Security researchers are warning of a criminal AI service built on Grok and Claude, among other models, that promises uncensored access to powerful AI capabilities for as little as $12.99 a month.
ThreatDown researchers say “Kriminal” is largely a storefront wrapped around legitimate AI services, using jailbreak prompts to bypass their guardrails and resell the resulting capabilities to would-be criminals.
The service is publicly accessible on the clearnet, indexed by Google and presented like a conventional SaaS product, featuring pricing tiers, usage statistics and a crypto payment system, the researchers said in a blog post shared with CSO ahead of its publication on Wednesday.
The service’s offerings include exploit development, OSINT, on-chain tracing, social engineering and code generation.
“This is a bellwether for a broader shift in cyber offense,” said Diana Kelley, Chief Information Security Officer at Noma Security. “As advanced offensive capability becomes cheaper and more accessible with AI, attackers can find and exploit weaknesses at a speed and scale that tilt the economics of cybercrime in their favor.”
CISO’s need to fight fire with fire, use advanced AI to uncover risk and exposure and eliminate years of tolerated security debt before cybercriminals weaponize it, she added.
The cheapest paid tier starts at $12.99 a month, while the top GHOST tier costs $99.
The criminal AI is mostly rented
ThreatDown’s analysis of Kriminal’s production JavaScript found no evidence of a proprietary foundation model. Instead, the service routes requests through several established providers.
xAI’s Grok is identified in the code as the primary inference engine for chat and agent runs. OpenRouter provides access to specialist models including Mistral Large and Llama 3.3, while Anthropic’s Claude is offered for long-context analysis. Tavily supplies live web search. The service itself is hosted through Google Cloud and Cloudflare, while NowPayments handles its crypto checkout.
ThreatDown noted that Kriminal operates as both a reseller and a jailbreak wrapper. Its own code shows that it forwards requests to legitimate AI providers and places a system prompt over those models to bypass their safety restrictions.
When researchers asked Kriminal to identify the underlying model, its default NEXUS persona identified itself as Grok, matching the provider information found in the code.
The problem is bigger than a jailbreak
Krimial’s pricing also illustrates how quickly sophisticated capabilities can become commoditized. Its paid tier offers roughly 200 to 1800 messages per month, with individual services including OSINT dossiers, blockchain analysis, unrestricted code generation and access to an in-browser Python and JavaScript sandbox.
Aviv Nahum, co-founder and CEO at Above Security, said the important takeaway is that there may be considerably less “criminal AI” underneath Kriminal than its branding suggests.
“The underlying capability is becoming a commodity,” Nahum said. “Organizations cannot outsource their security strategy to the guardrails of AI providers. Those safeguards are important, but attackers will jailbreak models, proxy access to them, use open models locally, or simply move between providers.”
Defenders must assume that increasingly capable AI will be available to both sides, he noted.
KRIMINAL has packaged its capabilities into four named agent personas in its premium GHOST tier. PHANTUM is designed for “financial intelligence” and asset tracing, ARCHITECT for exploit research and offensive code, ORACLE for document and intelligence analysis, and WRAITH for social engineering, persona crafting and identity construction. The researchers said they were able to corroborate many of the technical findings from their code analysis by questioning the service itself, as if the model was designed to spill every secret AI models aren’t supposed to talk about, including its own intent.


