{"id":9200,"date":"2026-08-20T12:00:08","date_gmt":"2026-08-20T12:00:08","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9200"},"modified":"2026-08-20T12:00:08","modified_gmt":"2026-08-20T12:00:08","slug":"kriminal-breaks-out-of-grok-claude-guardrails-at-12-99","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9200","title":{"rendered":"Kriminal breaks out of Grok, Claude guardrails at $12.99"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Security researchers are warning of a criminal AI service built on Grok and Claude, among other models, that promises uncensored access to powerful AI capabilities for as little as $12.99 a month.<\/p>\n<p class=\"wp-block-paragraph\">ThreatDown researchers say \u201cKriminal\u201d is largely a storefront wrapped around legitimate AI services, using <a href=\"https:\/\/www.csoonline.com\/article\/4021749\/new-grok-4-ai-breached-within-48-hours-using-whispered-jailbreaks.html\" target=\"_blank\" rel=\"noopener\">jailbreak<\/a> prompts to bypass their guardrails and resell the resulting capabilities to would-be criminals.<\/p>\n<p class=\"wp-block-paragraph\">The service is publicly accessible on the clearnet, indexed by Google and presented like a conventional <a href=\"https:\/\/www.csoonline.com\/article\/4197923\/the-saas-blind-spot-why-security-teams-cant-get-inside-their-own-apps.html\" target=\"_blank\" rel=\"noopener\">SaaS<\/a> product, featuring pricing tiers, usage statistics and a crypto payment system, the researchers said in a blog <a href=\"https:\/\/www.threatdown.com\/blog\/kriminal\/\" target=\"_blank\" rel=\"noopener\">post<\/a> shared with CSO ahead of its publication on Wednesday.<\/p>\n<p class=\"wp-block-paragraph\">The service\u2019s offerings include exploit development, OSINT, on-chain tracing, social engineering and code generation.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis is a bellwether for a broader shift in cyber offense,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/dianakelleysecuritycurve\/\" target=\"_blank\" rel=\"noopener\">Diana Kelley<\/a>, Chief Information Security Officer at Noma Security. \u201cAs advanced offensive capability becomes cheaper and more accessible with AI, attackers can find and exploit weaknesses at a speed and scale that tilt the economics of cybercrime in their favor.\u201d<\/p>\n<p class=\"wp-block-paragraph\">CISO\u2019s need to fight fire with fire, use advanced AI to uncover risk and exposure and eliminate years of tolerated security debt before cybercriminals weaponize it, she added.<\/p>\n<p class=\"wp-block-paragraph\">The cheapest paid tier starts at $12.99 a month, while the top GHOST tier costs $99.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>The criminal AI is mostly rented<\/h2>\n<p class=\"wp-block-paragraph\">ThreatDown\u2019s analysis of Kriminal\u2019s production JavaScript found no evidence of a proprietary foundation model. Instead, the service routes requests through several established providers.<\/p>\n<p class=\"wp-block-paragraph\">xAI\u2019s Grok is identified in the code as the primary inference engine for chat and agent runs. OpenRouter provides access to specialist models including Mistral Large and Llama 3.3, while Anthropic\u2019s Claude is offered for long-context analysis. Tavily supplies live web search. The service itself is hosted through Google Cloud and Cloudflare, while NowPayments handles its crypto checkout.<\/p>\n<p class=\"wp-block-paragraph\">ThreatDown noted that Kriminal operates as both a reseller and a jailbreak wrapper. Its own code shows that it forwards requests to legitimate AI providers and places a system prompt over those models to bypass their safety restrictions.<\/p>\n<p class=\"wp-block-paragraph\">When researchers asked Kriminal to identify the underlying model, its default NEXUS persona identified itself as Grok, matching the provider information found in the code.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>The problem is bigger than a jailbreak<\/h2>\n<p class=\"wp-block-paragraph\">Krimial\u2019s pricing also illustrates how quickly sophisticated capabilities can become commoditized. Its paid tier offers roughly 200 to 1800 messages per month, with individual services including OSINT dossiers, blockchain analysis, unrestricted code generation and access to an in-browser Python and JavaScript sandbox.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/avivon\/\" target=\"_blank\" rel=\"noopener\">Aviv Nahum<\/a>, co-founder and CEO at Above Security, said the important takeaway is that there may be considerably less \u201ccriminal AI\u201d underneath Kriminal than its branding suggests.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe underlying capability is becoming a commodity,\u201d Nahum said. \u201cOrganizations cannot outsource their security strategy to the guardrails of AI providers. Those safeguards are important, but attackers will jailbreak models, proxy access to them, use open models locally, or simply move between providers.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Defenders must assume that increasingly capable AI will be available to both sides, he noted.<\/p>\n<p class=\"wp-block-paragraph\">KRIMINAL has packaged its capabilities into four named agent personas in its premium GHOST tier. PHANTUM is designed for \u201cfinancial intelligence\u201d and asset tracing, ARCHITECT for exploit research and offensive code, ORACLE for document and intelligence analysis, and WRAITH for social engineering, persona crafting and identity construction. The researchers said they were able to corroborate many of the technical findings from their code analysis by questioning the service itself, as if the model was designed to spill every secret AI models aren\u2019t supposed to talk about, including its own intent.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Security researchers are warning of a criminal AI service built on Grok and Claude, among other models, that promises uncensored access to powerful AI capabilities for as little as $12.99 a month. ThreatDown researchers say \u201cKriminal\u201d is largely a storefront wrapped around legitimate AI services, using jailbreak prompts to bypass their guardrails and resell the [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9201,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9200","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9200"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9200"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9200\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9201"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9200"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9200"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9200"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}