CyberSecurityNews

New MessiahGPT AI Model Fueling Automated Ransomware and Phishing Attacks


A criminal AI service called MessiahGPT is being marketed on BreachForums as an uncensored platform for creating ransomware, phishing kits, stealers, crypters, rootkits, and social-engineering content.

Trellix researchers describe it as part of a growing underground market that turns offensive AI capabilities into a cheap subscription service.

MessiahGPT is advertised as a model built without the safety protections used by mainstream AI platforms. Its operators claim it has no Reinforcement Learning from Human Feedback, Constitutional AI controls, or internal restrictions related to illegal or harmful requests.

The service is linked to a live website, messiahgpt[.]de, and an associated Telegram community, and its marketing reportedly targets users seeking assistance with malware development and fraud.

According to the advertised specifications, MessiahGPT uses a Mixture-of-Experts design with 128 experts, activating 16 experts for each token. The operators claim the model was trained on unrestricted manuals, dark-web archives, leaked documentation, and raw web data.

MessiahGPT Fueling Attacks

However, Trellix cautions that the operators’ technical claims cannot be independently verified. Researchers confirmed that the platform is active and being openly promoted in criminal communities.

The business model lowers the barrier to entry for cybercrime. MessiahGPT reportedly offers free queries without registration, followed by cryptocurrency-only subscriptions starting at around $8 per month.

This allows inexperienced attackers to test prompts for phishing content, malicious scripts, or other harmful material before paying for continued access. The greater risk is not simply the creation of a single malware family.

AI-assisted services can help attackers rapidly produce variations of phishing emails, landing pages, scripts, and malicious code. These variations can reduce the effectiveness of static filters that depend on known phrases, file hashes, or previously seen templates.

A phishing lure can be rewritten repeatedly for different departments, languages, brands, and business scenarios, making campaign detection more difficult.

Security teams should focus on behavior rather than assuming an AI-generated sample has a unique signature. Email protections should inspect sender reputation, authentication failures, link behavior, attachment detonation results, and unusual login requests.

Endpoint defenses should monitor suspicious processes, privilege changes, mass file modification, credential access attempts, and unexpected encryption activity.

Network controls also matter. Organizations should use DNS logging, web filtering, and egress controls to identify or block access to known criminal AI infrastructure where appropriate.

Undercode Testing advises analysts to monitor suspicious AI-domain lookups, encrypted outbound traffic, and connections to newly registered or low-reputation domains, while using YARA and signature rules to support not replace behavioral detection and threat hunting.

Rules should target concrete malicious behavior, such as embedded credential theft logic, obfuscated command execution, ransomware file-extension changes, or known command-and-control patterns, rather than attempting to label code as “AI-generated.”

MessiahGPT illustrates the commercial maturity of the criminal AI ecosystem. Defenders should approach claims from underground vendors with caution, but the demand for unrestricted AI tools is real.

Organizations that combine strong identity controls, phishing-resistant authentication, endpoint telemetry, DNS visibility, and tested incident response plans will be better positioned to handle higher-volume, rapidly changing attacks.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.



Source link