven '
                                           'cybercriminal services.'},
 'recommendations': 'Organizations should monitor underground forums for '
                    'emerging threats, enhance AI model security to prevent '
                    'misuse, and educate stakeholders on the risks of '
                    'AI-driven cybercriminal services.',
 'references': [{'date_accessed': '2026-09-04',
                 'source': 'Sophos’ Counter Threat Unit (CTU)'},
                {'date_accessed': '2026-09-04',
                 'source': 'Exploit underground forum'}],
 'threat_actor': 'Optimus_Prime (alias), associated with *Luciferus* service',
 'title': "Emergence of 'Luciferus' AI-Driven Malware-as-a-Service Threat",
 'type': 'Malware-as-a-Service (MaaS)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.