Connect with us

Hi, what are you looking for?

HEADLINES

Sophos notes ‘Luciferus AI’ service advertised underground

Sophos Counter Threat Unit (CTU) researchers observed an Exploit forum persona named Optimus_Prime advertising Luciferus on August 24, 2026.

Sophos X-Ops has published new research on Luciferus, an uncensored AI subscription service advertised on the Exploit underground forum and promoted as answering requests without moral or ethical restrictions.

Sophos Counter Threat Unit (CTU) researchers observed an Exploit forum persona named Optimus_Prime advertising Luciferus on August 24, 2026. The advertisement claims the service is based on a proprietary model with “120 billion parameters,” although Sophos has not independently verified the model architecture, parameter count, performance, privacy claims, or advertised capabilities.

The research highlights a wider shift in the underground economy: threat actors are increasingly commercializing AI as a service, selling uncensored or modified large language models in the same way malware, phishing kits, brokered access, and ransomware tooling are commoditized. Luciferus appears to be positioned as a more stable alternative to “jailbroken” mainstream AI services because it is advertised as an uncensored local LLM from the outset.

“Luciferus shows how quickly the underground economy is trying to package AI into a cybercrime service model. The concern is not just that an AI tool can answer a malicious prompt, but that access is being marketed, tiered, and sold in a way that could make offensive capabilities easier for less technical actors to reach,” Aiden Sinnott, Senior Threat Researcher, Sophos Counter Threat Unit, said.

The service’s marketing explicitly advertises the absence of ethical safeguards, while CTU researchers also observed the Luciferus Junior model responding to a direct request for a simple Python remote access trojan.

Advertisement. Scroll to continue reading.
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

People need to know what kinds of concerns can be raised, where to bring them and what steps to take when something does not...

HEADLINES

Consider deploying a dedicated security solution that safeguards corporate emails from spam, email-borne infections, and all forms of phishing – such as Kaspersky Security...

HEADLINES

The attack begins with a malicious file ending up on a user’s device – this may be a result of the user downloading the...

ELECTRONICS

While most brands compete on how many passwords a lock can store or how much force a safe can survive, Philips built its ecosystem...

HEADLINES

The capability will be built with OpenAI's GPT cyber models through the Daybreak Defense Network, to return verified, evidence-backed verdicts that give defenders the...

HEADLINES

The recognitions, provided by Frost & Sullivan, highlight Kaspersky’s ability to align its cybersecurity strategy with the evolving needs of industrial organizations while executing through...

HEADLINES

EastWest has introduced EasyLock, a self-service security feature available through the EasyWay and EasyBiz apps, where customers can secure a chosen portion of their balance,...

HEADLINES

Smart Communications, Inc. (Smart), the first Philippine telco with a GSMA Open Gateway-certified Number Verification API with Silent Authentication, is building on this foundation...

Advertisement