AI on the dark web concept showing WormGPT and FraudGPT malicious LLMs and Tor network scrapers

AI on the Dark Web: From WormGPT to Tor Scrapers

AI on the dark web has become a commercialized crime economy. Unpack WormGPT, FraudGPT, DarkBard, Tor scrapers, and the guardrail-bypass tactics reshaping the 2026 threat landscape.

AI on the dark web concept showing WormGPT and FraudGPT malicious LLMs and Tor network scrapers

What Is AI on the Dark Web — and Why Should You Care?

AI on the dark web is no longer a fringe concern for threat researchers. It has become a fast-moving, commercialized ecosystem where criminal actors buy, sell, and deploy large language models stripped of every safety guardrail that legitimate tools enforce.

Here is a quick breakdown of what this means in practice:

Concept What It Means
Dark web AI tools LLMs fine-tuned or jailbroken to produce malware, phishing content, and exploit code on demand
How they're sold Subscription services on Telegram and dark web forums, priced from $200/month to $1,700/year
Who uses them Low-skill threat actors who previously lacked the technical ability to build these attacks
What they enable BEC campaigns, ransomware, deepfakes, credential theft, and child exploitation material
How defenders respond OSINT pipelines, automated Tor scrapers, and AI-powered threat intelligence monitoring

Between January and December 2023, cybercrime forums saw a sustained surge in discussions about using AI for illegal activity — peaking in April 2023. By 2024 and into 2025, that chatter had evolved from curiosity into a structured underground economy. Researchers tracked a 219% increase in dark web mentions of malicious AI tools over that period, with entire forum sections now dedicated to AI-powered crime.

The barrier to entry has collapsed. A threat actor who once needed coding skills to build a phishing kit can now subscribe to a criminal LLM service and generate convincing, targeted attack content in minutes.

This guide maps the full landscape — from the first generation of malicious LLMs like WormGPT and FraudGPT, through the technical methods used to strip AI safety controls, to the defensive OSINT tools security teams are using to monitor and disrupt these services on the Tor network.

Quick look at AI dark web:

The Evolution of the AI Dark Web Ecosystem

The dark web has always been an early adopter of disruptive technology. To understand how we arrived at the current landscape of the AI dark web, it helps to look at the underlying architecture. The Tor network, originally designed by the U.S. Naval Research Laboratory in the mid-1990s and released publicly in 2002, was built to provide anonymity through three-hop onion routing. While the dark web is estimated to represent less than 0.1% of the entire internet, it hosted anywhere from 30,000 to 100,000 active sites at its peak in 2016 and 2017.

Over the last decade, dark web marketplaces and underground forums transitioned from selling raw data and illicit goods to offering sophisticated software-as-a-service (SaaS) platforms. When generative AI exploded into the mainstream, cybercriminals quickly realized they could automate the most tedious parts of their operations. This sparked a massive wave of experimentation on hacker forums and dedicated Telegram channels, shifting the focus of underground developers toward Tag/Artificial Intelligence Ai and Tag/Ai Security.

From Jailbreaks to Unrestricted Criminal LLMs

In the early days of this shift, threat actors relied on "jailbreaking" legitimate commercial models like ChatGPT. Jailbreaks are cleverly engineered prompts designed to bypass the safety filters of a model, tricking it into generating malicious code, phishing templates, or instruction sets for physical crimes. During 2023, security researchers observed 249 distinct offers to distribute and sell jailbreak prompt sets on underground forums.

However, relying on jailbreaks is a fragile business model. Legitimate AI providers constantly patch their models to block these prompts. To achieve true operational independence, cybercriminals began downloading open-source foundational models, such as the six-billion-parameter GPT-J, and hosting them on private infrastructure. By stripping away all alignment training and safety guardrails, developers created the first generation of dedicated, unrestricted criminal LLMs. This transition is analyzed deeply in our Cybersecurity Ai Guide 2026.

The Rise of AI-as-a-Service (AIaaS) on Underground Forums

What started as garage-style model modifications has matured into a highly organized "AI-as-a-Service" (AIaaS) business model. Today, threat actors do not need high-end GPUs or machine learning expertise to leverage the power of the AI dark web. Instead, they pay subscription fees ranging from $200 per month to $1,700 per year to access cloud-hosted malicious chatbots.

cybercriminal forum discussions AIaaS subscription dashboard collage

These services mirror legitimate enterprise software. They offer polished web interfaces, API access, tiered pricing plans, and even private key licensing. Between January and May 2025, threat intelligence telemetry logged more than 2.5 million AI-related posts across over 100,000 illicit sources, including dark web marketplaces and private Telegram groups. The developers behind these tools even run customer support operations, rapidly updating their models when users report that a generated phishing template was flagged by common email security filters.

Anatomy of Malicious LLMs: WormGPT, FraudGPT, and Beyond

To understand the threat these tools pose to modern enterprises, we have to look closely at the specific platforms that have emerged in the underground marketplace.

The following table compares the capabilities, pricing, and lifespans of prominent dark-web AI tools against legitimate commercial offerings:

Tool Name Type Access / Pricing Primary Use Cases Status / Lifespan
WormGPT Malicious LLM Subscription (Discontinued) BEC phishing, basic malware writing Shut down August 2023 due to media exposure
FraudGPT Malicious LLM $200/month to $1,700/year Phishing pages, undetectable malware, carding Active; over 3,000 sales by late July 2023
DarkBard Malicious LLM Private / Subscription Zero-day exploitation, image-to-text analysis Active; integrated with Google Lens capabilities
PoisonGPT Poisoned Model Free (Open-source proof of concept) Undetectable misinformation, historical bias Distributed on public repositories like Hugging Face
N Unrestricted Service Free / Ad-supported Malware scripts, extremist content, backdoors Active; launched late September 2025
Legitimate LLMs Commercial AI Free to $20/month Code generation, writing, business analytics Maintained with strict safety guardrails

Phishing and BEC Engines: WormGPT and FraudGPT

WormGPT was one of the earliest and most notorious malicious LLMs. Based on the GPT-J model, it was specifically tailored for business email compromise (BEC) attacks. WormGPT allowed low-skilled attackers to generate highly persuasive, grammatically perfect spear-phishing emails in multiple languages. Although its developer shut down the project in August 2023 following intense media coverage and law enforcement pressure, it proved the commercial viability of malicious AI.

Shortly after WormGPT's demise, a threat actor known as "CanadianKingpin" launched FraudGPT. Marketed heavily on Telegram and carding forums, FraudGPT boasted over 3,000 confirmed sales and reviews by the end of July 2023. FraudGPT was designed as an all-in-one cybercrime assistant. Beyond writing phishing lures, it helps attackers build fake login pages, write basic keyloggers, craft polymorphic malware that evades signature-based antivirus detection, and automate credential stuffing campaigns.

Advanced Threats: DarkBard, PoisonGPT, and the "N" Service on the AI Dark Web

The ecosystem has evolved rapidly past simple text generators. DarkBard emerged as a sophisticated tool designed to mimic Google's Bard technology, integrating advanced capabilities like image-to-text analysis via Google Lens. This allows attackers to upload screenshots of enterprise network topologies or software interfaces and ask the AI to identify potential entry points or design flaws.

PoisonGPT represents a different kind of threat: model poisoning. Created as a proof of concept by security researchers to warn the industry, PoisonGPT demonstrated how a threat actor could take an open-source model like GPT-J, use Rank-One Model Editing (ROME) to surgically inject false information (such as historical untruths), and upload it back to public repositories under a slightly misspelled name. The poisoned model showed only a 0.1% difference in benchmark accuracy on the ToxiGen framework, making the manipulation virtually undetectable to developers downloading the model for enterprise use.

More recently, on September 29, 2025, a highly dangerous, unrestricted service named "N" was launched on the dark web. Unlike its predecessors, N requires no registration, no user accounts, and no subscription fees. It processed approximately 10,000 requests on its very first day. N is hosted on decentralized, block-resistant infrastructure and is openly advertised on high-risk forums. It generates fully functional malicious scripts, backdoors, and extremist materials without any built-in ethical restrictions, as detailed in the investigative report Content without brakes: criminal AI service appeared on the darknet | Articles | Izvestia .

Technical Exploitation: How Criminals Bypass Safety Guardrails

Legitimate AI companies spend millions of dollars training their models to refuse harmful requests. Cybercriminals bypass these defenses using three primary technical approaches: jailbreaking, fine-tuning, and post-training model editing. Understanding these methods is key to establishing proper Tag/Ai Governance.

Jailbreaking, Fine-Tuning, and ROME Model Editing

Jailbreaking relies entirely on prompt engineering. By wrapping a malicious request in a complex hypothetical scenario, roleplay, or translation exercise, attackers exploit the model's desire to be helpful. Because this is a game of cat-and-mouse, underground communities have commercialized "Prompt Engineering as a Service" (PEaaS), where developers sell guaranteed, regularly updated bypass prompts designed to crack mainstream APIs.

Fine-tuning is a much more permanent bypass. Attackers take an open-source model and feed it custom datasets containing thousands of successful scam letters, leaked credentials, exploit codes, and malware construction guides. This permanently alters the model’s weights, optimizing it for criminal workflows.

For highly targeted deception campaigns, threat actors use model-editing techniques like the ROME algorithm. Instead of retraining an entire model, ROME allows an attacker to locate the exact parameters where specific factual associations are stored and rewrite them. This allows an attacker to surgically inject misinformation or backdoors into an LLM while ensuring the model still passes standard security and performance benchmarks.

Automated Identity Attacks and Deepfakes on the AI Dark Web

The integration of multimodal AI has also supercharged identity-based attacks. Underground markets now offer Deepfake-as-a-Service (DaaS). For a small fee, attackers can generate custom face swaps, synthetic audio clones, and realistic video avatars.

These tools are specifically designed to bypass modern Know Your Customer (KYC) identity verification systems used by financial institutions and government portals. By combining automated credential stuffing with synthetic identity cloning, attackers can execute highly convincing account takeover campaigns. To explore how organizations are defending against these synthetic threats, see our guide on Digital Doppelg Ngers Ai Identity Cloning and learn how to manage compliance risks with Ai Compliance Monitoring.

Defensive AI and OSINT: Scraping and Monitoring the Tor Network

As the threat landscape scales, manual threat intelligence is no longer sufficient. Security teams and threat intelligence professionals are turning to automated Open Source Intelligence (OSINT) pipelines, machine learning classifiers, and Tor scrapers to monitor the dark web in real time.

automated threat intelligence pipeline dark web monitoring collage

These defensive architectures align with modern Zero Trust frameworks and NIST standards, allowing organizations to identify exposed credentials and brand impersonation campaigns before an attack is launched.

Breaking CAPTCHAs with Generative Adversarial Networks (GANs)

One of the biggest hurdles to automated dark web monitoring is the widespread use of text-based CAPTCHAs. Because dark web sites want to prevent security crawlers from indexing their forums, they implement highly distorted, noisy CAPTCHAs.

To overcome this, researchers developed DW-GAN, a framework that uses Generative Adversarial Networks to bypass these defenses. DW-GAN uses a GAN-based background denoising process to strip away colorful curves, dots, and background noise from CAPTCHAs. It then applies contour detection segmentation to break the CAPTCHA into individual characters, which are recognized by a Convolutional Neural Network (CNN). DW-GAN achieved a success rate of over 94.4% on real-world dark web CAPTCHAs, allowing automated security tools to scrape and index high-risk forums without human intervention. The academic mechanics of this approach are documented in Counteracting Dark Web Text-Based CAPTCHA with Generative Adversarial Learning for Proactive Cyber Threat Intelligence .

Open-Source AI OSINT Tools: VoidAccess, Robin, and OnionClaw

A new generation of open-source, AI-powered OSINT tools has emerged, allowing organizations to build private dark web monitoring pipelines without paying prohibitive commercial licensing fees.

  • VoidAccess: This self-hosted OSINT platform automates dark web investigations using a 13-step pipeline. It queries over 16 Tor search engines in parallel, scrapes hidden services, and uses LLMs to refine queries, filter out noise, and extract more than 55 entity types (including cryptocurrency wallets, credentials, and threat actor aliases). It also resolves threat actor aliases across investigations by correlating shared PGP keys and infrastructure. While commercial platforms like Recorded Future (~$25,000/year), DarkOwl (~$15,000/year), or Flare (~$8,000/year) are highly expensive, KatrielMoses/voidaccess is free. Running investigations using paid models like DeepSeek via OpenRouter costs under $0.50 per run, and drops to $0 when using free-tier models or local deployments via Ollama.
  • Robin: This tool leverages LLMs to automate dark web OSINT investigations. Accessible via a clean Streamlit web interface, aadityajs/robin uses AI to refine search queries, filter raw search results returned from Tor search engines, and compile comprehensive markdown intelligence summaries. It supports multiple backends, including OpenAI, Claude, Gemini, and local Ollama instances.
  • OnionClaw: Designed specifically to give autonomous AI agents full access to the dark web, CaptainBlackwave/OnionClaw integrates 18 dark web search engines. It handles Tor SOCKS5 proxy routing, automates Tor circuit rotation to prevent IP blocking, and uses LLMs to summarize scraped .onion pages.
  • Dark-Web-AI-Scout (Arachne): This autonomous discovery and classification system uses natural language processing to crawl hidden services and automatically categorize them into functional groups like Marketplaces, Forums, or Ransomware leak sites. Developed by MasterCaleb254/Dark-Web-AI-Scout , it features a built-in safety pipeline that pre-screens scraped content using hash matching to filter out illegal material before human analysts or machine learning models process the data. It also calculates a dynamic risk score from 0 to 100 for every discovered site.

Frequently Asked Questions about Dark Web AI

What is the difference between legitimate LLMs and dark web AI tools?

Legitimate LLMs operate under strict ethical guardrails, compliance frameworks, and safety filters. They are programmed to refuse requests to write malware, generate phishing templates, or assist in illegal activities. Dark web AI tools are either open-source models that have been fine-tuned on underground datasets or commercial models accessed via jailbreak wrappers. They have no built-in ethical locks, allowing users to generate unrestricted malicious content on demand.

How do security teams monitor malicious AI activity on the Tor network?

Security teams use automated OSINT crawlers, Tor scrapers, and natural language processing models to monitor dark web forums, marketplaces, and Telegram channels. Tools like VoidAccess and Arachne allow defenders to automate the discovery of new .onion sites, bypass text-based CAPTCHAs, and classify content based on risk levels. This threat intelligence is used to identify leaked credentials, brand impersonation campaigns, and early signs of targeted attacks.

Can open-source AI models be poisoned by threat actors?

Yes. Threat actors can download open-source models, use model-editing techniques like ROME to inject specific biases, false facts, or backdoors, and then re-upload the poisoned models to public repositories like Hugging Face. Because these modifications are highly localized, the poisoned models can still pass standard performance benchmarks, making it incredibly difficult for developers to detect the manipulation before integrating the model into an enterprise application.

Conclusion

The emergence of AI on the dark web represents a permanent shift in the threat landscape. By lowering the technical barrier to entry, tools like FraudGPT and unrestricted services like N have democratized cybercrime, allowing low-skilled actors to execute highly sophisticated phishing, BEC, and malware campaigns at scale.

To counter these automated threats, organizations must move away from reactive security postures. Implementing a proactive, zero-trust architecture is essential. Because compromised credentials sold on the dark web are the primary entry point for automated identity attacks, securing user identity and access management is your first line of defense.

For a detailed evaluation of how to secure your enterprise identity infrastructure against these evolving, AI-driven threats, read our comprehensive guide on the best IAM solutions of 2026. To learn more about how Unlocked and EveryKey can help you build a resilient, modern security architecture, visit Unlocked or sign up for our platform at the EveryKey Portal.

Share

Related articles