
Cybersecurity researchers have exposed a new uncensored artificial intelligence subscription service named Luciferus, which is actively marketed to threat actors on dark web forums to fulfill requests without moral or ethical guardrails.
According to new research from Sophos X-Ops, the service was spotted on the Exploit underground forum on August 24, 2026, posted by a user persona operating under the name Optimus_Prime.
The seller claims Luciferus operates on a proprietary model featuring 120 billion parameters, positioned specifically to handle malicious tasks. Sophos notes that it has not independently verified the model’s architecture, parameter count, performance, privacy claims, or advertised capabilities.
The emergence of Luciferus signals a broader evolution in the cybercrime ecosystem, where threat actors increasingly package and commercialize large language models alongside traditional criminal tools such as malware, phishing kits, brokered access credentials, and ransomware.
“Luciferus shows how quickly the underground economy is trying to package AI into a cybercrime service model. The concern is not just that an AI tool can answer a malicious prompt, but that access is being marketed, tiered, and sold in a way that could make offensive capabilities easier for less technical actors to reach,” said Aiden Sinnott, Senior Threat Researcher at the Sophos Counter Threat Unit (CTU).
Unlike conventional jailbreaking techniques—which attempt to bypass security filters on mainstream, consumer-facing AI platforms—Luciferus is advertised as a standalone, uncensored local large language model built without safety guardrails from inception. Threat actors are pitching this approach as a more reliable, stable alternative for cybercriminals seeking persistent access to unfiltered models.
During their investigation, Sophos Counter Threat Unit researchers tested the service’s claims and observed a variant called the Luciferus Junior model successfully generate code for a simple Python-based remote access trojan in response to a direct prompt.
Key Takeaways
- Service Name: Luciferus (including a variant known as Luciferus Junior)
- First Observed: August 24, 2026, on the Exploit underground forum by persona Optimus_Prime
- Promised Features: Uncensored processing without ethical boundaries, operating on an alleged 120-billion-parameter proprietary model
- Demonstrated Capabilities: Generated a functional Python remote access trojan upon request during researcher observation
- Market Significance: Represents a shift toward dedicated, tiered AI-as-a-service offerings that lower the technical barrier to entry for cybercriminals




Leave a Reply