- Halcyon tracked nearly 4,000 underground posts from October 2025 to April 2026. It found AI crime tools sold with free tiers, subscriptions and automated storefronts.
- The tools lower the skill bar for phishing, voice fraud and malware, so defenses that rely on attacker mistakes are weaker.
- Leaders should test voice and video approval steps, and ask teams whether detection looks at behavior rather than bad grammar.
Security teams have long assumed that good attacks take skill, and skill is scarce. Halcyon, a ransomware research group, calls skilled labor the limiting factor in cybercrime. Its new report says AI is easing that limit. The lesson here is that criminals now run a software business. Their customers need less skill than they used to.
Crime copied the software playbook
Halcyon's Ransomware Research Center gathered nearly 4,000 posts between October 2025 and April 2026. The posts came from more than 100 sources. Most were Telegram channels. The rest were dark web forums and underground markets.
Activity was small for most of late 2025. It rose in January 2026 and rose again from February to April. Rappler's account of the research puts monthly tool ads below 50 in late 2025 and above 1,400 by February.
The sales methods look familiar. Halcyon found that 40% of messages advertised free tools. Another 30% listed prices. One vendor on wormgpt.site sells monthly plans at $9.99, $19.99 and $49.99. It also offers a $500 lifetime plan and runs 24-hour promotions.
Automation does the selling too. Nine bot accounts produced 15.8% of the Telegram activity in the dataset. They work like storefronts that never close.
How the tools work
"Dark LLMs" are language models without the safety limits of mainstream chatbots. The first ones were jailbroken wrappers around commercial services. Over time, makers moved to their own servers. Some trained models on harmful data. Others took open-source models and removed the safety training.
Voice shows the change best. One Russian-language forum ad offered an automated calling system. It links to 3CX phone infrastructure and speaks up to 25 languages. It can place 120 calls at once. A buyer loads names from a spreadsheet, and the system greets each target by name. Live transcripts arrive on Telegram.
Identity fraud tools go after verification checks. Halcyon says vendors studied liveness checks, where a user must turn their head or speak a phrase. They then built services to beat each one. Halcyon also says a three-second recording can be enough to clone a voice.
Access is cheap. The median price for stolen AI account access was $0.10. Working jailbreaks sold for as little as $10 to $15. Halcyon also documented an AI-built malware framework of about 88,000 lines of code. It was produced in under a week with ByteDance's TRAE assistant.
What changes inside an organization
Halcyon argues that none of this created new kinds of crime. Phishing, business email compromise and identity fraud predate generative AI. What changed is the cost of carrying them out.
That matters for training. Halcyon says the usual phishing tells, such as poor grammar and awkward phrasing, are no longer reliable. It also says email defenses and awareness training alone cannot stop AI-generated voice calls.
The cited losses are large. A deepfake Zoom call cost a Singapore firm $499,000. A cloned CFO voice cost a European energy company $25 million. Halcyon notes that its screenshots do not show the tools used in those cases. They show the same category of tool, sold openly.
What the report did not find
The evidence has limits. The dataset is made of posts, so it cannot show victims or completed sales. Halcyon saw no ads for AI malware that rewrites itself to evade detection. It calls that capability theoretical for now, though it expects it to arrive.
Skill has not stopped mattering. Halcyon says frontier models quickly catch many jailbreak prompts, which makes many advertised ones obsolete. Rappler quotes the researchers saying results are "often cruder." Two ransomware crews built malware they could not decrypt. Even so, Halcyon's point is that a flawed tool still hands a novice a skill they did not have.
The market carries its own risk. The WormGPT.AI service was breached in February 2026. More than 19,000 user records appeared on hacker forums. Halcyon also found infostealer malware running on the machines of people who use these tools.
Questions to put to your team
Start with approvals. Can one phone call or video meeting move money or reset access? If so, require a callback to a known number or a second approver.
Next, ask your identity vendor how it tests liveness checks against deepfakes. Then ask whether detection depends on how a message reads or on what the account does. Halcyon recommends shifting from content-based to behavioral indicators.
Finally, retire the old training slogan. Staff taught to spot bad grammar need a new rule: verify the request, not the writing.
Halcyon's 88,000-line malware framework shows the shift. Work that once took professional teams months came together in under a week. A novice with a bought tool can now attempt work that once took skilled teams months. Defenses that wait for the attacker to slip up will have less to catch.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Halcyon Ransomware Research Center.





