Underground forums are now selling AI-powered attack tools that promise nation-state-level planning to anyone willing to pay, according to a report from security firm Trellix. The research details a fast-growing market where AI services lower the skill bar for sophisticated cybercrime.
Among the offerings, an actor known as Shadowx007 sells a service called APEX AI that generates complete attack plans for ransomware deployment after a target domain is entered, including step-by-step commands. Another operator markets Metamorphic Crypter on the Exploit forum, a crypter designed to bypass signature-based detection that its seller claims Windows Defender cannot catch. A third service, MessiahGPT, is being advertised on BreachForums as an AI model with zero ethical constraints, and was previously cited by Accenture and Google Cloud for its ability to generate exploits, payloads, and proof-of-concept code.
For Trellix’s Jambul Tologonov, the tools collapse the expertise gap: what once demanded deep manual understanding of network defenses can now be executed by novices. An attacker who would not know where to begin in a penetration test can get a prioritized attack plan that mirrors advanced persistent threat tradecraft from a single prompt.
Separately, Proofpoint documented indirect prompt injection services sold for about $150 per month. These embed hidden malicious commands in PDFs, emails, web pages, and calendar invites that AI agents process as legitimate instructions, potentially leading to credential theft, data exfiltration, or malware deployment on devices where employee-deployed agents operate.
Proofpoint said current activity is mostly testing and exploration rather than confirmed attacks, but the combination of cheaper AI tooling and agentic workflows expanding into the enterprise is widening the attack surface. For defenders, the report reinforces that AI adoption inside organizations needs the same monitoring, access controls, and incident response coverage as any other endpoint.
