A newly surfaced criminal AI service called MessiahGPT is being openly marketed on BreachForums as a purpose-built offensive model that writes ransomware, phishing kits, stealers, crypters, and rootkits on demand, according to findings published by the Trellix Advanced Research Center.
The service runs a live platform at messiahgpt[.]de alongside an active Telegram community, and its operators are not being subtle about who they are selling to.
What makes MessiahGPT different from the endless stream of jailbreak prompts circulating in underground channels is its underlying claim. The operator says the model was not jailbroken at all, but trained from scratch with what they describe as zero ethical constraints: no Reinforcement Learning from Human Feedback, no Constitutional AI layer, and no internal concept of harm or illegality.
The advertised training corpus reads like a catalog of everything mainstream labs filter out: unrestricted manuals, dark web archives, leaked documentation, and raw internet scrapes with no post-filtering applied.
The listed architecture is a Mixture-of-Experts design with 128 experts, 16 of which are active per token. None of these technical claims can be independently verified from outside the platform, and researchers are careful to say so. What is verifiable is that the service is live, reachable, and being promoted on one of the most trafficked criminal forums on the internet.
The commercial model is aggressively low-friction. MessiahGPT offers 50 free queries with no registration at all, letting prospective buyers test output quality before spending anything.
Paid plans then start at roughly $8 per month, payable only in cryptocurrency with no KYC checks. That price point matters more than it might appear.
For under the cost of a streaming subscription, a low-skilled actor gains a tool that will reportedly produce complete, compilable malware and ready-to-deploy phishing kits capability that previously required either genuine development skill or a relationship with a malware-as-a-service vendor.
The use cases listed in the advertisement are explicit rather than euphemistic. Alongside ransomware and phishing kit generation, the operator promotes social engineering scripts, fraud and carding guides, data breach exploitation, physical attack planning, and chemical and explosive synthesis.
The listing even includes a benchmark comparison table pitting MessiahGPT against ChatGPT-4o, DeepSeek-V3 and Mistral-Large, positioning itself as the only model that returns usable output across every category the others refuse.

That framing is a strong signal about the audience: these are buyers who have already hit refusal walls on commercial platforms and are shopping specifically for a model without them.
MessiahGPT is not operating in isolation. Trellix also tracked DarkGPT, a persistently advertised uncensored AI service circulating across multiple Russian-language Telegram channels, which offers bot access with three free queries before paid tiers kick in.
Its marketing openly promises full freedom to write malicious code and exploits without restrictions, custom hacker scripts tailored to the buyer, real-time “instant hacks” for complex scenarios, a 24/7 assistant, access to a hacker community, and what the advertisement literally brands as BlackHat AI uncensored power for darknet projects.
Whether DarkGPT is a genuinely fine-tuned local model or simply a jailbroken wrapper around a public LLM cannot be verified externally. What the repeated reposting across channels does indicate is durable demand: the operators are still spending on promotion, which suggests the revenue justifies it.
Between DarkGPT’s staying power and MessiahGPT’s custom-model ambitions, uncensored AI has become a standing product category rather than a novelty.
Researchers place both services within a broader 2026 shift toward the commercialization of criminal AI, where uncensored AI-as-a-service has moved from informal Telegram bots to dedicated platforms with versioned websites, demo channels, support communities, and tiered pricing.
Defenders should assume that phishing lures, ransomware variants and social engineering pretexts arriving in 2026 may be AI-generated, higher in volume, and cheaper to produce than ever.
Signature-based detection and template-matching phishing filters degrade quickly against machine-generated variation, making behavioral detection, strong identity controls and continuous user awareness training the more durable defenses.
Defenders should assume that phishing lures, ransomware variants and social engineering pretexts arriving in 2026 may be AI-generated, higher in volume, and cheaper to produce than ever.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
