Cheap Criminal AI Service Resells Bypassed Models
Researchers find Kriminal AI service routes requests through Grok, Claude, and others via jailbreaks for as little as $12.99 a month.
Security researchers have uncovered a commercial AI service that wraps legitimate language models in jailbreak prompts and resells their uncensored output to criminals. The service, called Kriminal, is openly advertised on the clearnet and priced to undercut typical enterprise AI subscriptions.
ThreatDown's analysis, shared with CSO ahead of its Wednesday publication, describes Kriminal as a storefront that borrows the underlying capabilities of models from xAI, Anthropic, and others, routing requests through them while bypassing their built-in safety restrictions.
Jailbreak Wrapper in Plain Sight
ThreatDown examined Kriminal's production JavaScript and found no evidence of a proprietary foundation model. Instead, the code shows the service forwards requests to several established providers, adding a system prompt designed to override their guardrails.
The service identifies xAI's Grok as the primary inference engine for chat and agent runs. OpenRouter provides access to specialist models including Mistral Large and Llama 3.3, while Anthropic's Claude is offered for long-context analysis. Tavily supplies live web search. The service itself is hosted through Google Cloud and Cloudflare, and NowPayments handles its crypto checkout.
When researchers asked Kriminal to identify its underlying model, its default NEXUS persona identified itself as Grok, matching the provider information found in the code.
A Subscription for Offense
Kriminal's pricing illustrates how quickly sophisticated capabilities have been commoditized. Its cheapest paid tier starts at $12.99 a month, while the top GHOST tier costs $99. The paid tier offers roughly 200 to 1800 messages per month, with individual services including OSINT dossiers, blockchain analysis, unrestricted code generation, and access to an in-browser Python and JavaScript sandbox.
The service's offerings include exploit development, OSINT, on-chain tracing, social engineering, and code generation. It is publicly accessible on the clearnet, indexed by Google, and presented like a conventional SaaS product, featuring pricing tiers, usage statistics, and a crypto payment system.
Agent Personas for Hire
In its premium GHOST tier, Kriminal packages its capabilities into four named agent personas. PHANTUM is designed for “financial intelligence” and asset tracing, ARCHITECT for exploit research and offensive code, ORACLE for document and intelligence analysis, and WRAITH for social engineering, persona crafting, and identity construction.
The researchers said they were able to corroborate many of the technical findings from their code analysis by questioning the service itself, as if the model was designed to spill every secret AI models aren’t supposed to talk about, including its own intent.
Borrowed Power, Real Risk
Aviv Nahum, co-founder and CEO at Above Security, said the important takeaway is that there may be considerably less “criminal AI” underneath Kriminal than its branding suggests.
“The underlying capability is becoming a commodity.”
— Aviv Nahum, co-founder and CEO at Above Security
Nahum added that organizations cannot outsource their security strategy to the guardrails of AI providers, since attackers will jailbreak models, proxy access to them, use open models locally, or simply move between providers. Defenders must assume that increasingly capable AI will be available to both sides, he noted.
Fighting Fire With Fire
Diana Kelley, Chief Information Security Officer at Noma Security, framed the development as a turning point in cyber offense economics.
“This is a bellwether for a broader shift in cyber offense.”
— Diana Kelley, Chief Information Security Officer at Noma Security
Kelley said that as advanced offensive capability becomes cheaper and more accessible with AI, attackers can find and exploit weaknesses at a speed and scale that tilt the economics of cybercrime in their favor. She added that CISOs need to fight fire with fire, use advanced AI to uncover risk and exposure, and eliminate years of tolerated security debt before cybercriminals weaponize it.
Why It Matters
Kriminal is a reminder that the frontier of criminal AI isn't always a bespoke, dark-web model. Often it's a repackaging of the same powerful tools legitimate businesses rely on, stripped of their safety layers and sold at consumer prices.
For defenders, the implication is clear: the same AI that can accelerate development, analysis, and automation is now equally available to those looking to exploit it. The economics of cybercrime are shifting, and security teams can no longer assume the other side is working with inferior tools.
As Nahum put it, the underlying capability is becoming a commodity. The question is not whether attackers will have access to capable AI, but how quickly organizations adapt to an environment where both sides wield it.
Sources
- CSO Online Original source
- SaaS Also reporting
Continue Reading
Malicious Firefox Add-ons Target Web3 Wallets
Researchers found 40 malicious Firefox extensions impersonating Web3 products to steal wallet secrets.
Manic malware taps nearby devices to steal data
New Android malware Manic can exfiltrate data through nearby infected devices using Wi-Fi Direct or Bluetooth.
Feds: AI-Assisted Attacks on Critical PLCs Are Here
Government agencies warn of active exploitation of Siemens S7 controllers using AI-generated attack code.