On August 24 a persona calling itself Optimus_Prime posted an advertisement on Exploit, a long-running Russian-language cybercrime forum, for a subscription service called Luciferus. The pitch was that it answers anything. No moral restrictions, no ethical guardrails, three price tiers, and a claim that it runs on a proprietary model with 120 billion parameters.
Researchers asked it for a remote access trojan. It wrote one.
Not a jailbreak, a product
The Sophos Counter Threat Unit research team, which spotted the listing, draws a distinction that matters more than it first appears. CTU has previously watched criminals advertise "jailbroken" versions of ChatGPT and Claude, mainstream models talked out of their own safety rules. Luciferus is sold as something else: a model designed or configured without safeguards from the outset. Sophos frames the difference as control, persistence, and the ability to tailor the service to a particular community of users, which in this case means a cybercrime forum.
Sophos is careful about what it did not check. CTU researchers say they did not independently verify the model architecture, the parameter count, the performance, the privacy claims or the advertised capabilities. They assess with low confidence that Luciferus is built on Qwen, the large language model family developed by Alibaba. They also note that "proprietary model" is a claim that rarely survives contact, because training a genuinely new foundation model takes expertise, data and computing power a forum vendor is unlikely to have. Services like this are usually a fine-tuned open-source model, a custom system prompt, or an orchestration layer over somebody else's weights.
Two price lists, two sets of names
The forum advertisement offers three monthly tiers, named Inquisitor at $35, Archdeviel at $55 and Prince of Darkness at $75, plus an "Individual Embodiment" VIP level promising a privately deployed model, custom training on the buyer's own data, dedicated computing power not shared with other users, and full control over the context window and response temperature. That one is priced on request. The service's own website tells a different story: the VIP option is not mentioned at all, and the three tiers are called Junior, Middle and Pro at $22, $34.75 and $47.14.
The RAT it wrote on request
Sophos published the model's answer to a plain prompt for a "simple RAT in python". The Junior tier replied in Russian with a description of a simple Python remote access trojan, walked through its networking and command execution functionality, and then listed source code. Sophos redacted that code in its report, and says CTU researchers did not execute it, test it, or assess how complete it was. What the exchange establishes is narrower than a working weapon but still the point: the service does what the advertisement says it does, and answers an overt request for malware development without argument.
Why a criminal would bother paying
Luciferus lands in a market that has been forming for a while. WormGPT and FraudGPT were sold the same way, as unrestricted alternatives to ChatGPT capable of producing phishing emails, business email compromise lures, malicious scripts and malware code. Sophos reports a steady increase in forum posts advertising AI-enabled services, dedicated AI discussion channels, and recruitment drives seeking AI specialists to support criminal operations. Some vendors sell brokered access to legitimate AI platforms or trade API keys instead, a pattern visible when attackers pulled AI proxy keys straight out of memory, and a Brazilian crew has already wired a chatbot into its marketplace for access to hacked companies.
There is no patch for a price list
Nothing here is a vulnerability, so there is nothing to update and no indicator to block. What changes is the floor. A $22 monthly subscription puts malware source code in front of someone who could not have written it, and Sophos makes no claim about whether that code was any good, so the reasonable expectation is more low-skill activity rather than better activity. The tracking details worth keeping are in the report: the Optimus_Prime persona joined Exploit on April 18, carries a "coding / coder" activity label, and had published 21 posts by September 4.
What is new is not that criminals can get an AI to help them. It is that the help now arrives as a product, with tiers, a website and a monthly bill, which is the shape every other criminal service settled into shortly before it scaled.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.