you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 0 min ago 255 onions tracked
home / news / security
24 August 2026 security 5 min read

AI on the dark web: how illicit communities actually use it in 2026

For years, coverage of AI on the dark web leaned on speculation: chatbots that might one day write perfect malware, marketplaces that might sell fully autonomous hacking agents. By mid-2026 the picture is less cinematic and more concrete. Analysts who monitor underground forums, and government agencies responding to live incidents, describe something quieter - ordinary criminal operations adopting AI the way they once adopted bulletproof hosting or escrow bots, as infrastructure that removes friction.

What Flashpoint sees across illicit communities

Flashpoint launched its AI Threat Report to track this shift month by month, drawing on direct visibility into forums, marketplaces, and chat services. In April 2026 alone its analysts counted more than 2.3 million posts discussing artificial intelligence in an illicit context, with Telegram accounting for the overwhelming majority of activity, followed by Reddit, GitHub Gist, Pastebin, Discord, and smaller forums. The dominant conversations were not about building exotic models. They were about usability: jailbreak prompts that bypass safeguards, phishing-oriented prompt collections, and access to alternative models such as VeniceAI that users believe carry fewer restrictions than mainstream platforms. The report's broader takeaway is that prompt engineering has become a transferable skill inside these communities. A jailbreak shared in one Telegram channel reappears on paste sites within days, revised when a platform patches it. Users leave feedback when outputs degrade, and updated versions follow quickly - the same reputation-and-maintenance cycle that governs any other illicit service listing.

AI-written exploit scripts against industrial controllers

The most consequential example came from governments rather than forums. On August 19, five US agencies - NSA, CISA, FBI, DOE, and EPA - issued a joint advisory describing an active threat to internet-exposed Siemens S7 Series PLCs used in energy, water, manufacturing, and agriculture (CISA advisory AA26-231A). Threat actors are combining open-source industrial libraries like python-snap7 with AI-assisted scripting to generate Python exploitation tools disguised as legitimate monitoring software, capable of reading and writing PLC memory and ladder logic over the S7comm protocol. The agencies were blunt about what changed. Using AI to generate exploit scripts, they wrote, represents an evolution in threat actor capabilities that dramatically reduces the technical expertise and time needed to produce working industrial control system attacks - attackers scan with services like Censys, feed public vulnerability information into coding assistants, and iterate rapidly. As The Record reported, the advisory calls the situation an active threat rather than a theoretical risk, though it stops short of attribution.

PentestGPT on a C2 server: the UAT-10147 case

If the Siemens advisory shows AI lowering the barrier, Cisco Talos's reporting on UAT-10147 shows what a mature operation looks like. The Chinese-speaking cybercrime group, which profits from SEO fraud and data theft, kept a target list of roughly 170,000 URLs and ran agentic AI tooling directly on its command-and-control servers. Researchers observed the PentestGPT framework being used to scan web servers and execute proof-of-concept exploits, while the DeepAudit framework handled source-code vulnerability scanning. Talos also recovered AI-generated documentation - a nine-section guide to exploiting an ASP.NET ViewState flaw, complete with companion Python scripts and troubleshooting notes written by the model itself during failed attempts. What stands out is not any individual technique; every vulnerability involved was publicly known. It is the orchestration. Talos assesses with moderate-to-high confidence that this marks a shift from AI-assisted scripting toward semi-autonomous offensive workflows, letting a small team operate at a scale that previously required many hands.

Malware with a chat interface: RedC2 and forum-sold services

AI has also become a selling point in its own right. In August 2026, researchers documented RedC2 4.0, a commercial C2 framework advertised on Hack Forums under the handle MarlboroMan through a storefront called Red Offsec (The Hacker News). Its headline feature, Red Agent, is an LLM-backed layer that turns natural-language instructions into beacon commands, letting low-skill operators run reconnaissance and credential theft without understanding the underlying steps. The same disclosure traced delivery to fourteen trojanized npm packages disguised as calendar utilities. This is the marketplace layer of the trend: AI capability packaged as a subscription. Alongside frameworks like RedC2, Telegram channels trade jailbreak scripts, phishing prompt packs, and AI-enabled KYC bypass kits - services sold with support channels and revision cycles much like any legitimate SaaS. Buyers no longer need to know how a model works, only which vendor's output is reliable this week. The dynamic resembles earlier waves of productized crime on the dark web, from booter panels to the DDoS-for-hire economy we covered in our piece on extortion against markets: each round lowers the skill floor further.

The sober reading

None of this means AI created new classes of attack. The Siemens targets were exposed devices with default credentials long before anyone added a language model; UAT-10147 exploited years-old vulnerabilities. What AI changes is economics - time, expertise, and headcount - which is precisely why both intelligence firms and regulators now treat illicit AI adoption as routine operational reality rather than a future scenario worth debating.

more notes

all news ›