Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-enabled-threat-activitycybercrime-service-ecosystemphishing-campaign-intelligenceloader-delivery-mechanism

AI-Powered Hacking Tools Proliferate on the Dark Web

Updated 2mo agoFirst seen Nov 26, 20253 sources

A growing underground market for AI-powered hacking tools is emerging on dark web forums, according to research from Palo Alto Networks' Unit 42. These tools, including commercialized versions like WormGPT and free models such as KawaiiGPT, are designed to assist cybercriminals with tasks such as vulnerability scanning, data encryption, and generating malicious code. The accessibility and user-friendly nature of these large language models (LLMs) are significantly lowering the technical barriers for cybercrime, enabling even unskilled individuals to create attack scripts and conduct cyberattacks using simple conversational prompts.

While the technical sophistication of these "dark LLMs" remains limited, their primary impact is in democratizing cybercrime by empowering low-level hackers and script kiddies. The tools are particularly useful for generating grammatically correct phishing emails and basic malware, especially for users operating across language barriers. Despite initial fears of highly advanced AI-driven cyberattacks, current evidence suggests that these models are more effective at aiding petty criminals than enabling complex, autonomous cyber operations.

Share:
AI-Powered Hacking Tools Proliferate on the Dark Web
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Apr 14, 20262mo ago

Academic study analyzes cybercriminal discussions of AI use

An academic paper examined more than 160 cybercrime forum conversations collected over seven months to assess how offenders discuss and experiment with AI. The study found growing interest in both legitimate AI services and bespoke criminal tools, alongside skepticism about effectiveness, operational security risks, and disruption to existing criminal business models.

How Hackers Are Thinking About AI - Schneier on Security
Nov 26, 20257mo ago

Researchers assess dark LLMs as low-skill enablers, not a major leap

In its analysis, Unit 42 concluded that so-called dark LLMs mainly help low-level criminals and non-native speakers create basic malware and more polished phishing content, rather than enabling sophisticated new attacks. The report said most outputs remain generic and detectable with existing defenses, with the main risk being lowered barriers to entry and easier attack-script creation through conversational prompts.

Unit 42 observes dark-web market for AI-powered hacking tools

Palo Alto Networks' Unit 42 documented an emerging underground market on dark web forums for custom, jailbroken, and open-source LLMs marketed for cybercriminal tasks such as phishing, malware generation, vulnerability scanning, and data encryption. Researchers found both commercial and free offerings, including subscription-based WormGPT variants and the free KawaiiGPT model.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Malware
2 linked
Organizations
5 linked
Check Point Software TechnologiesWormGPT.AIKawaiiGPTPalo Alto NetworksPalo Alto Networks' Unit 42
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

AI-Powered Hacking Tools Proliferate on the Dark Web | Mallory