Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime


The underground market for criminally oriented generative AI has moved beyond the early hype surrounding ‘malicious chatbots.’ The gradual integration of AI as a productivity layer within cybercrime operations has become the dominant story, indicating that while the potential for fully autonomous AI hacking systems is possible, attackers are not embracing them as expected. Instead, threat actors are increasingly using AI to accelerate routine, but operationally significant, tasks to scale their operations. Drafting phishing lures, profiling targets, debugging code, generating forged documents, modifying malware, translating victim communications, and processing stolen data at scale were once time-consuming activities that AI has made significantly easier. AI does not replace cybercriminals; it lowers friction, increases speed, and expands the range of actors able to perform tasks that previously required more time, skill, or external support.

Read more…
Source:  Rapid7 News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Grinchbots strike again this holiday shopping season as bot traffic spikes 73%

    December 8, 2021

    The days are getting chilly, holiday drinks are back on the menu at your favorite café and family gatherings are planned. In an almost pavlovian response, Grinchbots have also returned in record levels to ruin your online holiday shopping experience. In the State of Security Within eCommerce in 2021, Imperva Research Labs predicted that bad bots ...

  • US Cyber Command head confirms direct actions against ransomware gangs

    December 8, 2021

    General Paul M. Nakasone, head of US Cyber Command confirmed during a recent national security event that his agency has begun taking direct action against international ransomware gangs as part of a larger effort to curtail attacks on American companies and infrastructure. The General explained that his agency is working hand-in-hand with the NSA, FBI, and ...

  • Inside the criminal groups using disinformation to sell fake COVID passes

    December 8, 2021

    “For all those who do not wish to be vaccinated, here is an alternative.” This is how fake or fraudulent EU COVID certificates are being advertised online by criminal groups. Sky News has found evidence of these passes, which could be used as proof of vaccination to enter the UK, being advertised in at least nine European ...

  • Tor blocked in Russia

    December 8, 2021

    The Tor browser, which allows users to surf the internet anonymously and access prohibited webpages, has been blocked across much of Russia, according to recent reports from an internet-monitoring group. The Open Observatory of Network Interference, or OONI, reported last week that Tor’s system of proxy servers in Russia had partly stopped working at around 5:21pm ...

  • When Scammers Get Scammed, They Take It to Cybercrime Court

    December 7, 2021

    Blocked from legitimate courts, cybercriminals have set up their own system for settling disputes, handing over ultimate decision-making to senior underground forum administrators who have awarded claims totaling as much as $20 million. A new report from Analyst1 details activities inside these underground systems and found more than 600 requests for mediation on just one Russian-language ...

  • Canadian indicted for launching ransomware attacks on orgs in US, Canada

    December 7, 2021

    The FBI and Justice Department unsealed indictments today leveling a number of charges against 31-year-old Canadian Matthew Philbert for his alleged involvement in several ransomware attacks. Officials from the Ontario Provincial Police held a press conference on Tuesday to announce the charges and Philbert’s arrest in Ottawa. In a statement, US Attorney Bryan Wilson of the District ...