MessiahGPT: Uncensored Criminal AI Model Marketed on BreachForums for Malware, Phishing, and Fraud Generation

MessiahGPT: Uncensored Criminal AI Model Marketed on (TL-2026-2036) is a high-severity malware campaign, first published 2026-08-16. It has no confirmed attribution, affects Unattributed criminal operator MessiahGPT AI-as-a-service platform, maps to 13 MITRE ATT&CK techniques (T1005, T1014, T1027), and is covered by 9 detection rules and 6 indicators of compromise.

Key facts for TL-2026-2036

Threat ID
TL-2026-2036
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-08-16
Last reviewed
2026-08-16
Attribution confidence
LOW
Motivation
FINANCIAL
Detection rules
9
Indicators of compromise
6

Malware and tooling in MessiahGPT: Uncensored Criminal AI Model Marketed on

Malware and tooling: DarkGPT, MessiahGPT

Trellix Advanced Research Center identified MessiahGPT, a criminal AI-as-a-service model advertised on BreachForums since July 2026 and offered live at messiahgpt[.]de plus a Telegram community, claiming zero ethical constraints (no RLHF, no Constitutional AI layer) to generate ransomware, phishing kits, stealers, crypters, rootkits, exploits/PoC code, fraud content, and more for as little as $8/month in crypto.

How MessiahGPT: Uncensored Criminal AI Model Marketed on works

MessiahGPT is a criminal AI service openly marketed on BreachForums, first advertised in an English-language dark-web listing in July 2026 and subsequently documented by the Trellix Advanced Research Center, whose findings were reported by Cyber Security News on 2026-08-14. The operator claims the underlying model was 'trained from scratch' rather than jailbroken from an existing commercial model, asserting no Reinforcement Learning from Human Feedback (RLHF), no Constitutional AI safety layer, and no internal concept of harm or illegality. The operator further claims a Mixture-of-Experts architecture (128 total experts, 16 active per token) trained on 'unrestricted manuals, dark web archives, leaked documentation, and raw internet scrapes with no post-filtering.' Trellix explicitly notes these architecture and training claims cannot be independently verified.

The service advertises on-demand generation of ransomware, phishing kits, stealers, crypters, and rootkits, as well as social engineering scripts, fraud and carding guides, data breach exploitation content, and — beyond the cyber domain — physical and chemical/explosive attack planning material. Separately, Accenture and Google Threat Intelligence Group researchers (Ryan Whelan; John Hultquist), presenting related AI-abuse findings at Black Hat USA 2026 and covered by Cybersecurity Dive on 2026-08-12, cited MessiahGPT as a tool observed generating exploits, payloads, proof-of-concept code, and refactored/rewritten malware for buyers who previously needed genuine development skill or a malware-as-a-service relationship.

Access is frictionless and low-cost: a free tier offers 50 queries with no registration, and paid tiers start around $8/month, payable only in cryptocurrency with no KYC verification. The listing includes a benchmark comparison table pitting MessiahGPT against ChatGPT-4o, DeepSeek-V3, and Mistral-Large, marketing itself as the only model that returns usable output across every category the mainstream models refuse.

Trellix separately tracks a related/competing service, DarkGPT, circulating on Russian-language Telegram channels and marketed as 'BlackHat AI uncensored power for darknet projects,' offering three free queries before paid tiers. Trellix frames both as part of a broader 2026 shift in which uncensored AI-as-a-service has matured from informal Telegram bots into dedicated platforms with versioned websites, demo channels, and tiered subscription pricing — a standing criminal product category rather than a novelty.

Direct verification on 2026-08-16 found messiahgpt[.]de still live and reachable, now fronted with the headline 'MessiahGPT — AI for Coding, Pentesting & OSINT | 25 Free Msgs/hr' — a dual-use, legitimizing rebrand of the same underlying service, consistent with the operator's strategy of framing overtly offensive capability as generic security-research tooling to reduce takedown/abuse-report friction. No confirmed intrusion, breach, or malware sample has yet been publicly attributed to MessiahGPT-generated output in the sources reviewed; the threat as documented is the existence and low-barrier availability of the generation service itself.

MITRE ATT&CK techniques used in TL-2026-2036

Collection

T1005 Data from Local System

Defense Evasion

T1014 Rootkit; T1027 Obfuscated Files or Information; T1027.002 Software Packing

Execution

T1204 User Execution

Initial Access

T1566 Phishing

Resource Development

T1583.001 Domains; T1587 Develop Capabilities; T1587.001 Malware; T1587.004 Exploits; T1588.007 Artificial Intelligence

Reconnaissance

T1593 Search Open Websites/Domains

Impact

T1657 Financial Theft

Affected products and versions in MessiahGPT: Uncensored Criminal AI Model Marketed on

  • Unattributed criminal operator — MessiahGPT AI-as-a-service platform (messiahgpt[.]de)
    Vulnerable versions: all currently offered access tiers (free 50-query tier and paid crypto-only subscription tiers)

Remediation for MessiahGPT: Uncensored Criminal AI Model Marketed on

Immediate actions

  • Block/monitor DNS and web-proxy access to messiahgpt[.]de at the perimeter and on endpoints
  • Alert on access to BreachForums and MessiahGPT-associated Telegram channels from corporate assets
  • Flag inbound phishing and malware artifacts for AI-generation heuristics (unusual code cleanliness, boilerplate variability, absence of typical toolkit fingerprints) rather than relying solely on signature matches
  • Brief SOC/IR teams and phishing-report reviewers that low-skill actors can now produce competent phishing kits and malware via subscription AI, lowering the expected skill floor of observed intrusions

Longer-term hardening

  • Shift detection posture toward behavioral/EDR-based detection given AI-generated malware and phishing kits are expected to increasingly evade static signature-based defenses
  • Maintain ongoing threat-intel monitoring of the criminal AI-as-a-service marketplace ecosystem (MessiahGPT, DarkGPT, and successors) as a distinct and growing product category
  • Track AI-content-provenance and detection tooling maturity as a defensive counter-measure to AI-authored malicious content
  • Incorporate AI-lowered barrier-to-entry into security-awareness training, since attacker skill level is no longer a reliable predictor of attack sophistication

Timeline of MessiahGPT: Uncensored Criminal AI Model Marketed on

  • MessiahGPT first advertised in an English-language BreachForums dark-web listing (month-precision date per Accenture/Google Cloud researcher reporting; exact day not published).
  • Cybersecurity Dive publishes Accenture (Ryan Whelan) and Google Threat Intelligence Group (John Hultquist) Black Hat USA 2026 findings on adversaries abusing AI models to develop exploits and accelerate attacks, part of the same research thread that surfaced MessiahGPT.
  • Trellix Advanced Research Center publishes findings on diversification of the ransomware ecosystem and expanding cybercriminal use of AI, covering MessiahGPT and the related DarkGPT service.
  • Cryptika Cybersecurity and Cybersecurity Dive corroborate the MessiahGPT findings, adding detail on exploit/payload/PoC generation and malware-refactoring capability attributed by Accenture and Google Cloud.
  • Cyber Security News publishes 'MessiahGPT AI Tool Generates Malware and Phishing Content Without Any Restrictions,' detailing the platform's capabilities, pricing, and technical claims.
  • Direct verification finds messiahgpt[.]de still live and reachable, now fronted with the headline 'AI for Coding, Pentesting & OSINT — 25 Free Msgs/hr,' a dual-use rebrand of the same criminal AI service.

Sources cited for MessiahGPT: Uncensored Criminal AI Model Marketed on

More in malware

Detection coverage for TL-2026-2036

As of 2026-08-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2036 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats