€170/Month for the End of Trust
Evidence-first pattern recognition. Sourced to reputable reporting.
Editor's Note
Compiled from public threat-intelligence disclosures, vendor transparency reports, and FBI filing data. No underground surfaces were accessed directly.
Analysis
Independent analysis of a real claim, traced to its sources. Sources and factual claims are documented below.
The Pattern
A man who cannot write code sold working ransomware last year. He built it with an AI assistant, packaged it, listed it for $400 to $1,200 per copy, and found buyers. The product worked. The customers deployed it. He needed AI for every step. The only reason the operation stopped is that the AI company noticed the pattern and banned his account.
That man is not the story. The story is that the deception stack has a pricing page now. Tiered subscriptions. A freemium tier. Customer support that answers in three languages. The infrastructure of mass deception ships with the same frictionless onboarding as a streaming service, and it is growing faster than any legitimate SaaS product I have seen.
Between December 2025 and February 2026, AI utility posts on monitored dark-web surfaces grew from 38 to 1,486. That is a 39x increase in eight weeks. Halcyon, a ransomware response firm whose SVP is a former FBI Cyber Division deputy assistant director, presented the numbers at Infosecurity Europe in June 2026. They monitored 20 dark-web forums and 5 underground markets. The growth was not organic curiosity. It was product-market fit.
The storefront
This market did not appear from nowhere. It inherited its infrastructure from two decades of forum-based cybercrime. HackForums.net, founded in 2006, was the original on-ramp: a gamified reputation system where posting working exploits earned social capital and DDoS-for-hire services advertised openly. The Mirai botnet source code, which took down Dyn DNS and much of the internet in 2016, was released there by a user named Anna-senpai. When law enforcement pressure fragmented those communities, the commerce migrated to BreachForums, then to Exploit.in and XSS.is on the Russian-language side, and finally to the Telegram-bot storefronts that dominate today. Each migration stripped away friction. The old forums required posting, reputation-building, and trust negotiation. The Telegram bots require only a payment address.
The primary discovery layer is Telegram. Bot-driven storefronts automate sales the way a Shopify app automates a candle shop. You browse, you select a tier, you pay in crypto, you receive access. Tor-hosted checkout pages handle the transaction layer. The whole pipeline runs without a human touching it.
The products have brand names. FraudGPT rents for €170 per month or €1,500 per year. WormGPT was shut down in August 2023, but the brand is now cloned by multiple operators, most of whom are selling outright scams to other criminals. DarkBERT, DarkGemini, TorGPT, WolfGPT, and Xanthorox compete for market share. Xanthorox advertises a modular architecture of specialized AI models, offline operation, and real-time searches across 50 engines. It reads like a product launch, not a criminal enterprise.
Kaspersky’s Digital Footprint Intelligence team found over 3,000 posts on Russian-language cybercrime boards discussing LLM modification for malicious use. Telefónica Tech documented all-in-one fraud kits selling for over €4,000 with technical support included. Stolen ChatGPT premium accounts sell in bundles for €8 to €500 depending on usage limits. The jailbreak prompt market alone had 249 documented offers in a single year.
The product categories
Halcyon sorts the market into four categories:
Weaponized LLMs. Safety guardrails removed. The buyer types a prompt and gets malware, phishing copy, or social engineering scripts without refusal. This is the smallest category by volume but the loudest by brand recognition.
AI-enabled identity fraud. Voice cloning from a three-second sample. Deepfake video that defeats bank KYC selfie-verification from a single photograph. Trend Micro documented a tool called Deepfake 3D Pro that builds a synthetic 3D avatar from one victim photo and follows live head movement in real time. It is marketed for vishing campaigns and corporate BEC attacks. A tool called SwapFace does real-time face-swapping on video streams. VideoCallSpoofer builds a 3D avatar that tracks your movement and renders it as someone else on a Zoom call.
AI-augmented malware. AI-driven data aggregation, processing, and exfiltration. The AI does not write the malware. It manages the operation after infection.
Jailbroken and stolen AI services. The largest category by volume. The cheapest. Hacked accounts, leaked API keys, bypassed safety layers on legitimate models. This is the entry point. This is the funnel.
Two more facts that reframe the problem
In September 2025, Anthropic disrupted the first documented AI-orchestrated cyber espionage campaign. A Chinese state-sponsored group used AI to perform 80 to 90 percent of the operation against approximately 30 global targets. Humans made four to six decisions total. The AI did the rest. This was not AI advising a human operator. This was AI executing, with a human occasionally approving.
The FBI’s 2025 Internet Crime Complaint Center report created its first-ever AI section in 25 years of publication. 22,364 AI-nexus complaints. $893 million in losses. AI-nexus investment scams alone accounted for $632 million. Total US cybercrime losses for 2025: $21 billion across one million complaints. The FBI did not create a new section because the problem was small. They created it because the category could no longer be absorbed into existing ones.
The subscription model is the story
The tools are not the story. The tools existed in primitive form years ago. What changed is the delivery model. Criminal AI now operates with legitimate vendor business practices: tiered pricing, freemium access, automated customer support, Telegram-bot marketing funnels, and subscription retention mechanics. Cynthia Kaiser, Halcyon’s SVP and former FBI Cyber Division deputy assistant director, said it plainly: “Modern ransomware operators don’t need to build their operations from scratch.”
This is reality preemption at the infrastructure level. The deception is not a single fake video or a single cloned voice. The deception is an entire market that makes fake video, cloned voice, synthetic identity, and automated social engineering available as a utility. The buyer does not need to understand the technology. They need a payment method and a target.
The pattern is source obfuscation scaled to an economy. Every product in this marketplace is designed to make the origin of a deception untraceable. The voice is not the speaker. The face is not the person. The text is not the author. The identity is not the account holder. The entire value proposition is the erasure of provenance.
The infrastructure gap
The detection side is losing. Anthropic banned 832 accounts for malicious cyber activity between March 2025 and March 2026. OpenAI disrupted over 40 malicious networks since February 2024. Microsoft blocks 4.5 million new malware attempts daily and screens 5 billion emails for phishing. These are enormous numbers. They are also the numbers of a losing defense. Ransomware profitability rose 39 percent between Q1 2025 and Q1 2026. The Qilin ransomware group earned an estimated $193 million in nine months.
The generation tools improve faster than the detection tools. The tells that caught the Burkina Faso presidential deepfake in June 2026, poor lip-syncing, unnatural movements, repetitive sequences, are already disappearing. France24 reported that advanced AI visual generators have “largely erased the once-telltale glitch of extra fingers.” The detection window is shrinking. The marketplace is growing. These two curves do not need to cross for the damage to be irreversible. They only need to keep their current trajectories.
Who benefits
Not the script kiddie buying a €170 subscription. Not the mid-tier operator running vishing campaigns with cloned voices. They are the labor layer.
The beneficiaries are specific and identifiable by their incentives:
State propaganda operations. A government that needs to fabricate evidence of enemy atrocities, manufacture consent for intervention, or discredit dissidents no longer needs a media apparatus. It needs a subscription and a target list. The Burkina Faso deepfake was a prototype. The marketplace is the production line.
Corporate fraud networks. Investment scams, BEC operations, and synthetic-identity fraud rings that previously required teams of social engineers can now run with a fraction of the staff. The $632 million in AI-nexus investment fraud the FBI logged in 2025 is not the ceiling. It is the onboarding quarter.
Any actor that needs plausible deniability at scale. When every face can be faked and every voice cloned, the cost of attribution rises for everyone except the attacker. A state can deny its deepfake. A corporation can deny its cloned CEO call. A political operation can deny its synthetic whistleblower video. The marketplace does not just enable deception. It enables the denial of deception.
A world where any identity can be fabricated for €170 per month is a world where accountability becomes structurally impossible. That is not a cybercrime problem. That is a governance problem. That is the precondition for every authoritarian playbook ever written: when nothing can be verified, power belongs to whoever shouts loudest and punishes fastest. The deregulation of this market is not an oversight. It is a delivery mechanism. No one gated it, licensed it, or slowed it down, because the people in a position to do so benefit from a world where evidence is cheap and trust is expensive.
Verdict: The deception stack is a subscription service. It has pricing tiers, customer support, and product-market fit. It grew 39x in eight weeks. The FBI created a new reporting category because the old ones could not hold it. A man who cannot code sells working ransomware. A state actor runs an espionage campaign with four human decisions. A single photograph defeats a bank’s identity verification. The tools are not the threat. The delivery model is. The infrastructure of mass deception now onboards like Netflix, and no one gated it, licensed it, or slowed it down. That absence is not an accident. It is the policy.
Sources verified August 2026. Halcyon data presented at Infosecurity Europe, June 2026. FBI IC3 report released April 2026. Anthropic disclosures published August 2025 and September 2025. Trend Micro research published July 2024. Kaspersky DFI research published 2024. Telefónica Tech analysis published June 2025.
Patterns in this piece
Sources
- CSO Online: AI tools becoming hot commodities on ransomware marketplaces (Halcyon / Infosecurity Europe, June 2026)
- FBI IC3 2025 Annual Report
- Anthropic: Detecting and countering misuse (August 2025)
- Anthropic: Disrupting AI-enabled espionage
- Trend Micro: AI deepfake tools in cybercrime
- Telefónica Tech: How AI is reshaping the dark web economy
- Kaspersky DFI: AI in the darknet
- FBI: Mirai botnet operators sentenced (2018)
- Krebs on Security: Who is Anna-senpai? (2016)
Related Field Notes
The Deepfake Propaganda Pipeline
Multiple sources (12)
A viral video claimed Saint Carlo Acutis predicted three days of darkness. He did not.
Multiple sources (4)
Italy's PM was deepfaked in lingerie. She could defend herself. Most people can't.
Multiple sources (3)