In this article

Dark AI & Enterprise Risk: How to Defeat Malicious GenAI Models

Dark AI services are increasingly used across phishing, social engineering, reconnaissance, malware development, fraud, and impersonation. These capabilities increase the speed, scale, and personalization of criminal activity while creating new challenges for enterprise security teams.

a black and red logo with the word ikela
By KELA Cyber Intelligence Center
a man in a suit and tie looking at the camera
Fact-check by Lewis Henderson, Director, Intelligence Communications

Published September 21, 2026

Blog banners - Dark AI & Enterprise Risk_ How to Defeat Malicious GenAI Models (1).png

A finance employee receives an urgent payment request that appears to come from a senior executive. The message is polished, specific to an ongoing project, and followed by a convincing voice call confirming the request. Nothing about the email, infrastructure, or communication immediately resembles a conventional cyberattack, yet the entire interaction may have been prepared with AI tools designed for criminal use.

In this blog, we'll explore what Dark AI is, how it is changing cybercrime, the types of malicious AI services available, and how organizations can identify and reduce their exposure to AI-assisted attacks.

» Read the AI Cybercrime Report for Q4 2026 KELA

What Is Dark AI?

Dark AI refers to AI models or services that are specifically developed, fine-tuned, or marketed for malicious or criminal activity, particularly where their creators intentionally remove or avoid the safety controls found in legitimate AI systems.

Unlike ordinary AI misuse, the malicious purpose is built into the service itself. Dark AI tools may be designed to help users create phishing content, malware, fraud campaigns, or other harmful material without the restrictions typically imposed by mainstream AI providers.

» Know how to prevent phishing attacks before they catch you

How Dark AI Differs From Other AI Risks

  • Legitimate GenAI: Mainstream generative AI tools are designed for legitimate use and typically include safety policies, content restrictions, and abuse-prevention measures. Their capabilities can still be misused, but malicious activity is not their intended purpose.
  • Uncensored AI models: These models may have fewer safety restrictions than mainstream services, but a lack of guardrails does not necessarily mean they were created specifically for criminal use. Their purpose depends on how they were developed and marketed.
  • Jailbroken AI: A jailbroken service is generally a legitimate model whose safeguards have been bypassed through prompts, exploits, or other techniques. The underlying model was not necessarily designed for malicious activity, and the workaround may stop working when the system is updated.
  • Shadow AI: Shadow AI describes employees using AI tools without their organization's approval or security review. It primarily creates data governance, privacy, and compliance risks, rather than representing a dedicated criminal AI ecosystem.
  • AI misuse: AI misuse is the broader category of people using legitimate AI systems for harmful purposes. Dark AI is more specific because the malicious use case is part of the product's intended design.

» Find out how cybercriminals exploit generative AI

Why Dark AI Matters to Cybersecurity

The distinction is important because Dark AI services can operate as commercial products within underground communities, rather than simply being individual attempts to misuse legitimate AI. KELA's 2026 Mid-Year Threat Landscape Report documents underground AI services sold as commercial products: a reconnaissance and credential-extraction platform advertised at a one-time $5,000 lifetime license, and a phishing-as-a-service dashboard marketed as a managed subscription with anonymous registration and cryptocurrency payment. These are packaged offerings with pricing, support, and subscription models, not one-off attempts to misuse legitimate AI.

This makes Dark AI a distinct cybersecurity concern that requires organizations to consider not only how legitimate AI tools are being misused, but also how purpose-built malicious AI services can support threat actors.

» Make sure you understand how threat actors breach and exploit your data

How Does Malicious GenAI Change Cybercrime?

Malicious GenAI is not necessarily more technically advanced than traditional malware, phishing kits, or other cybercrime tools. Its main advantage is that it can reduce the time, expertise, and effort needed to use those techniques effectively.

  • Speed: AI can automate time-consuming preparation, including reconnaissance, target research, lure creation, and content generation. Work that previously took hours or days can be completed much faster.
  • Scale: A threat actor can generate large volumes of personalized phishing messages instead of manually creating each one. AI can also adapt language, tone, and messaging to different targets, industries, and regions.
  • Cost: Automation reduces the amount of manual labor required for attacks. This can make activities such as personalized phishing and social engineering more economical to conduct at scale.
  • Lower skill requirements: AI-assisted code and content generation can help people with less technical or language expertise attempt attacks that would previously have required greater specialist knowledge. This does not make every inexperienced attacker capable of developing sophisticated malware, but it can lower the barrier to entry.

The result is a shift in attack economics. AI can allow criminals to experiment more quickly, personalize attacks more extensively, and run more attempts for the same amount of human effort. IBM's Cost of a Data Breach Report has for many years consistently found that organizations face significant costs when breaches take longer to contain, making the ability to accelerate attack activity particularly relevant to defenders.

» Make sure you understand the most targeted entry points by attackers

Strengthen AI Security

Reduce AI security risks with KELA’s AiFort, designed to identify vulnerabilities and protect AI applications from emerging threats.

Start for FREE
Learn More

Types of Malicious AI Products and Services

The underground AI market includes a growing range of products and services that can support different stages of cybercrime, including reconnaissance, phishing, malware development, fraud, and impersonation.

AI-Assisted Phishing and Social Engineering

AI-assisted phishing and social engineering tools help criminals create more convincing emails, messages, scams, and other deceptive content. LLMs can generate content in multiple languages and adapt its wording, tone, and level of detail to different audiences, reducing the manual effort required to prepare and personalize campaigns.

Key Capabilities and Enterprise Impact

  • AI can generate large volumes of phishing and social engineering content, allowing attackers to create more campaign variations without manually writing every message.
  • Attackers can adapt generated content to specific individuals, industries, languages, or regions, making fraudulent communications appear more natural and relevant to their intended targets.
  • Information gathered about a victim can be incorporated into generated messages, allowing attackers to create more convincing requests involving payments, credentials, documents, or other sensitive information.
  • These capabilities can increase the effectiveness of business email compromise, credential theft, payment fraud, and other social engineering attacks by making malicious communications more difficult to distinguish from legitimate messages.

» Here's everything you need to know about infostealers

Malicious Code Assistance

Malicious code assistance involves AI models or services that help threat actors write, modify, translate, or understand code used in cyberattacks. AI does not necessarily replace experienced malware developers, but it can reduce the programming knowledge and manual effort required for certain malicious development tasks.

Key Capabilities and Enterprise Impact

  • AI can help attackers generate scripts, modify existing malware, or add functionality to publicly available malicious code.
  • It can explain unfamiliar code and help attackers understand how existing malware or software components work.
  • AI can assist with debugging and modifying malicious code, allowing attackers to make repeated changes without having to manually identify every programming problem.
  • More advanced malware can incorporate LLM capabilities during execution, allowing the malware to generate scripts, create functions, or alter aspects of its behavior in response to changing requirements.
  • These capabilities can lower some technical barriers to malware development and make malicious software faster to modify and potentially more adaptable during an attack.

Credential and Account Takeover Automation

AI can support workflows targeting credentials and online accounts by helping attackers process information, create personalized social engineering content, and automate parts of an operation. This does not represent an entirely new form of credential theft, but it can make existing account takeover activities faster and more adaptable.

Key Capabilities and Enterprise Impact

  • AI can process information collected about potential victims and identify details that may be useful when preparing targeted credential theft or impersonation campaigns.
  • It can generate different versions of phishing and social engineering content, this allows attackers to tailor their approach to different individuals or groups.
  • AI can help process information associated with compromised accounts, potentially reducing the manual effort required to organize and interpret stolen data.
  • It can be incorporated into broader automated workflows in which information gathering, social engineering, and other attack activities are connected rather than performed as separate manual steps.

» Learn more about about credential compromise

Deepfake and Synthetic Media

Deepfake services use AI to generate or manipulate audio, images, and video for impersonation, fraud, and social engineering. In an enterprise environment, synthetic media can be used to imitate executives, employees, business partners, or other trusted individuals and make fraudulent requests appear more credible.

Key Capabilities and Enterprise Impact

  • AI can generate synthetic voices, images, and videos that imitate real people, giving attackers additional ways to impersonate trusted individuals.
  • Attackers can combine synthetic media with other forms of social engineering to make fraudulent payment requests, instructions, or communications appear more legitimate.
  • Employees who rely on a familiar person's voice, appearance, or video presence as part of an identity check may be more vulnerable when synthetic media is introduced into the interaction.
  • Executives, finance teams, and employees responsible for approving transactions can face particular risk because convincing impersonation may be used to support payment fraud or requests for sensitive information.
The use of synthetic media can make identity verification more difficult because organizations may need to rely on independent authentication methods rather than appearance or voice alone.

Malicious AI Chatbots

Malicious AI chatbots are purpose-built or modified AI services marketed to criminals as alternatives to mainstream models with safety restrictions.

Examples promoted in underground communities include WormGPT, FraudGPT, WolfGPT, and GhostGPT, marketed for phishing, fraud, and malicious code generation.

Status varies sharply. WormGPT was shut down by one of its creators in August 2023 and the name has since been reused by unrelated copycat services; FraudGPT's sale threads have disappeared; WolfGPT was exposed as a wrapper returning mainstream refusals rather than a purpose-built model; GhostGPT is sold as a Telegram bot on a weekly subscription. (Status as of September 2026.)

Key Capabilities and Enterprise Impact

  • These services may provide assistance with criminal tasks that mainstream AI providers restrict, including generating phishing content, supporting fraud, and producing or modifying malicious code.
  • Their commercial or subscription-based models allow threat actors to obtain AI-assisted capabilities without developing their own models or building every component of their criminal tooling themselves.
  • A single service can potentially support several stages of an attack, allowing criminals to use AI for activities such as content generation, social engineering, reconnaissance, and code-related tasks.
  • The availability of these services can lower the barrier to entry for less-skilled criminals who may otherwise lack the technical knowledge required to perform certain activities.
Remember: Organizations should not assume that every underground "Dark AI" chatbot is genuinely sophisticated, because some services have been found to be technically weak or to exaggerate their advertised capabilities.

AI-Powered Target Reconnaissance

AI-powered reconnaissance uses AI to collect, organize, summarize, and interpret information about potential targets. This can include publicly available information about organizations, employees, technologies, and business relationships that may later be used to support phishing, impersonation, or intrusion attempts.

Key Capabilities and Enterprise Impact

  • AI can process large amounts of publicly available information more quickly than manual research, helping attackers build profiles of organizations and potential victims.
  • It can organize information about employees, technologies, organizational structures, and business relationships so attackers can more easily identify valuable targets or potential attack opportunities.
  • AI can help identify connections between different pieces of information, allowing attackers to develop a more detailed understanding of how an organization operates.
  • Reconnaissance findings can then provide context for more targeted phishing, impersonation, credential theft, or intrusion attempts.
  • By reducing the time and effort required to research potential victims, AI can make reconnaissance more efficient and allow information gathering to become more closely integrated with other stages of an attack.

» Find out how agentic AI is transforming cybersecurity

How to Detect AI-Assisted Attacks

AI-assisted attacks can use conventional payloads, infrastructure, and access methods, making them difficult to identify through signatures alone. Organizations should therefore monitor behavioral signals and unusual combinations of activity. Key behavioral signals include:

  • Unusually polished communications: Messages that are significantly more fluent or contextually appropriate than a sender's normal communication style can warrant additional scrutiny, particularly when paired with urgency or unusual requests.
  • Authentication and transaction anomalies: Changes in the timing, frequency, or sequence of authentication attempts or transaction approvals can indicate activity that does not match normal human behavior.
  • Unexpected verification requests: Requests to confirm an identity or sensitive action through an unusual phone or video channel may indicate an attempt to bypass established verification procedures.
  • Instruction-like AI inputs: Prompts or uploaded content that contain instructions directed at an AI system rather than relevant information may indicate a prompt injection attempt.
  • Multiple anomalies occurring together: Several unusual events occurring within a short period can provide a stronger indication of an attack than any single suspicious event.
Did you know? Effective defense requires visibility both inside and outside the organization. Behavioral monitoring can help detect suspicious activity internally, while KELA's threat intelligence provides insight into emerging criminal activity. For organizations using AI, KELA’s AiFort helps identify vulnerabilities in generative AI and MLOps applications during development and monitor deployed models for emerging threats.

Stay Ahead of AI Threats

Combine KELA Cyber's Cybercrime Threat Intelligence Platform with AiFort to detect, monitor, and defend against evolving AI threats.

Contact us

Prepare for the Dark AI Threat

AI-assisted attacks are making familiar threats faster, more scalable, and harder to distinguish from legitimate activity. Organizations need visibility into both internal behavior and the wider threat environment to identify these risks early. KELA’s AiFort helps organizations secure generative AI and MLOps applications by identifying vulnerabilities during development and monitoring deployed models for emerging threats.

Combined with KELA’s threat intelligence, this gives security teams greater visibility into both the risks affecting their AI applications and the threats emerging beyond the organization.

The takeaway is that the defense is not a new tool category but earlier visibility: behavioral signals inside the organization, and intelligence on criminal activity outside it.

» Ready to begin? Contact us to learn more or try KELA for free

FAQs

What is Dark AI

Dark AI refers to AI models or services specifically developed, fine-tuned, or marketed for malicious or criminal purposes, often without the safety restrictions found in mainstream AI systems.

How is Dark AI different from AI misuse?

AI misuse involves using a legitimate AI system for harmful purposes, while Dark AI is specifically designed or marketed around malicious use cases.

What can criminals use Dark AI for?

Dark AI can support activities such as phishing, social engineering, malware development, reconnaissance, fraud, credential theft, and impersonation.

How can threat intelligence help organizations defend against Dark AI?

Threat intelligence can provide visibility into underground activity before a threat reaches an organization, including emerging malicious AI services, criminal discussions, and industries being targeted.