ESPNDon't look now, Michiganders, but you're back in the Bottom 10RTP Desporto12h30 Aviso a CR7: "Jesus não vira cara à luta"The Jerusalem PostMaine Senate candidate Troy Jackson opposes US giving Israel 'blank check'PunchTinubu mourns NADECO chieftain Ralph ObiohaVanguardIGP Disu mourns 25 NAF personnel, passengers killed in crashRapplerAnyare? Villars’ AllHome, AllDay confirm store closuresCollider‘Carrie’s Mike Flanagan Confirms Why He Made a Major Change From Stephen King’s BookSouth China Morning PostChinese consortium to build Latin America’s longest cable-stayed bridge in BrazilZDF heuteAktuelle Pressemitteilungen des ZDFVariety‘In the Shadows’ Producers to Self-Release British Boxing Biopic Following Collapse of U.K. Distributor True Brit Entertainment (EXCLUSIVE)UN NewsWHO releases first global guidelines on child obesity as cases surgeTagesschauFrüherer BND-Präsident Hanning muss in Untersuchungshaft
The Daily Newsstand · Free, Always
Wednesday, October 7, 2026

Underground AI cybercrime tools surge in 2026

Translate

Underground AI cybercrime tools surge in 2026

AI is making phishing, voice scams, identity fraud, and malware development cheaper and easier to scale, while lowering the technical barrier for cybercriminals

AT A GLANCE

  • Artificial intelligence is making cybercrime tools more accessible, enabling less-skilled attackers to engage in phishing, identity fraud, and malware development.
  • AI is enhancing the capabilities of cybercriminals, allowing them to conduct sophisticated attacks.

This is AI-generated. Read the article for full context. Report any errors.

MANILA, Philippines – Artificial intelligence is making cybercrime tools cheaper, easier to use, and more widely available, helping less-skilled attackers carry out phishing, identity fraud, and malware development at greater scale, according to research from the US-based Halcyon Ransomware Research Center.

Halcyon tracked nearly 4,000 posts across 77 Telegram channels, 20 dark web forums, and five underground markets between October 2025 and May 2026. It found that messages advertising AI-related cybercrime tools rose from fewer than 50 per month in late 2025 to more than 1,400 by February 2026.

The researchers said the underground market had rapidly developed many of the features of legitimate software businesses, including subscriptions, free tiers, automated storefronts, and multi-platform distribution.

Halcyon grouped the tools into four categories: weaponized large language models (LLMs), AI-enabled identity fraud, AI-assisted malware and attack infrastructure, and jailbroken or stolen AI services.

One of the biggest changes is the reduced technical barrier to carrying out attacks. “AI supplies skills [would-be hackers] never had. The results are often cruder (two ransomware crews have accidentally built malware they could not decrypt), but some capability beats none, and each tool for sale lowers the bar further,” Halcyon said.

AI tools can generate phishing messages, malicious code, and fraud scripts, while also helping attackers work in languages they may not speak. Halcyon said this allows inexperienced actors to perform tasks that previously required stronger technical skills, language ability, or operational experience.

In one striking example, Halcyon identified an AI-powered outbound call center advertised on a Russian-language hacker forum that could make up to 120 calls at the same time and communicate in as many as 25 languages. Operators could upload victim names and contact details through spreadsheets, while the system could address targets by name, generate human-like call center sounds, and provide live transcripts through Telegram and a web dashboard.

The researchers said the system represents a shift from AI being used mainly to generate written phishing content to conducting live conversations over professional telephony systems. This has resulted in some successful attacks. “One deepfake Zoom call resulted in a Singapore firm losing $499,000. A European energy company lost $25 million from a single cloned CFO voice,” Halcyon said.

Voice cloning adds another risk. Halcyon said some voice-cloning technology can reproduce a person’s voice using as little as three seconds of audio, making it easier for attackers to impersonate executives, employees, relatives, or other trusted contacts.

Halcyon found vendors selling deepfake video, voice editing, synthetic documents, and tools designed to bypass identity verification systems used by banks and online platforms. Some vendors advertised deepfake services that could generate head movements, facial expressions, and other responses intended to defeat “liveness” checks during online verification.

AI is also accelerating malware development. Halcyon documented one malware framework containing about 88,000 lines of functional code that a vendor said had been produced in less than a week using an AI development assistant — work that without AI would have taken a professional team months to create.

However, Halcyon said it did not find evidence of criminals selling AI systems capable of independently carrying out fully autonomous cyberattacks. It did not observe tools explicitly advertising AI-powered “polymorphic” malware that could rewrite itself to evade signature-based detection, suggesting that some of the most advanced AI attack capabilities remain more theoretical than commercially available in the underground market.

But Halcyon warned: “Given the underground market demand for such a capability, we assess it is a matter of when, not if, such tools become available.”

Stolen accounts for popular services such as ChatGPT and jailbreak prompts meant to defeat guardrails were also being sold at very low prices, with the median price for stolen or jailbroken services at around $0.10.

Defending ourselves

What can people and organizations do? Halcyon said we can no longer rely on traditional phishing warning signs, such as poor grammar, awkward phrasing, and generic greetings, as AI-generated messages become more fluent and contextually appropriate.

It recommended that organizations shift from relying mainly on the content of messages to looking at behavior and verification patterns. These include unusual transaction requests, unexpected credential demands, and deviations from normal communication procedures.

With the rise of sophisticated video and audio phishing, Halcyon also recommended mandatory “out-of-band verification” for sensitive requests, wherein confirmation of a request is made through a separate communication channel from the one where the request came in.

Security teams should also prepare for a higher volume of attacks from less-skilled operators.

The researchers said AI has not created fundamentally new forms of cybercrime. Instead, it is reducing the time, cost, and expertise needed to carry out existing attacks while allowing criminals to operate at greater scale. – Rappler.com

View the original on Rappler →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.