An AI subscription service advertised on an underground forum is offering users access to a chatbot without ethical restrictions, according to new research from Sophos X-Ops.
Sophos Counter Threat Unit (CTU) researchers found an advertisement for the service, called Luciferus, on the Exploit forum on Aug. 24, 2026. The advertiser claimed it runs on a proprietary AI model with 120 billion parameters, a measure of a model’s size. Sophos said it has not independently verified that claim or the service’s performance, privacy claims, and other advertised capabilities.
The finding shows how sellers in the underground market are trying to turn AI into a paid cybercrime service, alongside tools such as phishing kits and ransomware. For businesses, the concern is that such services could make it easier for people with limited technical skills to develop or adapt attacks.
“Luciferus shows how quickly the underground economy is trying to package AI into a cybercrime service model,” said Aiden Sinnott, senior threat researcher, Sophos Counter Threat Unit. The concern is not just that an AI tool can answer a malicious prompt, but that access is being marketed, tiered, and sold in a way that could make offensive capabilities easier for less technical actors to reach,”
The advertisement presents Luciferus as an uncensored AI model, rather than a mainstream chatbot whose safeguards have been bypassed. CTU researchers also observed a version called Luciferus Junior respond to a request for a simple Python remote access trojan, a program that can give an attacker control of another computer.
That response shows the model was willing to address the request. It does not establish whether the resulting code worked or whether Luciferus has been used in an attack.

