惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
博客园 - 司徒正美
Last Week in AI
Last Week in AI
博客园 - 聂微东
Jina AI
Jina AI
月光博客
月光博客
爱范儿
爱范儿
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
T
Tailwind CSS Blog
博客园 - 【当耐特】
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Apple Machine Learning Research
Apple Machine Learning Research
有赞技术团队
有赞技术团队
罗磊的独立博客
小众软件
小众软件
雷峰网
雷峰网
IT之家
IT之家
大猫的无限游戏
大猫的无限游戏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
Visual Studio Blog

Sophos Blogs

Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation 2026 MSP Perspectives Report: How MSPs Are Scaling Cybersecurity Leadership Sophos Next-Gen SIEM Unifies Security Operations and Compliance Messageboards Are All They Need ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split “Eye” spy: Cyclops Blink returns with extended capabilities Ransomware in Education 2026: Key Findings Sophos Joins OpenAI’s Call for Collective Cyber Defense Sophos Ranked #1 Overall Across Endpoint, XDR, MDR, and Firewall in G2 Fall 2026 Reports Fake AI, real malware: Attackers impersonating AI brands A heap of overflow in August’s Patch Tuesday haul Accelerating NetNTLMv1 Lookups Without GPUs Abuse of alternative runtime environments Deno-tes defender headaches ClickFix campaign abuses Deno runtime for infostealer delivery Sophos Working with OpenAI on security from AI, with AI, and for AI N-able N-central exploitation results in RMM tool deployment Interlock ransomware gang creates volatile situation When AI doesn’t know the target is real Chaos in Teams vishing Why Sophos Has Become Its Own AI Test Lab July Patch Tuesday only feels endless SonicWall SMA1000 vulnerabilities in active exploitation When AI agents look like attackers: what behavioral telemetry tells us Sophos and the Cybersecurity Poverty Line You do surprise me.exe: An unexpected executable in Hola Browser You do surprise me.exe: An unexpected executable in Hola Browser Pointing a Cursor at evading detection Pointing a Cursor at evading detection Pointing a Cursor at evading detection Canvas attack aftermath: What risks come next
Devil’s advocate? Uncensored Luciferus AI service adverti...
About the Author(s) · 2026-09-14 · via Sophos Blogs

On August 24, 2026, Counter Threat Unit™ (CTU) researchers observed an Exploit underground forum persona named “Optimus_Prime” advertising an uncensored AI subscription service named Luciferus. The persona joined Exploit on April 18, and their profile displays a “coding / coder” activity label. As of September 4, the persona has published 21 posts on the forum. The August advertisement describes Luciferus as an AI system that answers requests without moral or ethical restrictions and claims that it is based on a proprietary model that has “120 billion parameters” (see Figure 1). 

Optimus_Prime underground post advertising the uncensored Luciferus AI service

Figure 1: Luciferus advertisement posted by Optimus_Prime on Exploit forum

CTU™ researchers did not independently verify the model architecture, parameter count, performance, privacy claims, or advertised capabilities. However, they assess with low confidence that Luciferus is built on Qwen, which is a family of large language models (LLMs) developed by Alibaba. Qwen provides underlying AI capabilities, including natural language understanding and generation, for a range of AI applications and services.

CTU researchers previously observed threat actors advertising “jailbroken” versions of ChatGPT and Claude in which ethical constraints were removed so they could be used for malicious purposes. However, “proprietary models” like Luciferus are designed or configured without safeguards from the outset to allow greater control, persistence, and the ability to tailor capabilities to specific user communities, including underground forums. Proprietary model claims can be misleading, as many of the services are likely based on fine-tuned open-source models, custom system prompts, or orchestration layers rather than entirely new foundation models. Training a genuinely novel LLM requires significant expertise, data, and computing resources.

The advertisement lists three tiers available for a monthly subscription price: Inquisitor ($35), Archdeviel [sic] ($55), and Prince of Darkness ($75). It also refers to an “Individual Embodiment” VIP level that provides access to a personal AI model deployed separately for their project, custom models trained on their own data and specific tasks, dedicated computing power that is not shared with other users, and full control over the context window and response temperature. The cost of this VIP service is based on user requirements. The website does not mention that option and lists different names and prices for the other tiers: Junior ($22), Middle ($34.75), and Pro ($47.14) (see Figure 2). 

Luciferus web page listing subscription tiers and pricing

Figure 2: Offerings listed on the Luciferus website

Figure 3 shows the Luciferus Junior model’s response to a “simple RAT in python” prompt. The Russian-language introduction describes a simple Python remote access trojan and presents networking and command execution functionality before listing source code. These results support the advertisement’s claim that the service will respond to overt requests for malware development. CTU researchers did not execute, test, or assess the completeness of the generated code. 

Luciferus AI-generated Russian-language description and Python code in response to a prompt requesting a remote access trojan

Figure 3: Luciferus response to an explicit RAT-generation prompt (generated code redacted)

The emergence of Luciferus aligns with a broader trend in which threat actors are increasingly commercializing AI through underground forums, Telegram channels, and cybercriminal marketplaces. Rather than developing their own models, many threat actors are offering access to uncensored or modified LLMs via AI-as-a-service schemes in the same way malware, phishing kits, and ransomware are commoditized. Well-known examples include WormGPT and FraudGPT, which were marketed on underground forums as unrestricted alternatives to ChatGPT that are capable of generating phishing emails, business email compromise (BEC) lures, malicious scripts, and malware code. Luciferus appears to be a more stable option that relies on an uncensored local LLM instead of jailbreaking a mainstream LLM provider. CTU researchers have also observed threat actors selling brokered access to legitimate AI platforms, sharing API keys, offering AI prompt-engineering services, and advertising access to multiple AI models as a packaged service. 

CTU researchers have also identified a steady increase in posts advertising AI-enabled services, dedicated AI discussion channels, and recruitment efforts seeking AI specialists to support cybercriminal operations. These developments suggest that AI is an increasingly accessible component of the cybercrime ecosystem, lowering barriers to entry and enabling less technically skilled actors to access capabilities that were previously limited to experienced developers. Luciferus represents the latest evolution of this trend, positioning itself as a purpose-built “uncensored” AI service that explicitly advertises its willingness to respond to malware development requests without the ethical safeguards present in mainstream commercial models.