Monday, September 28, 2026

Sophos X-Ops research: Uncensored Luciferus AI service advertised underground

5

Sophos X-Ops research: Uncensored Luciferus AI service advertised underground

How do you feel about this story?

Express Your Reaction
Like
Love
Haha
Wow
Sad
Angry

Sophos X-Ops has published new research on Luciferus, an uncensored AI subscription service advertised on the Exploit underground forum and promoted as answering requests without moral or ethical restrictions.

Sophos Counter Threat Unit (CTU) researchers observed an Exploit forum persona named Optimus_Prime advertising Luciferus on August 24, 2026. The advertisement claims the service is based on a proprietary model with “120 billion parameters,” although Sophos has not independently verified the model architecture, parameter count, performance, privacy claims, or advertised capabilities.

The research highlights a wider shift in the underground economy: threat actors are increasingly commercializing AI as a service, selling uncensored or modified large language models in the same way malware, phishing kits, brokered access, and ransomware tooling are commoditized. Luciferus appears to be positioned as a more stable alternative to “jailbroken” mainstream AI services because it is advertised as an uncensored local LLM from the outset.

“Luciferus shows how quickly the underground economy is trying to package AI into a cybercrime service model. The concern is not just that an AI tool can answer a malicious prompt, but that access is being marketed, tiered, and sold in a way that could make offensive capabilities easier for less technical actors to reach,” Aiden Sinnott, Senior Threat Researcher, Sophos Counter Threat Unit, said.

The service’s marketing explicitly advertises the absence of ethical safeguards, while CTU researchers also observed the Luciferus Junior model responding to a direct request for a simple Python remote access trojan.