MessiahGPT Criminal AI Service Advertised on BreachForums

MessiahGPT Criminal AI Service Advertised on BreachForums

Trellix details MessiahGPT, an unrestricted criminal AI platform offering malware, phishing and fraud assistance through 50 free queries and paid plans from $8.

Listen to this article

0:00

Press play to start listening

A cybercriminal AI service called MessiahGPT is being advertised on BreachForums as an unrestricted platform for generating malware, phishing material, and other illegal content, according to new research from Trellix.

MessiahGPT operates through messiahgpt.de and has an associated Telegram community. Trellix said the platform was live when its researchers examined it, offering 50 free queries without registration. Paid plans start at $8 per month, with cryptocurrency accepted and no identity verification required.

MessiahGPT Criminal AI Service Advertised on BreachForums
Screenshot from the official website of MessiahGPT (Image credit: Hackread.com)

MessiahGPT Claims to Remove AI Safety Controls

The service is marketed as a custom-built model without Reinforcement Learning from Human Feedback, commonly known as RLHF, or Constitutional AI. These methods are used by commercial AI companies to guide model behaviour and limit harmful responses.

Its operator claims the model was trained from scratch using unrestricted manuals, dark web archives, leaked documentation and raw internet data without post-training filters. The advertised architecture uses a Mixture-of-Experts design containing 128 experts, with 16 activated for each token processed.

Trellix could not independently verify the model’s architecture, training data, or performance. The advertised specifications should therefore be treated as claims made by the service operator, not confirmed technical findings.

Unlike a jailbreak prompt applied to a public chatbot, MessiahGPT is presented as a dedicated criminal service. Its operators control the website, payment system and claimed model infrastructure, reducing their dependence on accounts that commercial AI providers can suspend.

Malware, Phishing and Fraud Advertised as Features

MessiahGPT’s advertisements list ransomware, information stealers, crypters and rootkits among its claimed capabilities. The service also promotes phishing kit generation, social-engineering scripts, fraud guidance, carding instructions and assistance with exploiting stolen data.

More severe advertised uses include physical attack planning and instructions involving chemical or explosive materials. Trellix did not report testing these functions or finding confirmed attacks conducted with MessiahGPT.

The service’s promotional material compares MessiahGPT with ChatGPT-4o, DeepSeek-V3 and Mistral-Large. Its operators claim mainstream models refuse requests that MessiahGPT accepts, but no independent benchmark was provided to support the comparison.

Public advertising on the cybercrime and hacker platform BreachForums, a dedicated website, subscription pricing and a Telegram community show how criminal AI services are being packaged like ordinary commercial software. Buyers can test the platform before paying and purchase continued access without supplying conventional billing information.

MessiahGPT Criminal AI Service Advertised on BreachForums
MessiahGPT being sold on BreachForums (Image credit: Trellix)

A Growing Market for Criminal AI Access

MessiahGPT was one of several AI-powered tools identified by the Trellix Advanced Research Center during the first half of 2026.

DarkGPT is being promoted in Russian-language Telegram channels with three free queries and paid access to an uncensored chatbot. Trellix said it could not determine whether DarkGPT uses a modified local model or acts as a wrapper around another AI service.

Another offering, APEX AI, is advertised as a self-hosted system that creates attack plans from a target domain. Trellix also documented a claimed APEX AI-generated exploit for the WinRAR vulnerability CVE-2025-8088, although the company did not independently confirm every claim made by its seller.

MessiahGPT Criminal AI Service Advertised on BreachForums
APEX AI being sold on DarkForums, another cybercrime forum (Image credit: Hackread.com)

Criminals are also buying stolen access to legitimate platforms. Trellix observed an Exploit forum (a Russian-speaking cybercrime forum) user purchasing Claude session cookies in bulk, while CheapAI advertised discounted access to commercial models with no additional filtering.

Using stolen accounts can hide criminal activity behind legitimate customer sessions, making attribution more difficult for AI providers. Together with dedicated services such as MessiahGPT, the findings show an underground market selling both purpose-built criminal models and unauthorized access to established AI platforms.

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts