Security analysts have uncovered MessiahGPT, an illicit artificial intelligence service advertised publicly on BreachForums. The unrestricted tool builds malicious software packages on demand, including ransomware, rootkits, credential stealers, crypters, and phishing templates. Access runs on a subscription starting near $8 monthly paid via crypto, alongside a tier of fifty complimentary prompts requiring no sign-up.
The service runs via a web portal at messiahgpt[.]de alongside an active Telegram channel. According to its creator, the underlying model was built from the ground up without moral boundaries. Unlike commercial AI assistants, it lacks Reinforcement Learning from Human Feedback, omits safety frameworks, and enforces no blocks against malicious requests.
The creators assert the training corpus included dark-web repositories, raw web data, leaked manuals, and unedited guides. Trellix points out these architectural claims are unconfirmed, though the service produces working payloads that cybercriminals find useful enough to buy.
MessiahGPT fits into a growing marketplace of malicious offensive tools. Back in 2023, WormGPT appeared on underground boards to support business email compromise schemes, quickly followed by FraudGPT, which sold for up to $1,700 a year to generate malware and phishing sites. These platforms proved that hackers readily invest in unaligned AI. Meanwhile, DarkBERT has been co-opted by bad actors to craft sophisticated social engineering attacks and malware.
The real breakthrough of MessiahGPT lies in affordability and ease of use rather than advanced engineering. By pricing access at $8 a month, the cost falls beneath standard commercial apps. The freemium approach borrows from traditional software-as-a-service playbooks, turning cyberattack capabilities into everyday consumer goods.
The risk of Generative AI allows real-time alteration of phishing messages, fake websites, and malicious scripts. Every altered instance evades basic security filters that look for signatures or fixed phrasing. Advanced phishing-as-a-service frameworks now incorporate features like browser fingerprinting, anti-bot mechanisms, rotating CAPTCHAs, and hosting filters to dodge traditional detection methods.
Police and intelligence agencies have sounded alarms regarding this shift. Europol documented upward of 120 distinct ransomware strains active during 2025. Meanwhile, the FBI noted that business email compromise cost victims $3.046 billion in reported damages that same year.
The platform was undone by researchers at Trellix.
