Warning: Malicious AI Tools Are Spreading in the Criminal Underground

KnowBe4 Team | Aug 27, 2026

Criminals are now selling malicious AI tools for use in cyberattacks, according to researchers at Trellix. These tools dramatically lower the barrier for unskilled crooks to launch sophisticated attacks.

“In the first half of 2026, the Trellix research team identified multiple distinct AI-related offerings across major underground forums,” the researchers write. “These offerings span the full spectrum of the attack lifecycle, from initial reconnaissance and exploit development through payload delivery, evasion, and post-compromise operations.”

One of the tools, called “APEX AI,” allows threat actors to simply type in a targeted domain, and the tool will lay out a detailed, step-by-step plan for a ransomware attack. The tool even goes so far as to identify employees who would be best to target with spear phishing attacks.

The researchers have observed a great deal of interest in these tools on underground forums, and early signs indicate that attackers are seeing success with the tools.

“What distinguishes the current moment from earlier periods of AI hype in criminal communities is the shift from experimentation to commercialization,” Trellix says. “The services documented here are not proof-of-concept (PoC) demonstrations or theoretical discussions. They are structured commercial offerings with pricing tiers, support channels, update cadences, and in some cases, customer reviews. This maturation mirrors the broader evolution of the cybercriminal economy, where specialization and service-based models have long been the norm for ransomware, initial access brokerage, and exploit development.”

Trellix concludes that the proliferation of malicious AI platforms will fundamentally change the cybercriminal economy, and organizations should expect to see faster and more sophisticated attacks from a larger number of threat actors.

“The integration of AI into this existing commercial infrastructure represents a qualitative change in capability, not merely a quantitative one,” the researchers write. “Tasks that previously required skilled human operators working across multiple tools and data sources are being compressed into single-prompt workflows. Evasion techniques that previously required manual tuning per target environment are being automated through per-build morphing.”

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce workforce risk.

Trellix has the story: https://www.trellix.com/blogs/research/weaponized-ai-commoditization-of-cybercrime/

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.