Criminal AI tools are increasingly resembling commercial software.
Trellix researchers found MessiahGPT openly advertised on BreachForums as an unrestricted AI service for generating ransomware, phishing kits, malware, and social-engineering material. The platform has its own website and Telegram community, although researchers could not independently verify the operator’s claims about the model or its capabilities.
The packaging may be as significant as the technology itself: cybercrime-focused AI is being branded, compared against mainstream models, and sold as a dedicated service to attackers.
Marketing without the usual AI guardrails
In its research on weaponized AI, Trellix says MessiahGPT is presented as a custom model trained without Reinforcement Learning from Human Feedback or Constitutional AI. Its operator claims the training material includes dark-web archives, leaked documentation, and unrestricted manuals.
Researchers could not independently verify the technical claims, but the service is openly marketed to cybercriminals.
A comparison shown to prospective buyers pits the platform against ChatGPT-4o, DeepSeek-V3, and Mistral-Large based on whether each model will produce content in categories mainstream systems refuse. Its marketing uses unrestricted output as a selling point.

The research linked the advertisement to the live MessiahGPT website at messiahgpt.de. The public site now uses more conventional language, marketing coding, penetration testing, and OSINT even though researchers documented far more explicit criminal uses in its forum promotion.
Ransomware and phishing sit within a wider attack menu
Trellix lists complete and compilable ransomware, stealers, crypters, and rootkits among the advertised outputs. Phishing kit generation and social engineering scripts appear alongside fraud guidance and assistance for exploiting breached data.
Advertised capabilities span several parts of an intrusion, from approaching a victim to developing malicious code.
Criminal phishing kits increasingly operate like SaaS platforms. AI-powered cybercrime tools also expand the amount of offensive work attackers can automate or generate. MessiahGPT consolidates several of those functions into a single service.
Promotion extends outside private criminal groups. BreachForums advertising, a dedicated website, and a Telegram presence provide several access points for prospective users.
Security teams should restrict access and protect accounts
Block MessiahGPT’s domain through DNS filtering or secure web gateways if your organization has no approved reason to access it. Log attempted connections so visits from corporate devices can be reviewed.
If stolen credentials surface, invalidate compromised passwords quickly and protect privileged accounts with phishing-resistant MFA. Review unusual sign-ins involving sensitive systems as well, since a single valid account can open a path deeper into your environment.
Use EDR tools to watch what happens if malicious code reaches an endpoint. Behavioral monitoring can detect suspicious process activity even when files or scripts do not match known samples.
You cannot control who accesses criminal AI services outside your network, so focus your defenses on the points an attacker must still cross within it. Restrict unauthorized access, protect accounts, and monitor code execution before an intrusion spreads.
Related reading: An actively exploited SAP Commerce Cloud RCE flaw is putting unpatched environments at heightened risk.





