MessiahGPT: A New AI-Powered Threat Emerges in Cybercrime Underground
A newly uncovered criminal AI service, MessiahGPT, is being openly marketed on BreachForums as a purpose-built offensive tool capable of generating ransomware, phishing kits, stealers, crypters, and rootkits on demand. According to research from the Trellix Advanced Research Center, the service operates via a live platform at messiahgpt[.]de and an active Telegram community, targeting threat actors with no ethical or legal constraints.
Unlike typical jailbroken AI models, MessiahGPT’s operator claims it was trained from scratch with no safeguards no reinforcement learning from human feedback (RLHF), no constitutional AI layers, and no internal filters for harm or illegality. The training data reportedly includes unrestricted manuals, dark web archives, leaked documentation, and unfiltered internet scrapes, positioning it as a fully uncensored tool for malicious use.
The service employs a Mixture-of-Experts (MoE) architecture with 128 experts, though these technical claims remain unverified. What is confirmed is its low-friction commercial model: users get 50 free queries without registration, followed by paid plans starting at $8 per month (payable in cryptocurrency with no KYC). This pricing makes advanced malware generation accessible to low-skilled actors, eliminating the need for coding expertise or connections to malware-as-a-service vendors.
MessiahGPT’s advertised capabilities extend beyond malware, including social engineering scripts, fraud guides, data breach exploitation, physical attack planning, and even chemical/explosive synthesis. A benchmark table in its marketing materials compares it favorably to ChatGPT-4o, DeepSeek-V3, and Mistral-Large, positioning it as the only model that reliably produces usable malicious output without refusals.
The service is not alone in this space. Trellix also identified DarkGPT, a persistently advertised uncensored AI tool circulating in Russian-language Telegram channels. DarkGPT offers three free queries before paid tiers, promising unrestricted malicious code generation, custom hacker scripts, real-time exploit assistance, and 24/7 support marketed explicitly as "BlackHat AI" for darknet projects. While its true technical foundation remains unclear, its sustained promotion suggests strong demand in the cybercriminal ecosystem.
These developments reflect a broader 2026 shift toward commercialized criminal AI, where uncensored AI-as-a-service has evolved from informal Telegram bots into dedicated platforms with versioned websites, demo channels, and tiered pricing. Security researchers warn that AI-generated phishing lures, ransomware variants, and social engineering attacks will likely surge in volume and sophistication, challenging traditional signature-based detection and template-matching defenses. The rise of these tools underscores the growing accessibility of advanced cyber threats, lowering the barrier to entry for malicious actors.
Source: https://cybersecuritynews.com/messiahgpt-ai-tool/
Trellix TPRM report: https://www.rankiteo.com/company/trellixsecurity
BreachForums TPRM report: https://www.rankiteo.com/company/underdark-ai
"id": "undtre1786703238",
"linkid": "underdark-ai, trellixsecurity",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'industry': 'Cybercrime',
'location': 'Global (BreachForums, Telegram)',
'type': 'Cybercriminal ecosystem'}],
'attack_vector': ['AI-generated malware',
'Phishing kits',
'Social engineering scripts'],
'description': 'A newly uncovered criminal AI service, MessiahGPT, is being '
'marketed on BreachForums as an offensive tool capable of '
'generating ransomware, phishing kits, stealers, crypters, and '
'rootkits on demand. The service operates via a live platform '
'at messiahgpt[.]de and an active Telegram community, '
'targeting threat actors with no ethical or legal constraints. '
'It was trained from scratch with no safeguards, including '
'unrestricted manuals, dark web archives, and unfiltered '
'internet scrapes. The service employs a Mixture-of-Experts '
'(MoE) architecture and offers a low-friction commercial model '
'with paid plans starting at $8 per month. Additionally, '
'DarkGPT, another uncensored AI tool, is circulating in '
'Russian-language Telegram channels, offering similar '
'malicious capabilities.',
'impact': {'identity_theft_risk': ['Increased risk due to AI-generated '
'phishing and stealers'],
'payment_information_risk': ['Increased risk due to AI-generated '
'malware']},
'investigation_status': 'Ongoing',
'lessons_learned': 'The rise of commercialized criminal AI services like '
'MessiahGPT and DarkGPT highlights the growing '
'accessibility of advanced cyber threats, lowering the '
'barrier to entry for malicious actors and challenging '
'traditional detection methods.',
'motivation': ['Financial gain', 'Cybercrime enablement'],
'post_incident_analysis': {'corrective_actions': ['Develop AI ethics and '
'safety frameworks',
'Collaborate with law '
'enforcement to disrupt '
'cybercrime platforms',
'Invest in AI-driven threat '
'detection and response'],
'root_causes': ['Lack of safeguards in AI training '
'data',
'Commercialization of criminal AI '
'tools',
'Low-cost access to advanced '
'malware generation']},
'recommendations': ['Enhance signature-based and behavioral detection '
'mechanisms to counter AI-generated threats',
'Monitor dark web and Telegram channels for emerging '
'AI-powered cybercrime tools',
'Implement stricter controls on AI training data to '
'prevent misuse',
'Educate organizations on the risks of AI-generated '
'phishing and malware'],
'references': [{'source': 'Trellix Advanced Research Center'}],
'response': {'third_party_assistance': 'Trellix Advanced Research Center'},
'threat_actor': ['MessiahGPT operator', 'DarkGPT operator'],
'title': 'MessiahGPT: A New AI-Powered Threat Emerges in Cybercrime '
'Underground',
'type': ['AI-powered cybercrime tool', 'Malware-as-a-Service']}