Security2 publishers3 min readPublished
Luciferus sells uncensored malware generation on the Exploit forum starting at $35 a month
Sophos's Counter Threat Unit found the advertisement on August 24. The cheapest tier answered a direct request for a Python remote access trojan with source code, and the service runs on a local model no provider can patch.
The Watch · Security desk
What happened
- Sophos's Counter Threat Unit saw a persona called Optimus_Prime advertise Luciferus, an uncensored AI subscription service, on the Exploit underground forum on August 24, 2026.
- The advertisement says the service answers requests without moral or ethical restrictions and claims it is based on a proprietary model with 120 billion parameters.
- The forum ad prices three monthly tiers, Inquisitor at $35, Archdeviel at $55 and Prince of Darkness at $75, plus an Individual Embodiment VIP level quoted on request.
- The Luciferus website carries different tier names and lower prices, Junior at $22, Middle at $34.75 and Pro at $47.14, and omits the VIP option entirely.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Provider-side patching has no effect on this buyer: nothing OpenAI or Anthropic ships degrades a locally hosted uncensored model, so removal depends on the seller's infrastructure.
- cost At $264 a year for the cheapest tier, malware code on demand sits inside the budget of an actor with no development skill, and the seller collects recurring revenue whether or not the output ever works.
- capability The Individual Embodiment tier offers dedicated compute and models trained on the buyer's own data. A crew could tune output to its own targets on hardware shared with no other customer.
- contradiction Two price lists for one product, flagged by Sophos without explanation, leave buyers and trackers unable to say which storefront is the operating one.
Divide each website price by its forum counterpart and the same figure comes back three times: $22 against $35 is 0.63, $34.75 against $55 is 0.632, $47.14 against $75 is 0.629 [21]. The website list looks like the forum list run through one multiplier. Sophos flagged the mismatch in names and prices and did not explain it [9].
For a defender the difference that counts sits upstream of the price. According to Help Net Security's account of the Sophos research, jailbroken builds of ChatGPT or Claude lose their restrictions the moment a vendor patches them, while tools built without safeguards from the start give sellers a longer shelf life [15]. Sophos describes services of this kind as designed or configured without safeguards from the outset, which the researchers tie to greater control, persistence, and the ability to tailor capabilities to specific user communities [14]. "Luciferus appears to be a more stable option that relies on an uncensored local LLM instead of jailbreaking a mainstream LLM provider," CTU researchers wrote [13]. A patch shipped by a mainstream provider costs this seller nothing.
Everything the advertisement says about the model itself is unverified. CTU did not check the architecture, the parameter count, the performance or the privacy claims, and it puts only low confidence on its own assessment that Alibaba's Qwen family is underneath [4][5]. The researchers were blunt about the proprietary-model claim: "Proprietary model claims can be misleading, as many of the services are likely based on fine-tuned open-source models, custom system prompts, or orchestration layers rather than entirely new foundation models. Training a genuinely novel LLM requires significant expertise, data, and computing resources," they wrote [16].
The test result is narrow. The Junior tier answered a prompt for a simple Python RAT with a Russian-language description of its networking and command execution functions, then source code, which Sophos says supports the ad's claim that the service will respond to overt malware requests [10]. CTU stopped short of running the code or checking whether it was complete [11]. Sophos did not report how many subscribers the service has.
Optimus_Prime has a thin record on the forum: 21 posts in the 139 days between joining on April 18 and September 4, about one a week [2][22]. The category around the persona is busier. WormGPT and FraudGPT were sold the same way, as unrestricted ChatGPT alternatives for phishing emails, BEC lures, malicious scripts and malware code [17], and CTU also tracks brokered access to legitimate AI platforms, shared API keys, prompt-engineering services and multi-model packages [18]. Posts advertising AI-enabled services are increasing, alongside dedicated AI discussion channels and recruitment aimed at AI specialists [19].
At $22 a month the cheapest tier runs $264 a year; the top forum tier at $75 runs $900 [23]. "These developments suggest that AI is an increasingly accessible component of the cybercrime ecosystem, lowering barriers to entry and enabling less technically skilled actors to access capabilities that were previously limited to experienced developers," Sophos wrote [20].
What to watch
- Whether anyone obtains a sample and tests the 120-billion-parameter claim or the low-confidence Qwen attribution.
- Whether the website storefront and the forum tier list converge, or one of them goes dark. Either outcome would show which channel is live.
- Whether other Exploit sellers copy the Individual Embodiment offer of dedicated compute and training on buyer-supplied data.