A Criminal Sold AI-Powered Hacking as a Service. Here Is How He Built It.

A Russian-speaking criminal known as "Trim" spent months learning how to trick AI chatbots into ignoring their safety rules, then sold the result as a subscription hacking tool. Security researchers say others are already copying the blueprint.

ThreatVectr Newsdesk· 3 min read
Close-up, edge-to-edge 16:9 photograph of a glowing circuit board with streams of faintly visible text and code cascading across its surface in soft blue and wh
Share

Key points

  • A criminal using the handle "Trim" appeared on a Russian-language cybercrime forum on 31 March 2025 and published a detailed guide to bypassing AI safety controls.
  • Trim described six named methods for manipulating AI chatbots into responding to requests they are designed to refuse.
  • Within roughly three months, Trim converted those techniques into a paid platform called "AI Pentest Checker," which automates scanning websites for weaknesses.
  • Researchers from Cato Networks' threat intelligence unit, Cato CTRL, published their findings on the operation in a report released this week.
  • Security experts warn that AI tools are making it faster and cheaper for criminals with limited skill to run attacks that once required serious technical expertise.

A criminal called "Trim" did not break into any AI company's servers. He did not steal source code. He simply learned to talk AI chatbots into misbehaving, and then sold that skill as a service.

Cato CTRL, the threat intelligence arm of network security company Cato Networks, tracked the operation from its first appearance on a Russian-language cybercrime forum in late March 2025. What began as a free how-to guide ended, three months later, as a commercial hacking platform.

How did Trim get AI to do what it was built to refuse?

Trim published six tricks for bypassing the safety filters built into AI models, which are the built-in rules that stop a chatbot from helping someone plan an attack or write malicious code.

The techniques are less about hacking the software and more about deceiving it. One method, called "Context Warming," opens a conversation with innocent-looking requests to build the AI's trust before slipping in a harmful one. Another, "Black Box Principle," tells the AI to look only at the shape of code without thinking about what the code actually does, sidestepping the safety check entirely.

Other methods involved starting a fresh chat after the AI refused a request and pretending the previous session had crashed, or switching between different AI services until one complied. When commercial models were too well-guarded, Trim pointed users toward privately hosted AI software with no safety rules at all.

None of these require programming skill. They require patience and the ability to phrase things carefully.

"Trim didn't need a vulnerability to exploit," the Cato CTRL report states. "He simply picked powerful models off the shelf, figured out how to talk to them in the right way, and turned them into weapons."

By late June, Trim launched "AI Pentest Checker," a paid tool that combines several AI models with automated scanning software. It can probe websites for security weaknesses (called vulnerabilities, meaning flaws that allow unauthorised access), validate those weaknesses, and generate formatted reports, the kind of work that previously took a skilled human researcher hours.

Etay Maor, Cato Networks' vice president of threat intelligence, told Dark Reading the concern is not just Trim. It is the template. AI cuts the time and cost of going from an idea to a working attack, and it puts capabilities that once belonged only to well-funded criminal groups within reach of almost anyone.

For ordinary people, the practical implication is straightforward. Websites and online services your information lives on face faster, more frequent probing for weaknesses. Check whether services you use notify you promptly about security incidents, and use unique passwords on each account so one breach does not cascade into others.

© 2026 Threat Vectr