A company is selling an AI platform that advertises itself as having no limits, raising questions about the product’s potential usage by cybercriminals.
The model’s name is “Kriminal,” and it’s the subject of new research published yesterday by ThreatDown, Malwarebytes’ enterprise-focused security brand. ThreatDown describes Kriminal in a blog post as “one of the newest and most popular tools in the criminal AI market.”
Despite the platform’s name and ThreatDown’s characterization of it as a popular tool in the emerging “criminal AI” market, it’s indexed on the clear web and can be found through a simple Google search. Unlike traditional exploit kits and other cybercrime services, which are often marketed directly around attack capabilities, Kriminal presents itself more like a conventional software-as-a-service (SaaS) product.
One similarity between Kriminal and illicit services is the payment method: subscriptions are purchased using cryptocurrency only. Access starts at $12.99 per month.
The Kriminal website claims 18,400-plus messages have been sent to its platform to date, with 2,300 active users and 99% of questions answered.
Makeup of a Kriminal
While Kriminal’s website doesn’t explicitly advertise itself as a cybercrime tool, its “WRAITH” feature offers “social engineering & persona craft” for those who pay for the highest tier of service. Another feature, the “ARCHITECT” agent, advertises an “offensive security & exploit expert.” Kriminal also offers guardrail-free conspiracy discussion, uncensored image generation, open-source intelligence (OSINT) scanning for things like names and addresses, cryptocurrency tracing, and more.
Moreover, Kriminal’s terms page explicitly says the service is for “research, creative, and educational purposes,” and forbids activities that “use the Service in any manner that violates applicable local, national, or international law.” The terms suggest Kriminal’s operators distinguish between an “uncensored” AI service and an unmoderated one; the terms reference the use of manual and automated detection for illicit exploitation content involving minors, and the company says user efforts to generate such content may be sent to the appropriate authorities.
But the platform’s no-filter, no-guardrail marketing strategy — not to mention the service’s name — raises questions. The operators of Kriminal AI do not appear to publicly identify themselves on the service’s website, and no contact information was available (Dark Reading attempted to contact the company but did not receive a response at press time). On the other hand, legitimate parties also use OSINT scanning, cryptocurrency tracing, and offensive cybersecurity testing.
Kriminal: A Smattering of Off-the-Shelf AI Parts?
On what it described as a “cybercrime network,” ThreatDown said Kriminal pitched itself as “not a jailbreak wrapped around someone else’s API,” but based on an under the hood analysis, almost none of its components are proprietary.
According to the vendor’s analysis, Kriminal appears to rely on Grok for primary inference; Google Cloud and Cloudflare for hosting; Anthropic’s Claude for a long-context model layer; Llama routed through OpenRouter for certain specialized tasks; Tavily for live search; NowPayments for cryptocurrency checkout (no KYC included, apparently); and Cloudflare/Let’s Encrypt for DNS and TLS.
As ThreatDown puts it, even if Kriminal uses various models for tasks they’re otherwise not intended for, each only sees a part of the criminal whole.
“That’s what makes it resilient. Cloudflare can see traffic, not what it’s for. NowPayments can see a crypto payment, not what it purchased,” ThreatDown’s blog post explained. “Each vendor in the stack only has visibility into its own layer, so no single company can act on the whole picture, only its own slice of it. The takedown surface isn’t a bulletproof host to seize: it’s a dozen separate abuse-desk tickets, each addressing a fragment of an operation none of them can see in full.”
If ThreatDown’s research and characterizations are accurate, Kriminal may create compliance and policy questions for the AI providers whose models it relies on. However, proving a term of service violation would be difficult. It would require examining the specific agreements, API usage patterns, and outputs involved to reach any sort of conclusion.
Click Here For The Original Source.
