Listings for anything newer can be found on a forum that is located several layers below anything that can be accessed thru a conventional browser, between tutorials on SIM-swapping mobile accounts and ads for stolen payment information. The product names, such as FraudGPT, WormGPT, and branding versions that purposefully borrow from genuine AI products to convey competence, are intended to be identifiable. The product being sold is a language model that has been trained, optimized, or altered to perform tasks that commercial AI systems are specifically designed not to perform: create functional malware without triggering antivirus detection, write convincing phishing emails at scale, and create business email compromise scripts that evade spam filters and end up in inboxes appearing to be authentic correspondence from a CFO.
Since ChatGPT’s inception in late 2022, the market for this type of tooling has been expanding for almost two years, almost perfectly keeping pace with the general public’s increased understanding of massive language models. The relationship is straightforward: when reputable AI tools showed what these systems might generate when given the correct queries, a parallel industry emerged centered on eliminating the limitations that dictate what questions these systems will respond to.

The practice of selling pre-packaged rapid injection techniques that get beyond safety precautions on commercial models is known as “jailbreak-as-a-service,” or “JaaS” in the nomenclature used in cybersecurity publications. Nothing needs to be adjusted. You have access to a version of a commercial model that has been effectively made available for applications that its designers did not intend by paying for a prompt library and a collection of API workarounds.
Beyond that is the market for custom fine-tuning. Here, threat actors retrain open-source base models using illegal datasets, such as Llama variations, Mistral derivatives, and other weights that are available for public distribution. Retraining eliminates resistance mechanisms and increases capacity for limited activities. The final model carries whatever additional capabilities the training data adds, but it lacks all of the original’s safety features. The chain of custody that would support enforcement is broken at the outset as the base model was made available to the public and could be downloaded legally. The altered weights can then be packaged into automation platforms that execute business email compromise campaigns without requiring the operator to have any technical knowledge, sold, or rented as a service.
Security experts are truly concerned about how this final point alters the danger landscape. A cyberattack’s sophistication is correlated with the attacker’s technological prowess. It takes talent to write convincing, customized phishing emails on a large scale. Either coding expertise or connection to someone with it was necessary to generate effective malware. Both benign and malevolent AI tools have separated those prerequisites. Tools that can create personalized deception at a volume previously only achievable for well-resourced operations are available to anyone with a list of email addresses, sufficient funds to pay a forum subscription fee, and little technological expertise. The entry barrier has decreased, and the effects of this decrease are currently being assessed.
An additional attack surface that did not exist eighteen months ago has been added by enterprise AI integration. As businesses integrate AI systems into internal processes, including as internal knowledge retrieval, document processing tools, and customer support bots, those integrations become possible targets for rapid injection attacks. In certain situations, an AI may leak internal data, alter its own outputs, or conduct unauthorized activities if a malicious input that has been meticulously crafted to manipulate the system’s behavior is inserted thru a client request or a document submitted for processing. After years of developing defenses against traditional software flaws, security teams are now handling a type of attack that uses language instead of code.
To put it plainly, the enforcement picture is not comforting. Cybersecurity organizations like CISA and Europol are monitoring the development of the black market and have created guidelines on AI-related risks. However, compared to the rate at which the market is expanding, the legal and technical frameworks for intercepting the spread of deliberately altered AI model weights are still in their infancy. Because many base models are open-source, each updated system’s starting point was lawfully and publicly released, creating evidential and jurisdictional challenges that traditional cybercrime enforcement wasn’t meant to address.
