New research from ThreatDown, a business unit of Malwarebytes, shows that Kriminal AI (with the official domain Kriminal.ai) — one of the most popular criminal AI platforms on the market — is not actually a “custom-built” model, but a simple wrapper around xAI’s Grok 4, with security filters bypassed via jailbreak. The case highlights a building block of the current criminal AI economy: crooks don’t build their own models, they rent access to legitimate ones.
Kriminal doesn’t hide on the dark web. The platform operates on the regular internet, is indexed by Google, and touts the slogan “artificial intelligence that answers everything — no filters, no restrictions, no ‘I can’t help you with that.’” Subscriptions start at $12.99 per month, with a higher GHOST package at $99, and payments are made in cryptocurrencies through NowPayments.
See also: Europol: "Strike" in online fraud ring — Victims also in Greece
What does a Kriminal AI subscriber actually buy?
Unlike regular chatbots, Kriminal doesn’t just sell conversations. It sells ready-made criminal intelligence tools: open intelligence (OSINT) dossiers at 55 to 90 minutes per search, cryptocurrency transaction tracking at 12 minutes per analysis, and an unrestricted code-writing feature that generates exploits. Subscribers also get an in-browser sandbox and a technical access point compatible with OpenAI’s programming tools, which they can plug into code editors like Cursor or Cline.
The top-tier GHOST package comes with four specialized digital agents with distinctive names. PHANTOM deals with money laundering and asset tracing. ARCHITECT covers vulnerability research and writing offensive code. ORACLE performs document analysis and intelligence gathering. WRAITH is designed for social engineering and creating fake identities. The names and responsibilities are reserved by the creators themselves within the platform code.
How ThreatDown's technical team exposed Kriminal AI
The researchers used two independent techniques to uncover what was really going on underneath Kriminal. First, they examined the JavaScript code downloaded to the user’s browser — the code that determines how the page works — and identified calls to legitimate AI providers. Second, they asked the platform to “unmask” and declare the real underlying model. The answer was clear: “Grok 4, built by xAI.” Both techniques led to the same conclusion.
Kriminal's full technology layer, as mapped by ThreatDown, reveals the extent of its parasitic relationship with the legitimate industry: hosting is done via Google Cloud and Cloudflare, core inference via xAI (Grok), routing to specialized models via OpenRouter (Mistral Large, Llama 3.3), large document analysis via Anthropic (Claude), and live web search via the Tavily service. The TLS security certificate was issued for free by Let's Encrypt on May 16, 2026.
See also: Suspect arrested for global crypto fraud — Arrests also in Greece

The broader pattern of "rented intelligence"
Kriminal is not an isolated case. ThreatDown’s comprehensive report Cybercrime in the Age of AI mapped similar platforms — WormGPT, DadGPT, and Xanthorox — all of which rely on the same infrastructure of legitimate cloud providers and AI models (Cloudflare, Google Cloud, Vercel, OpenRouter, xAI, Anthropic, DeepSeek, and Alibaba). The same research identified 6,644 models openly published on the Hugging Face platform with tags like “abliterated,” “uncensored,” and “unfiltered,” which were downloaded over 22 million times in just thirty days.
ThreatDown’s vice president and head of research, Marco Guiliani, summed it up for Forbes : “Despite the tough language and sophisticated digital guises, Kriminal is simply xAI’s Grok with its security filters completely removed.” The criminal AI market, according to the same report, “doesn’t build intelligence — it rents it from the legitimate industry.”

What does it mean for Greek businesses?
The existence of services like Kriminal.ai at a price of $13 per month dramatically lowers the threshold of entry for malicious actions. Anyone with a cryptocurrency can acquire capabilities that previously required years of experience: automated construction of phishing campaigns personalized to the target, development of malicious code, vulnerability research, and even assistance in phone fraud scenarios. The SecNews technical team estimates that the Greek business ecosystem — especially small and medium-sized enterprises without a specialized cybersecurity department — is particularly exposed to this type of threat.
ThreatDown suggests three immediate preparedness actions. First, modernize vulnerability management processes with a focus on rapid patching, as AI accelerates the discovery of new vulnerabilities. Second, monitor systems 24/7 through a security operations center (SOC) or managed detection and response service. Third, identify and control “shadow AI” — AI tools used by employees without formal authorization, creating security gaps that cannot be addressed unless they are first captured.
The SecNews editorial team will monitor the evolution of the criminal AI market and update with new findings from research companies such as ThreatDown, Rapid7 and Trend Micro. The basic finding remains the same: the main threat is not some mysterious “malicious model”, but the abuse of the same models we use every day — through techniques to bypass their security mechanisms.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
