Are LLMs Transforming Cybercriminal Operations? A Study of LLMs on Dark Web Marketplaces
This project was generously funded by the UK AI Security Institute from 2025-2026.
About the Project
Recent innovations in artificial intelligence (AI) and Large Language Models (LLMs) have transformed many aspects of society—including crime. Criminals have creatively adapted widely available AI applications to develop malware, create customized phishing attacks, analyze intelligence gathered from surveillance, and even draft text for romance scams. However, despite several notable incidents, some skeptics contend that the use of LLMs in facilitating cybercrime is overstated, driven more by speculation rather than by measurable evidence.
One way to assess the use of AI and LLMs in cybercrime is by examining the illegal marketplaces where these tools are bought and sold. In recent years, cybercriminal activity—carried out by state-backed actors, organized criminal groups, and individuals—has become increasingly professionalized and democratized. With the rise of ransomware-as-a-service and dark web markets that sell exploits, malware, and other tools, cybercrime has become more accessible, scalable, and sophisticated. Accordingly, the emergence of LLMs within this context aligns with these broader trends, democratizing access to these tools and increasing the reach and complexity of cybercriminal operations.
This trend is already beginning to take shape. Several so-called “dark LLMs” have emerged for sale on dark web markets, with prices ranging from $50-$5,000. Models such as FraudGPT, WormGPT, DarkGPT, and ruGPT are marketed specifically for malicious use, including creating targeted phishing messages, developing malware, and generating child sexual abuse material. Despite the growing marketplace for dark LLMs, more systematic research is necessary to better quantify, measure, and understand the emergence and impact of these tools on cybercriminal operations.
This project aims to build a centralized body of knowledge that tracks the rise of dark LLMs for sale or shared on the dark web and intended for cybercriminal use. Specifically, we aim to: (1) map the presence of dark LLMs; (2) create a typology of dark LLMs, including their intended uses; (3) assess the utility and application of dark LLMs within cybercriminal operations; and (4) offer an assessment of dark LLMs’ potential to transform the cybercriminal ecosystem.
Workshop
In April 2026, CSINT and the Middlebury Institute of International Studies at Monterey convened a two-day workshop at EADA Business School in Barcelona, bringing together scholars working at the intersection of artificial intelligence and cybercrime. While the diffusion of AI into criminal ecosystems is widely assumed, the actual adoption patterns — which tools are used, by whom, and to what effect — remain undertheorized and thinly evidenced. Papers presented across three sessions examined AI-enabled state revenue operations and influence campaigns, the shifting organizational and economic dynamics of cybercriminal networks, the fragmented international regulatory picture, as well as our research on the jailbreak techniques circulating in underground forums.
Read the full agenda here.
Publications and Conferences
Stay tuned for the articles that come out of this research. In the meantime, you can catch our paper presentation at the Stanford Trust and Safety Research Conference in Fall 2027.