Close Menu
  • Cyber security
    • Malware
    • Mobile security
  • Computer Security
  • Cyber news
    • Data breaches
  • Cyber law & Compliance
  • About us
Facebook X (Twitter) Instagram Threads
Facebook X (Twitter) Instagram
Cyber infos
Join us
  • Cyber security
    • Malware
    • Mobile security
  • Computer Security
  • Cyber news
    • Data breaches
  • Cyber law & Compliance
  • About us
Cyber infos
Home » AI Tools Promoted by Threat Actors: How Artificial Intelligence Is Fueling a New Era of Cybercrime
Cyber news

AI Tools Promoted by Threat Actors: How Artificial Intelligence Is Fueling a New Era of Cybercrime

When intelligence turns against its creator — AI’s dark evolution in the world of cybercrime.
Cyber infosBy Cyber infosNovember 7, 2025No Comments4 Mins Read
Share Facebook Twitter WhatsApp Pinterest Email LinkedIn Copy Link Threads Reddit Telegram
Follow Us
WhatsApp X (Twitter) Instagram LinkedIn Telegram
Share
WhatsApp Facebook Twitter LinkedIn Email Telegram Copy Link Pinterest Threads Reddit
The dark corners of the internet are evolving and fast. In 2025, artificial intelligence (AI) isn’t just a tool for innovation; it’s also one of the most powerful weapons in the hands of cybercriminals that is AI tools
A recent report by Google’s Threat Intelligence Group (GTIG) reveals that AI-based hacking tools are being actively promoted in underground forums, transforming how cybercrime is executed. What used to require advanced technical skills can now be done by anyone with access to these AI-driven platforms.
Table of Contents hide
1 The Underground AI Boom
2 WormGPT — The Blackhat Pioneer
3 FraudGPT — The AI-as-a-Service Model
4 Xanthorox AI — The “Killer of WormGPT”
5 NYTHEON AI — The Rise of GenAI-as-a-Service
6 AI-Powered Phishing and Malware Development
7 The Subscription Economy of Cybercrime
8 A Dangerous Future
9 Final thoughts

The Underground AI Boom

According to cybersecurity researchers at KELA, discussions around AI-powered hacking tools increased by over 200% in 2024 — and the momentum has only grown through 2025. The surge marks a major shift in how hackers operate, with underground markets offering AI services designed to automate phishing, malware development, and social engineering.

Among the most popular tools in circulation are WormGPT, FraudGPT, Evil-GPT, Xanthorox AI, and NYTHEON AI — each crafted for a specific purpose in the cyberattack chain.

WormGPT — The Blackhat Pioneer

Launched in mid-2023, WormGPT quickly became infamous for its ability to create realistic phishing and BEC (Business Email Compromise) emails. Built on the GPT-J model, the tool was marketed as a “blackhat alternative” to ChatGPT, capable of crafting convincing corporate messages that easily slip past spam filters.

Subscriptions range from $100 per month to $5,000 for private access, making it accessible to a wide range of attackers. In several documented cases, WormGPT was used to impersonate executives and trick employees into authorizing fraudulent transactions — a new low in digital deception.

FraudGPT — The AI-as-a-Service Model

Following closely was FraudGPT, launched in July 2023 by the underground seller “CanadianKingpin12.” This AI tool offered a subscription model similar to legitimate SaaS platforms — $200 per month or $1,700 annually complete with customer support, tutorials, and premium feature tiers.

FraudGPT could generate malicious code, identify vulnerabilities, and even teach hacking methods. At higher tiers, users gained access to API integrations, image generation, and Discord connectivity. Its success marked the moment when cybercrime adopted the polished professionalism of the tech industry.

AI Tools Promoted by Threat Actors: How Artificial Intelligence Is Fueling a New Era of Cybercrime

Xanthorox AI — The “Killer of WormGPT”

By early 2025, new entrants like Xanthorox AI appeared, boasting modular design and enhanced stealth. Marketed as the “Killer of WormGPT,” Xanthorox runs entirely on private, self-hosted servers, making detection nearly impossible.

The platform offers a full range of capabilities, from phishing and deepfake generation to malware creation and vulnerability scanning. Its developers claim it delivers an all-in-one AI hacking environment — and unfortunately, that claim seems accurate.

NYTHEON AI — The Rise of GenAI-as-a-Service

NYTHEON AI represents another step forward — or backward, depending on perspective. Operated through the dark web and Telegram channels, NYTHEON combines several legitimate open-source AI models into a unified malicious framework.

It includes six specialized modules: Nytheon Coder (for generating malicious code), Nytheon Vision (for image recognition), and Nytheon R1 (for reasoning tasks). This modular structure offers hackers unprecedented flexibility and efficiency, resembling the AI capabilities used by ethical developers — but with criminal intent.

AI-Powered Phishing and Malware Development

Phishing remains the top weapon of choice among cybercriminals. Security analysts report a 1,265% surge in AI-generated phishing attacks, with many proving just as effective as those written by humans — but produced in seconds.

Tools such as WormGPT and MalwareGPT are also enabling polymorphic malware that continuously changes its code to evade detection. Google’s research identified five new malware families in 2025 using AI to rewrite their own code, rendering traditional antivirus systems less effective.

The Subscription Economy of Cybercrime

Underground AI developers are now copying the business strategies of legitimate software firms. They offer tiered pricing, free trials, customer support, and regular updates — transforming cybercrime into a fully operational economy.

Tools like Evil-GPT are sold for as little as $10, proving that advanced attack capabilities are now accessible to almost anyone with malicious intent.

A Dangerous Future

Authorities such as the FBI warn that AI has dramatically accelerated the pace and sophistication of cyberattacks. In early 2025, AI-assisted phishing made up more than 80% of global social engineering campaigns, a staggering indication of how deeply AI has infiltrated cybercrime.

Final thoughts

The rise of WormGPT, FraudGPT, Xanthorox AI, and NYTHEON AI signals a pivotal shift in cybersecurity. Artificial intelligence, once used to defend networks, is now equally effective in breaching them. As these underground markets mature, defenders must adapt quickly — deploying AI-driven defense strategies and real-time threat intelligence to stay ahead of this growing menace.

Follow Cyberinfos for daily updates on AI-driven threats, vulnerability reports, and digital defense strategies. 

Follow on X (Twitter) Follow on Instagram Follow on LinkedIn Follow on WhatsApp Follow on Telegram
Share. Twitter Email WhatsApp Copy Link
Previous ArticlePentest Copilot: AI-Powered Ethical Hacking Tool Redefining Penetration Testing
Next Article Google Maps Review Extortion: New Feature Lets Businesses Report Fake Reviews and Scams
Cyber infos
  • Website

Related Posts

Cyber news

Android Photo Frames Malware: A Hidden Threat to Your Home Network

November 15, 2025
Cyber news

Google Maps Review Extortion: New Feature Lets Businesses Report Fake Reviews and Scams

November 9, 2025
Cyber news

Pentest Copilot: AI-Powered Ethical Hacking Tool Redefining Penetration Testing

October 30, 2025
Add A Comment
Leave A Reply Cancel Reply

Search
Recent post
  • Android Photo Frames Malware: A Hidden Threat to Your Home Network
  • Top 10 Best Autonomous Endpoint Management Tools in 2025
  • Google Maps Review Extortion: New Feature Lets Businesses Report Fake Reviews and Scams
  • AI Tools Promoted by Threat Actors: How Artificial Intelligence Is Fueling a New Era of Cybercrime
  • Pentest Copilot: AI-Powered Ethical Hacking Tool Redefining Penetration Testing
  • Top 10 Best API Security Testing Tools in 2025
Archives
Recents

Android Photo Frames Malware: A Hidden Threat to Your Home Network

November 15, 2025

Top 10 Best Autonomous Endpoint Management Tools in 2025

November 14, 2025

Google Maps Review Extortion: New Feature Lets Businesses Report Fake Reviews and Scams

November 9, 2025

AI Tools Promoted by Threat Actors: How Artificial Intelligence Is Fueling a New Era of Cybercrime

November 7, 2025
Pages
  • About us
  • Contact us
  • Disclaimer
  • Privacy policy
  • Sitemaps
  • Terms and conditions
Facebook X (Twitter) Instagram Pinterest WhatsApp
  • About us
  • Contact us
  • Sitemaps
© 2025 Cyberinfos - All rights are reserved

Type above and press Enter to search. Press Esc to cancel.