nathlabs
All posts
· 2 min read

AI-Powered Ransomware Tools Are Flooding Cybercrime Marketplaces

AI-powered ransomware tools are proliferating across cybercrime marketplaces, with listings surging from dozens to over a thousand in months. Weaponized LLMs, deepfake identity fraud, and stolen AI services are lowering the barrier for attacks, while ransomware profits have jumped nearly 40% year-over-year.

AI-Powered Ransomware Tools Are Flooding Cybercrime Marketplaces

AI-powered tools inundate ransomware forums

Sales of AI-based tools are accelerating within underground ransomware marketplaces, according to an analysis by anti-ransomware platform vendor Halcyon. The firm tracked Telegram channels, 20 dark web forums, and five underground markets and found that posts offering AI utilities surged from just 38 in December 2025 to 1,486 in February 2026.

Four classes of weaponized AI

The AI tools on offer fall into four broad categories:

  • Weaponized LLMs: So-called “dark LLMs” that strip away safety guardrails and rules. “WormGPT” is the most recognized brand in this space, though multiple operators use the name—and some are outright scams that collect payments without delivering any service.
  • AI-enabled identity fraud: Voice and video deepfakes designed to defeat selfie-based recognition systems and other KYC controls. The same technology is also deployed in business email compromise (BEC) attacks.
  • AI-augmented malware and attack infrastructure: AI-driven backends that aggregate, process, and exfiltrate stolen data more efficiently.
  • Jailbroken and stolen AI services: This is the largest and cheapest category, consisting of hacked AI accounts.

The barrier to entry keeps dropping

Halcyon estimates that ransomware volume has grown 20% since 2023, with smaller enterprises now bearing 80% of attacks. Cynthia Kaiser, SVP of Halcyon’s Ransomware Research Center and former deputy assistant director of the FBI’s Cyber Division, told Infosecurity Europe that largest operators—such as Akira—increasingly mirror legitimate vendors by selling services and infrastructure to affiliates. “Modern ransomware operators don’t need to build their operations from scratch,” she said, noting that the required skill level has dropped markedly.

The criminal “vendor” model

Ransomware groups now sell through multiple channels for redundancy, offer tiered pricing and freemium models, and use Telegram bots to automate sales and marketing. Some even apply AI-based utilities for customer service. Yet this professionalization has limits: Kaiser pointed out that criminal operational security remains porous. In one episode, credentials from a WormGPT instance were stolen by rival cybercriminals and dumped back onto the same forum that originally sold access.

Ransomware profits climb sharply

Separate research from Rapid7 shows that ransomware is becoming more profitable, with payments up 39% between the first quarters of 2025 and 2026. The Qilin group is estimated to have made $193 million between July 2025 and March 2026, while The Gentleman reportedly earned $52 million over the same period—figures derived from average ransom payments and payment rates tracked by CoveWare. Thom Langford, CTO EMEA at Rapid7, described a mature underground marketplace where access, tooling, and full attack services are commercially available. He added that AI-powered social engineering is widely used to craft more convincing phishing lures, and that most principal players “speak Russian.”

What enterprises can do

While law enforcement takedowns slow the growth of ransomware operations, Halcyon advises organizations to focus on denying initial access, detecting lateral movement, and disrupting exfiltration and encryption. Regular tabletop exercises round out a resilience-focused strategy.