Luciferus Uncensored AI Service Lets Cybercriminals Generate RAT Malware
Sophos reports cybercriminals are selling Luciferus, an uncensored subscription AI service claiming a 120-billion-parameter model that generates RAT code without safeguards.
Sophos Counter Threat Unit observed a user named Optimus_Prime advertising the Luciferus uncensored AI service on August 24, claiming a proprietary 120-billion-parameter model offering unrestricted coding assistance, with tiers priced at $35, $55, and $75. The public website shows different pricing ($22 to $47.14), and Sophos speculates with low confidence the service may be based on Alibaba's Qwen rather than a truly proprietary model. Researchers documented the Junior tier generating a basic Python RAT with network communication and command-execution functionality, though the code was not tested. The service follows the commercialization trend of WormGPT and FraudGPT in cybercriminal ecosystems.
- Advertised August 24 by user Optimus_Prime with Inquisitor, Archdevil, and Prince of Darkness tiers priced $35-$75.
- Claims a proprietary 120-billion-parameter model; Sophos speculates with low confidence it may be Qwen-based.
- Junior tier reportedly generated a basic Python RAT with network communication and command execution.
- Discrepancy between underground ad pricing and website pricing suggests possibly separate operations.
- Follows the WormGPT/FraudGPT trend of subscription AI services lowering the barrier for novice cybercriminals.
Full article552 words · extracted from gbhackers.com · click to collapse
Cybercriminals are promoting a new “uncensored” artificial intelligence service called Luciferus that allegedly generates malicious code, including components for remote access trojans (RATs), without the safeguards typically found in mainstream AI platforms.
Researchers from the Sophos Counter Threat Unit reported that they first noticed a user named “Optimus_Prime” advertising this subscription service on August 24.
Luciferus Uncensored AI Service
The seller described Luciferus as an AI system that responds to requests without moral or ethical constraints. According to the advertisement, the service operates on a proprietary 120-billion-parameter model.
It is designed to provide users with unrestricted assistance for coding and other technical tasks. However, Sophos researchers cautioned that they have not independently verified the claimed model architecture, performance, privacy assurances, or the full range of its advertised capabilities.
With low confidence, Sophos speculates that Luciferus may be based on Qwen, a family of large language models from Alibaba.
The researchers noted that underground operators often market their products as proprietary AI models, even though many such offerings may actually rely on fine-tuned open-source models, customized system prompts, or orchestration layers built around existing foundation models.
Creating a truly new large language model requires considerable computing power, specialized expertise, vast datasets, and significant financial investment.
Thus, treat claims about exclusive or proprietary cybercriminal AI systems with caution. Nonetheless, even a repackaged open-source model set up to bypass safety restrictions can pose operational risks by making malicious technical guidance more accessible.
The Luciferus advertisement listed three subscription tiers: Inquisitor for $35, Archdevil for $55, and Prince of Darkness for $75.
It also promoted a VIP offering called “Individual Embodiment,” which allegedly includes a separately deployed personal model, custom training on the user’s data, dedicated computing resources, and options for user-defined context windows and response temperatures.
Interestingly, the public Luciferus website displayed a different pricing structure, advertising Junior, Middle, and Pro plans priced at $22, $34.75, and $47.14, respectively.

This discrepancy may suggest that the underground advertisement and public service are developing independently, or that the operator uses varying prices and branding for different audiences.
Most notably, Sophos documented a response from the Junior tier to a specific request for a simple Python RAT.
The response, written in Russian, reportedly introduced a basic remote-access tool and generated code with network communication and command-execution functionality. Researchers redacted the code and did not execute, test, or evaluate whether it was complete or functional.
Luciferus represents the increasing commercialization of AI within cybercriminal ecosystems. Threat actors have previously advertised jailbroken versions of ChatGPT and Claude, along with services like WormGPT and FraudGPT, for activities such as phishing, business email compromise, malicious scripting, and malware development.
Unlike services that aim to bypass safety measures in legitimate hosted models, Luciferus appears to be a purpose-built, locally hosted unrestricted AI offering.
Such services lower the technical barrier for inexperienced criminals, enabling them to obtain malware-related guidance and social engineering content through a subscription model akin to malware-as-a-service and phishing kit operations.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/luciferus-uncensored-ai-service/