Criminal AI Service MessiahGPT Emerges, Offering Ransomware and Phishing Kits
A new AI service named MessiahGPT is being marketed on BreachForums, offering to generate ransomware, phishing kits, and other malicious tools with no ethical constraints.

A new criminal AI service called MessiahGPT has surfaced, actively marketed on the BreachForums platform as a purpose-built offensive model capable of generating ransomware, phishing kits, stealers, crypters, and rootkits on demand. Researchers from the Trellix Advanced Research Center have identified the service, which operates a live platform at messiahgpt[.]de and maintains an active Telegram community. Unlike many existing AI tools that have been "jailbroken" to bypass ethical restrictions, MessiahGPT's operators claim the model was trained from scratch with "zero ethical constraints," eschewing common safety mechanisms like Reinforcement Learning from Human Feedback (RLHF) or Constitutional AI.
The advertised training data for MessiahGPT reportedly includes unrestricted manuals, dark web archives, leaked documentation, and unfiltered internet scrapes, suggesting a deliberate effort to create a model free from the ethical guardrails present in mainstream AI. While these technical claims cannot be independently verified, the service's accessibility and promotion on a major criminal forum are confirmed. MessiahGPT offers a low-friction commercial model, providing 50 free queries without registration, allowing potential buyers to test its capabilities. Paid plans start at approximately $8 per month, payable exclusively in cryptocurrency, with no Know Your Customer (KYC) checks required.
This aggressive pricing and accessibility democratize the creation of sophisticated malware and phishing kits, capabilities that previously required significant technical expertise or access to specialized malware-as-a-service vendors. The service explicitly lists use cases beyond ransomware and phishing, including social engineering scripts, fraud and carding guides, data breach exploitation, physical attack planning, and even chemical and explosive synthesis. Advertisements for MessiahGPT include comparisons against leading AI models like ChatGPT-4o, positioning itself as the only option that provides usable output across categories where other models refuse to engage.
MessiahGPT is not an isolated phenomenon; it is part of a growing trend of "uncensored AI" services catering to malicious actors. Trellix also noted DarkGPT, another AI service advertised on Russian-language Telegram channels, which openly promises unrestricted malicious code generation, custom hacker scripts, and "BlackHat AI uncensored power." The persistent promotion of such services suggests a durable demand and a viable revenue stream for their operators.
The emergence of MessiahGPT and similar platforms signifies a maturation of the criminal AI landscape in 2026. Uncensored AI has transitioned from informal bots to dedicated platforms featuring versioned websites, demo channels, support communities, and tiered pricing structures. This commercialization of AI for offensive cyber operations means that defenders must anticipate an increase in the volume and sophistication of AI-generated phishing lures, ransomware variants, and social engineering pretexts.
Defenders are advised to adapt their strategies, as traditional signature-based detection and template-matching filters may become less effective against the rapid variation introduced by machine-generated content. More durable defenses will rely on behavioral detection, robust identity controls, and continuous user awareness training. The threat landscape is evolving, and the accessibility of powerful AI tools to low-skilled actors poses a significant challenge to cybersecurity professionals worldwide.
The implications of MessiahGPT extend to the broader cybersecurity ecosystem. As AI tools become more accessible and less restricted, the barrier to entry for cybercrime is lowered, potentially leading to a surge in attacks. Organizations must prioritize proactive security measures and stay informed about the evolving capabilities of threat actors leveraging these new technologies.