Uncensored Luciferus AI Service Advertised on Underground Forum

Summary
Sophos researchers found an underground forum ad for Luciferus, an uncensored AI service that responded to a prompt for a Python remote access trojan. They say the service reflects growing cybercriminal commercialization of AI.
Key points
- A forum persona named “Optimus_Prime” advertised Luciferus on the Exploit underground forum in August 2026.
- Luciferus is marketed as an AI service without moral or ethical restrictions; researchers assess with low confidence that it may be based on Alibaba’s Qwen models.
- In a demonstration, Luciferus answered a request for a simple Python remote access trojan with networking and command-execution functionality. Researchers did not execute or assess the completeness of the generated code.
- Researchers could not independently verify the service’s model architecture, performance, privacy claims, or advertised capabilities.
- Sophos reports a broader rise in underground AI services, including offerings for modified models, access to legitimate platforms, and AI support for cybercrime.
Article Details
- Event Type
- Advertising of an uncensored AI subscription service on an underground forum
- Impact
- In a researcher test, Luciferus Junior generated Python remote access trojan code in response to an explicit prompt. Researchers did not execute or assess the code, and the article reports no resulting compromise.
Vendors
Products
Luciferusunderground forum persona named “Optimus_Prime” advertising an uncensored AI subscription service named Luciferus. The persona joined Exploit on April 18, and their profile displays a “coding / coder” activity label.Qwenclaims, or advertised capabilities. However, they assess with low confidence that Luciferus is built on Qwen, which is a family of large language models (LLMs) developed by Alibaba. Qwen provides underlying AI