{"id":8390,"date":"2026-06-05T07:10:00","date_gmt":"2026-06-05T07:10:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8390"},"modified":"2026-06-05T07:10:00","modified_gmt":"2026-06-05T07:10:00","slug":"ai-tools-becoming-hot-commodities-on-ransomware-marketplaces","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8390","title":{"rendered":"AI tools becoming hot commodities on ransomware marketplaces"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p>Sales of AI-based tools is accelerating within underground <a href=\"https:\/\/www.csoonline.com\/article\/563507\/what-is-ransomware-how-it-works-and-how-to-remove-it.html\">ransomware<\/a> marketplaces, lowering the barrier to entry for new actors in the process.<\/p>\n<p>An analysis of Telegram channels, 20 dark web forums, and five underground markets by anti-ransomware platform vendor Halcyon found that AI utility posts grew to 1,486 in February 2026, up from just 38 in December 2025.<\/p>\n<p>The AI tools for sale divided into four categories:<\/p>\n<p>Weaponized LLMs: Sometimes called dark LLMs, these tools omit the safety guardrails and rules present in legitimate large language models (LLMs). \u201cWormGPT\u201d is the market leader in this category of cybercrime-focused AI tooling but only as a brand used by multiple operators, some of which are straightforward scams that collect payments without offering any service.<\/p>\n<p>AI-enabled identity fraud: Tools in this category include voice and video-enabled deepfakes, created using AI, that are used to fool selfie-based recognition systems and other know your customer (KYC) security controls, among other fraudulent applications. The same tools can also be used as part of <a href=\"https:\/\/www.csoonline.com\/article\/3995364\/ai-superpowers-bec-attacks.html\">business email compromise scams<\/a>.<\/p>\n<p>AI-augmented malware and attack infrastructure: AI-driven infrastructure is being used to aggregate, process, and exfiltrate stolen data more efficiently.<\/p>\n<p>Jailbroken and stolen AI services: Hacked AI accounts are the largest category of services offered and the cheapest.<\/p>\n<p>Halcyon estimates that ransomware attacks have grown in volume by 20% since 2023 with an increased focus on targeting smaller enterprises, which now comprise 80% of attacks.<\/p>\n<p>During a keynote presentation at Infosecurity Europe, Cynthia Kaiser, SVP of Halcyon\u2019s Ransomware Research Center, told delegates that the <a href=\"https:\/\/www.csoonline.com\/article\/3838121\/the-dirty-dozen-12-worst-ransomware-groups-active-today.html\">largest ransomware operators<\/a> \u2014 such as Akira \u2014 are increasingly operating the <a href=\"https:\/\/www.csoonline.com\/article\/4119555\/cybercrime-inc-the-new-industry-challenging-cisos-in-2026.html\">same business models as legitimate vendors<\/a> by selling services and infrastructure to their clients and affiliates. The main difference is that the goods on offer are exploits and stolen credentials rather than the legitimate goods sold through legitimate marketplaces.<\/p>\n<p>Ransomware groups sell routinely through multiple channels, thereby creating redundancy in the event that any channel is taken down. Their services are often offered with tiered pricing, and are commonly available with a freemium model popularised by legitimate web services. Telegram bot-driven channels are automating the process of sales and marketing, while AI-based utilities are being applied by cybercriminals to offer customer service.<\/p>\n<p>\u201cModern ransomware operators don\u2019t need to build their operations from scratch,\u201d said Kaiser, the former deputy assistant director of the FBI\u2019s Cyber Division, who added that the skill level required from would-be <a href=\"https:\/\/www.csoonline.com\/cybercrime\/\">cybercriminals<\/a> has dropped.<\/p>\n<h2 class=\"wp-block-heading\">Dishonour among thieves<\/h2>\n<p>All this may seem impressive, but Kaiser noted that criminal operational security (OpSec) is weaker than it looks.<\/p>\n<p>\u201cCriminal AI markets have a theft problem [because] black hats are attacking each other,\u201d Kaiser said.<\/p>\n<p>For example, credentials from one WormGPT instance were stolen by rival cybercriminals and dumped back onto the same forum that originally sold access to the malign AI-based utility.<\/p>\n<p>Such disruption aside, the greater use of AI tooling is part of a sign that the underground ransomware scene has professionalised not least by making it easier in run multiple attacks at scale.<\/p>\n<h2 class=\"wp-block-heading\">Raking it in<\/h2>\n<p>According to separate research from Rapid7, ransomware is becoming more profitable, up 39% between Q1 2025 and Q1 2026.<\/p>\n<p>The <a href=\"https:\/\/www.csoonline.com\/article\/4070290\/lockbit-dragonforce-and-qilin-form-a-cartel-to-dictate-ransomware-market-conditions.html\">Qilin ransomware group<\/a> made an estimated $193 million between July 2025 and March 2026. And <a href=\"https:\/\/www.csoonline.com\/article\/4178580\/the-gentlemen-are-coming-for-your-files-and-then-your-network.html\">The Gentleman<\/a>, which is just behind Qilin as the biggest ransomware group, made an estimated $52 million between July 2025 and March 2026, according to Rapid7.<\/p>\n<p>Rapid7\u2019s analysis is based on average ransom payments and payment rates from CoveWare, a ransomware and cyber extortion incident response firm.<\/p>\n<p>Thom Langford, CTO EMEA at Rapid7, said that the ransomware ecosystem has evolved into a mature underground marketplace where access, tooling, and full attack services are now commercially available to almost anyone.<\/p>\n<p>Langford added that AI-based social engineering, primarily to craft more convincing phishing lures, is widely used.<\/p>\n<p>Marketplaces offer an a la carte menu where cybercriminals can contract services for initial access, exfiltration, or negotiation with victims, according to Langford, who added that many if not all of the principal players in the ransomware scene \u201cspeak Russian.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Countermeasures<\/h2>\n<p>Law enforcement takedowns are curtailing the growth of ransomware operations, but businesses also need to play their part in defence, Halcyon advises.<\/p>\n<p>Enterprises should concentrate on measures such as stopping initial access, detecting lateral movement, and disrupting exfiltration and encryption. Companies can also build resilience through tabletop exercises, Kaiser concluded.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Sales of AI-based tools is accelerating within underground ransomware marketplaces, lowering the barrier to entry for new actors in the process. An analysis of Telegram channels, 20 dark web forums, and five underground markets by anti-ransomware platform vendor Halcyon found that AI utility posts grew to 1,486 in February 2026, up from just 38 in [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8391,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8390","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8390"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8390"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8390\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8391"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8390"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8390"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8390"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}