{"slug": "messiahgpt-criminal-ai-ransomware-tool-exposed-by-trellix", "title": "MessiahGPT Criminal AI Ransomware Tool Exposed by Trellix", "summary": "Trellix researchers exposed MessiahGPT, a criminal AI service on BreachForums selling ransomware, rootkits, and credential stealers for as little as $8 per month, with 50 free prompts available without an account. The platform, accessible via a web portal and Telegram, generates working malicious payloads by omitting safety frameworks, marking a shift toward affordable, easy-to-use cyberattack tools. This follows a pattern of unaligned AI services like WormGPT and FraudGPT, with Europol documenting over 120 ransomware strains in 2025 and FBI reporting $3.046 billion in business email compromise losses that year.", "body_md": "**August 17, 2026**, (Inside AI) — A new criminal AI service called **MessiahGPT** is selling ransomware, rootkits, and credential stealers on **BreachForums** for as little as **$8** a month. Security researchers at **Trellix** exposed the platform, which also gives away **50** free prompts without requiring an account.\n\nThe tool runs through a web portal at messiahgpt[.]de and an active **Telegram** channel. Its creator claims the underlying model was built from scratch without moral boundaries. Unlike commercial assistants, it skips **Reinforcement Learning from Human Feedback**, omits safety frameworks, and blocks no malicious requests.\n\nThis is not a theoretical risk. Trellix confirmed the service produces working payloads that cybercriminals find useful enough to buy. The training corpus allegedly includes dark-web repositories, raw web data, leaked manuals, and unedited guides. Those architectural claims remain unverified, but the output speaks for itself.\n\nThe discovery matters because it marks a shift in who can launch sophisticated attacks. MessiahGPT does not rely on advanced engineering. Its real breakthrough is affordability and ease of use. A freemium model borrowed from software-as-a-service playbooks turns cyberattack capabilities into everyday consumer goods.\n\nThis fits a pattern. In **2023**, **WormGPT** appeared on underground boards to support business email compromise schemes. **FraudGPT** followed, selling for up to **$1,700** a year to generate malware and phishing sites. **DarkBERT** has also been co-opted by bad actors for social engineering and malware. Hackers have already proven they will pay for unaligned AI.\n\n## Cheap access fuels a phishing arms race\n\nGenerative AI lets attackers alter phishing messages, fake websites, and malicious scripts in real time. Every changed instance evades basic security filters that look for signatures or fixed phrasing. Advanced phishing-as-a-service frameworks now add browser fingerprinting, anti-bot mechanisms, rotating **CAPTCHAs**, and hosting filters to dodge detection.\n\nLaw enforcement has sounded alarms. **Europol** documented more than **120** distinct ransomware strains active during **2025**. The **FBI** reported that business email compromise cost victims **$3.046 billion** in damages that same year. MessiahGPT lowers the barrier further, putting these tools within reach of low-skill criminals.\n\nTrellix researchers uncovered the platform while tracking illicit AI services on underground forums. The subscription runs on crypto payments, which complicates attribution and takedowns. The free tier acts as a gateway, letting potential buyers test malware generation before committing funds.\n\nThe service also highlights a structural gap. Commercial AI vendors invest heavily in safety layers. Criminal developers have no incentive to do the same. They can strip alignment, fine-tune on harmful data, and sell access without legal consequence. MessiahGPT is the latest proof that this underground economy is maturing.\n\nWhat comes next is unclear. Takedowns of such services are rare and often temporary. New domains and Telegram channels appear quickly. The more pressing question is whether defenders can adapt faster than attackers can subscribe.", "url": "https://wpnews.pro/news/messiahgpt-criminal-ai-ransomware-tool-exposed-by-trellix", "canonical_source": "https://insideai.news/news/cybersecurity-ai/messiahgpt-criminal-ai-ransomware-tool-exposed-by-trellix/8005/", "published_at": "2026-08-17 13:37:19+00:00", "updated_at": "2026-08-17 13:43:28.544591+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy"], "entities": ["Trellix", "MessiahGPT", "BreachForums", "Telegram", "Europol", "FBI", "WormGPT", "FraudGPT"], "alternates": {"html": "https://wpnews.pro/news/messiahgpt-criminal-ai-ransomware-tool-exposed-by-trellix", "markdown": "https://wpnews.pro/news/messiahgpt-criminal-ai-ransomware-tool-exposed-by-trellix.md", "text": "https://wpnews.pro/news/messiahgpt-criminal-ai-ransomware-tool-exposed-by-trellix.txt", "jsonld": "https://wpnews.pro/news/messiahgpt-criminal-ai-ransomware-tool-exposed-by-trellix.jsonld"}}