Sophos X-Ops has published new research on Luciferus, an uncensored AI subscription service advertised on the Exploit underground forum and promoted as answering requests without moral or ethical restrictions.
Sophos Counter Threat Unit (CTU) researchers observed an Exploit forum persona named Optimus_Prime advertising Luciferus on August 24, 2026. The advertisement claims the service is based on a proprietary model with “120 billion parameters,” although Sophos has not independently verified the model architecture, parameter count, performance, privacy claims, or advertised capabilities.
The research highlights a wider shift in the underground economy: threat actors are increasingly commercializing AI as a service, selling uncensored or modified large language models in the same way malware, phishing kits, brokered access, and ransomware tooling are commoditized. Luciferus appears to be positioned as a more stable alternative to “jailbroken” mainstream AI services because it is advertised as an uncensored local LLM from the outset.
“Luciferus shows how quickly the underground economy is trying to package AI into a cybercrime service model. The concern is not just that an AI tool can answer a malicious prompt, but that access is being marketed, tiered, and sold in a way that could make offensive capabilities easier for less technical actors to reach,” Aiden Sinnott, Senior Threat Researcher, Sophos Counter Threat Unit, said.
The service’s marketing explicitly advertises the absence of ethical safeguards, while CTU researchers also observed the Luciferus Junior model responding to a direct request for a simple Python remote access trojan.




















































































