Dark Web Swarms with Subscription-Based AI Hacking Tools, Bypassing ChatGPT Safeguards
- Input
- 2026-08-24 18:07:24
- Updated
- 2026-08-24 18:07:24

On the 24th, Financial News said that after reviewing the dark web through AhnLab, Inc., a global integrated security company, it found that AI hacking tools are being distributed in various forms, including Software as a Service (SaaS) and open-weight models, which publicly release trained model weights.
Among SaaS-based hacking tools, 'WormGPT,' which emerged in 2023, was followed by 'FraudGPT' and 'EvilAI.' WormGPT is now being operated under the same brand on multiple websites. Some offer cryptocurrency payments and monthly subscriptions or lifetime access, while others support card payments and usage-based billing. FraudGPT is also being distributed through monthly, quarterly, and annual subscription plans. EvilAI initially offered features such as phishing page creation, but later expanded into a web service with both free and paid tiers. They emphasized 'unrestricted generation' and 'filter-free responses,' highlighting their ability to bypass the safeguards of mainstream generative AI.
Open-weight models, such as 'KawaiiGPT,' which can be downloaded and used, are also spreading. Because users can run them themselves, they are easier to use in ways that bypass safeguards and monitoring. KawaiiGPT has received hundreds of stars and forks on GitHub, indicating active copying and use. More recently, there has also been growing demand for services that provide the methods themselves for bypassing the safeguards of AI platforms such as ChatGPT, Claude, and Gemini. In April, it was revealed that an attacker used Anthropic's Claude Code and other tools to operate a hacking tool called 'Visa Scanner' and compromised more than 900 companies. In the attacker's repository, more than 65,000 files containing authentication information for AI platforms such as Anthropic and Google Experience Center, as well as cloud services such as Amazon Web Services (AWS) and payment services such as PayPal Holdings, Inc., were found, including duplicate copies.

As attack tools become more diverse, hacking speed is also increasing exponentially. According to global security company CrowdStrike Holdings, Inc., the average time it takes an attacker to move from the initial breach to another system has fallen from 62 minutes in 2023 to 48 minutes in 2024 and 29 minutes in 2025. In 2025, there was even a case in which an attacker moved to another system in just 27 seconds.
Experts say this does not mean we have entered an era in which anyone can hack with AI. Rather, they argue that the environment has become easier and faster for existing attackers. To respond to the changing threat landscape, they say organizations must faithfully follow basic security practices while also strengthening their AI-based response capabilities.
Jung Jin-sung, a talent manager at AhnLab Security Intelligence Center (ASEC), said, "Not only illegal AI tools but also publicly available generative AI and legitimate security tools are increasingly being abused." He added, "It is important to strictly follow basic security practices, such as applying Multi-Factor Authentication (MFA), not opening suspicious emails or links, and promptly applying security updates to systems in operation."
He also said, "AI is both a new threat and a new defense tool," and added, "What matters is not fearing AI itself, but continuously strengthening security systems to match the changing threat environment."
[email protected] Choi Hye-rim Reporter