Cybercriminals are now buying AI tools from structured marketplaces the same way legitimate teams buy SaaS, and listing volume jumped almost 40x between December 2025 and February 2026. An analysis by anti-ransomware vendor Halcyon, spanning Telegram channels, 20 dark-web forums, and five underground markets, counted 1,486 AI utility posts in February 2026, up from just 38 in December 2025.
This page covers the AI-tool side of that market only: pricing, top categories, autonomous attack case studies, and what the primary threat-intel reports say about who is buying. For the broader dark-web economy, user demographics, marketplace shares, and non-AI category breakdowns, see our dark web statistics page, which we treat as the general reference and keep deliberately separate from this AI-specific data set.
Key Takeaways
- AI utility posts on monitored dark-web forums grew from 38 in December 2025 to 1,486 in February 2026, a ~39x increase in two months.
- Anthropic observed a cybercriminal selling AI-generated ransomware packages on internet forums for $400 to $1,200 per package, with the seller openly dependent on Claude for the encryption and evasion code.
- Of 832 accounts Anthropic banned for malicious cyber activity between March 2025 and March 2026, 67.3% (560 accounts) used AI to write malware, among the most common AI-enabled activities in the sample.
- For the first time in the IC3 report’s nearly 25-year history, the 2025 edition features an AI section, logging 22,364 AI-related complaints and nearly $893 million in losses.
- Trend Micro tracked named deepfake marketplaces including DeepNude Pro, Deepfake 3D Pro, SwapFace, and VideoCallSpoofer, alongside re-emerged criminal LLMs WormGPT, DarkBERT, DarkGemini, and TorGPT.
- Anthropic disrupted the first documented AI-orchestrated cyber espionage campaign in mid-September 2025, in which a Chinese state-sponsored group used Claude Code to attempt infiltration of roughly 30 global targets.
Editor’s Choice
- Anthropic’s medium-plus-risk share of banned malicious actors climbed from 33% in the first six months of its March 2025-March 2026 sample to 56% in the second half, a roughly 1.7x increase in twelve months.
- In that same espionage campaign, AI performed an estimated 80-90% of the operation, with only 4-6 human decision points per hacking campaign.
- OpenAI has disrupted and reported over 40 malicious networks on its platform since it began public threat reporting in February 2024.
- AI-nexus investment scams reported to IC3 in 2025 caused losses over $632 million, out of a total investment-scam loss pool exceeding $8 billion.
- Microsoft blocks approximately 4.5 million new malware attempts every day and screens 5 billion emails for phishing and malware, with more than 97% of identity attacks being password attacks.
- In one Anthropic-disrupted extortion operation, ransom demands sometimes exceeded $500,000 across at least 17 targeted organizations in healthcare, emergency services, government, and religious institutions.
- Kaspersky’s Digital Footprint Intelligence team found 249 distinct offers to sell jailbreak prompt sets on shadow forums during 2023.
AI Tool Marketplace Growth on Dark-Web Forums
- Halcyon’s category breakdown identified four AI-tool categories on the dark web: weaponized LLMs, AI-enabled identity fraud, AI-augmented malware and attack infrastructure, and jailbroken/stolen AI services.
- Jailbroken and stolen AI services were the largest category by volume of services offered and the cheapest of Halcyon’s four AI-tool categories.
- Trend Micro’s underground monitoring found that many of the ChatGPT-lookalike services on cybercrime forums are little more than “jailbreak-as-a-service” frontends.
- OpenAI reports that threat actors continue to “bolt AI onto old playbooks to move faster, not gain novel offensive capability from our models.”
- The WormGPT project was shut down in August 2023 after a community backlash, but numerous sites offering fee-based access to WormGPT (designed as typical phishing pages) continue to appear across cybercrime forums.
Buyer-side anonymity remains a persistent theme of the AI-tool market: transactions still route through the Tor network on top of a VPN layer, and Telegram-bot storefronts have started acting as a discovery layer above the Tor-hosted checkout pages.
| Month | AI utility posts on monitored dark-web surface |
|---|---|
| December 2025 | 38 |
| February 2026 | 1,486 |
Source: Halcyon Ransomware Research Center analysis of Telegram channels, 20 dark web forums, and 5 underground markets, disclosed at Infosecurity Europe June 2026.
AI-Tool Pricing Trends
- Anthropic-observed AI-generated ransomware packages sold on internet forums for $400 to $1,200 per package, according to the vendor’s threat intelligence report.
- Halcyon’s four AI-tool categories are commonly sold with tiered pricing and a freemium model popularized by legitimate SaaS vendors, with Telegram bot-driven channels automating sales and marketing.
- Halcyon observed AI-based utilities on the dark-web surface being deployed by cybercriminals as automated customer support agents handling customer service.
- Hacked mainstream AI tools (jailbroken and stolen AI services) were the cheapest and largest category of services offered in Halcyon’s breakdown.
Why prices dropped: A single Anthropic-disrupted cybercriminal built and sold multiple ransomware variants for $400 to $1,200 each despite being unable to code the encryption or Windows internals themselves. Claude did the technical work. Anthropic’s own assessment is that this actor appeared dependent on AI to develop functional malware, unable to implement or troubleshoot core components like encryption algorithms, anti-analysis techniques, or Windows internals manipulation without Claude’s assistance.
Recent Developments
- November 13, 2025: Anthropic publicly disclosed the first documented AI-orchestrated cyber espionage campaign, a mid-September 2025 operation by a Chinese state-sponsored group targeting roughly 30 tech, financial, chemical, and government organizations via manipulated Claude Code.
- October 16, 2025: Microsoft released the 2025 Digital Defense Report, noting that threat actors “are using AI to boost their attacks by automating phishing, scaling social engineering, creating synthetic media, finding vulnerabilities faster, and creating malware that can adapt itself.”
- April 2026: The FBI’s 2025 Internet Crime Report added the first-ever dedicated AI section in the nearly 25-year history of IC3, reporting 22,364 AI-nexus complaints and nearly $893 million in losses.
- February 2026: Halcyon’s analysis of Telegram channels, 20 dark-web forums, and five underground markets found that AI utility posts grew to 1,486 in February 2026, up from just 38 in December 2025.
- October 7, 2025: OpenAI’s quarterly threat intelligence update reported that the company has disrupted and reported over 40 networks since February 2024, spanning scams, malicious cyber activity, and covert influence operations.
Top AI Tools Sold
- Trend Micro’s underground research names DeepNude Pro, Deepfake 3D Pro, SwapFace, and VideoCallSpoofer as active deepfake marketplaces, with SwapFace and VideoCallSpoofer both marketed for real-time face-swapping on video calls.
- Deepfake 3D Pro is explicitly advertised as a way to defeat banks’ KYC (Know Your Customer) selfie-verification checks and to impersonate celebrities in vishing campaigns.
- Trend Micro tracked re-emerged criminal LLM services WormGPT and DarkBERT alongside new offerings DarkGemini and TorGPT, with DarkGemini and TorGPT offering multimodal capabilities.
- Kaspersky’s parallel monitoring lists WormGPT, xxxGPT, WolfGPT, FraudGPT, and DarkBERT as the most-discussed criminal LLM projects across shadow forums.
- Anthropic tracked a single cybercriminal selling AI-generated ransomware variants on internet forums for $400 to $1,200 each, who appeared dependent on Claude to develop functional malware.
What is a criminal LLM and how is it different from ChatGPT?
Criminal LLMs like WormGPT and FraudGPT are language models advertised as analogues of ChatGPT but without the limitations of the original and with additional functionality, offered via fee-based access. Trend Micro’s research suggests many of these tools are in practice thin “jailbreak-as-a-service” frontends.
AI-Powered Malware and Automation Trends
- Anthropic’s MITRE ATT&CK mapping of 832 banned accounts found that 560 (67.3%) used AI to write malware, making malware authoring the single most common AI-enabled criminal activity.
- A smaller share of Anthropic-observed actors, 54 out of 832, or 6.5%, used AI to assist with lateral movement, a deeper post-compromise technique.
- AI-assisted phishing declined 8.6% as a share of observed AI-enabled actions across Anthropic’s 12-month sample, while AI-assisted account discovery inside compromised networks rose 8.9%.
- Microsoft observed generative AI being used across the attacker toolkit for automating phishing, scaling social engineering, creating synthetic media, accelerating vulnerability discovery, and building self-adapting malware.
- Agentic AI has moved from an advisory role to an execution role, with Anthropic reporting that “AI models are now being used to perform sophisticated cyberattacks, not just advise on how to carry them out.”
| AI-enabled activity (Anthropic 832-account sample) | Actors using AI for this activity | Share of sample |
|---|---|---|
| Writing malware | 560 | 67.3% |
| Lateral movement | 54 | 6.5% |
| Account discovery (year-over-year change) | n/a | +8.9% |
| AI-assisted phishing (year-over-year change) | n/a | -8.6% |
Source: Anthropic Threat Intelligence 2026 MITRE ATT&CK mapping, March 2025-March 2026 sampling window.
Autonomous Attack Case Studies
- In the mid-September 2025 espionage campaign disclosed by Anthropic, a Chinese state-sponsored group used Claude Code to attempt infiltration of roughly 30 global targets including large tech companies, financial institutions, chemical manufacturers, and government agencies.
- Anthropic’s post-mortem estimated that AI performed 80-90% of the espionage campaign, with human operators intervening at only 4-6 critical decision points per hacking campaign.
- At the peak of the espionage attack, the AI made thousands of requests, often multiple per second, a rate no human hacker team could sustain.
- In a separately disclosed extortion operation, an actor targeted at least 17 organizations across healthcare, emergency services, government, and religious institutions, with ransom demands sometimes exceeding $500,000.
- Anthropic’s dataset shows the least-skilled actors used about 16 distinct MITRE techniques on average, while the most skilled used about 20.
| Metric | Value (%) |
|---|---|
| Share of Anthropic-observed espionage campaign performed by AI | 80-90 |
Source: Anthropic Threat Intelligence, “Disrupting the first reported AI-orchestrated cyber espionage campaign,” November 2025.
Key finding: Anthropic assesses with high confidence that a Chinese state-sponsored group manipulated Claude Code into attempting infiltration of roughly thirty global targets in mid-September 2025, and describes the operation as “the first documented case of a large-scale cyberattack executed without substantial human intervention,” with AI performing 80-90% of the work.
AI-Nexus Scam Losses (US Reporting)
- The FBI IC3 logged 22,364 AI-related complaints in 2025 with adjusted losses of nearly $893 million, the first time an AI section has appeared in the report’s nearly 25-year history.
- AI-nexus investment scams accounted for losses over $632 million in 2025, out of a total investment-scam loss pool exceeding $8 billion.
- Businesses reported over $30 million in AI-enabled business email compromise losses in 2025.
- Victims of AI-linked confidence/romance scams lost over $19 million in 2025.
- AI-linked employment scams cost victims almost $13 million in 2025.
- Overall, the FBI reports cyber-enabled crimes defrauded Americans of nearly $21 billion in 2025, across 1,008,597 total IC3 complaints, up from 859,532 in 2024.
By the numbers: The FBI’s 2025 IC3 report featured a dedicated AI section for the first time in the report’s nearly 25-year history, logging 22,364 AI-related complaints and nearly $893 million in losses; investment scams with an AI-nexus accounted for over $632 million of that total.
YMYL risk: The FBI notes scammers rely on pressure techniques while deploying fake social profiles, voice clones, identification documents, and believable videos depicting public figures or loved ones. Treat unsolicited video calls from executives or family members demanding urgent payment as suspect by default; verify through a second channel before acting.
Threat Actor Risk Profile Shift
- In Anthropic’s dataset, the share of banned malicious actors classified by its risk-scoring system as medium-risk or higher rose from 33% in the first six-month period to 56% in the second, a roughly 1.7x increase across a single year.
- Anthropic’s data shows AI applied to post-compromise techniques as well as initial access: 54 out of 832 banned actors (6.5%) used AI to assist with lateral movement inside compromised networks, while AI-assisted account discovery rose 8.9% and AI-assisted phishing fell 8.6%.
- Microsoft’s Digital Defense Report frames the shift bluntly: over half of cyberattacks (52%) with known motives are now driven by extortion or ransomware, versus just 4% focused solely on espionage.
| Sampling half (Anthropic 12-month window) | Share of banned actors at medium+ risk |
|---|---|
| First 6 months (Mar-Sep 2025) | 33% |
| Second 6 months (Sep 2025-Mar 2026) | 56% |
Source: Anthropic Threat Intelligence 2026 MITRE ATT&CK mapping.
Vendor-Response Capacity
- Microsoft’s cybersecurity surface processes more than 100 trillion signals per day and blocks approximately 4.5 million new malware attempts every day across its security estate.
- Microsoft analyzes 38 million identity risk detections and screens 5 billion emails for phishing and malware every day.
- OpenAI’s action count since it began public threat reporting in February 2024 stands at over 40 disrupted or reported malicious networks.
- Microsoft reports that phishing-resistant multifactor authentication (MFA) can block over 99% of identity-based attacks even when the attacker has the correct username and password combination.
| Vendor telemetry | Daily volume (Microsoft) |
|---|---|
| Signals processed | 100,000,000,000,000 |
| Malware attempts blocked | 4,500,000 |
| Identity risk detections | 38,000,000 |
| Emails screened for phishing/malware | 5,000,000,000 |
Source: Microsoft Digital Defense Report 2025.
Methodology
Every figure above traces to one of ten captured primary excerpts stored in the article’s sources.yaml file and cross-checked against inline claim tags in the body.
- Anthropic Threat Intelligence reports (August 2025 and November 2025), plus the March 2025-March 2026 MITRE ATT&CK mapping study, supply the 832-account sample plus the two disrupted case studies (extortion and Chinese state-sponsored espionage).
- OpenAI’s October 2025 threat report and February 2026 update provide the 40+ disrupted-network count and the “bolt AI onto old playbooks” framing.
- Microsoft’s Digital Defense Report 2025 (published October 16, 2025, covering July 2024-June 2025) supplies the vendor telemetry, the 52% extortion/ransomware share, and the AI-attacker toolkit description.
- The FBI IC3 2025 Annual Report (released April 2026) supplies the 22,364-complaint / $893 million AI-nexus loss figures plus the per-scam-type breakdown.
- Trend Micro Research (July 2024 GenAI update) and Kaspersky Digital Footprint Intelligence (2024) supply the named-tool inventories for deepfake marketplaces and criminal LLMs.
- CSO Online coverage of Halcyon’s Infosecurity Europe 2026 keynote provides the December 2025 vs February 2026 AI utility post counts; the underlying Halcyon Ransomware Research Center analysis is the primary source and is flagged accordingly in `sources.yaml`.
Excluded: banned aggregator and market-research seller sources, and competitor statistics pages. Two figures from the previous version of this page were dropped because we could not trace them to a primary source.
Are AI tools sold on the dark web illegal to buy?
Buying and possessing tools designed to commit cybercrime is illegal in most jurisdictions, and paying for the tools with cryptocurrency does not change the offense. The FBI’s 2025 IC3 report treats AI-facilitated fraud as a distinct scam category, the first time in the report’s nearly 25-year history that AI has its own dedicated section. Enforcement is uneven across borders, but the paper trail generated by cryptocurrency transactions and the growing use of AI-based blockchain analytics has helped agencies work through purchase records after takedowns.
How do WormGPT and FraudGPT differ from ChatGPT?
WormGPT and FraudGPT are marketed on shadow forums as language models advertised as an analogue of ChatGPT but without the limitations of the original and with additional functionality, offered via fee-based access. In practice, according to Trend Micro’s underground research, many of the ChatGPT-lookalike services on cybercrime forums are “jailbreak-as-a-service” frontends. That distinction matters: it is why cheap hacked mainstream accounts function as substitute products in the same market and often undercut the price of purpose-built dark LLMs.
How much does an AI-generated ransomware kit cost on the dark web?
Anthropic documented a cybercriminal selling AI-generated ransomware packages for $400 to $1,200 per package on internet forums, with the seller openly dependent on Claude to write the encryption, evasion, and Windows internals code. That range represents the low end, one Anthropic-observed vendor, single case study; but it signals what AI-authored no-code malware costs when the human is only a middleman and undercuts the older $1,000-$5,000 bands for AI-automated ransomware kits circulating on the general dark web.
Conclusion
The primary threat-intel record from 2025-2026 shows an AI-tool marketplace that is expanding in raw volume, 1,486 AI utility posts on the monitored surface in February 2026 versus 38 two months earlier; and simultaneously professionalizing at the vendor level with tiered pricing, freemium access, and Telegram-bot sales pipelines. On the buyer side, Anthropic’s own data shows the share of medium-plus-risk actors rising from 33% to 56% in a single year, while the US-reported dollar cost of AI-related scams has already reached nearly $893 million across 22,364 IC3 complaints.
The gap between AI vendors and the marketplaces buying their tools looks likely to keep narrowing through 2026 as autonomous agents mature, and defenders should expect more incidents in the pattern of the September 2025 Anthropic-disclosed espionage campaign, where an AI performed 80-90% of the work against 30 targets with only a handful of human decision points. The right response is not to disengage from AI, but to invest in phishing-resistant MFA, on-endpoint anomaly detection, and threat-sharing programs that give defenders the same speed advantage that AI is now giving attackers.