AI Tools Surge in Ransomware Markets, Lowering Entry Barriers

Underground markets see a boom in AI-driven tools, making ransomware more accessible and profitable.

ThreatVectr Newsdesk· 2 min read
AI Tools Surge in Ransomware Markets, Lowering Entry Barriers
Share

AI-based tools are flooding underground ransomware markets, significantly lowering the barrier for new cybercriminals. An analysis revealed that AI utility posts grew from 38 in December 2025 to 1,486 by February 2026. These tools fall into four categories: weaponized LLMs, AI-enabled identity fraud, AI-augmented malware, and jailbroken AI services.

Weaponized LLMs, sometimes called 'dark LLMs', strip away safety protocols found in legitimate models. 'WormGPT' dominates this market, though it's often just a brand for scammers collecting payments without delivering services. AI-enabled identity fraud tools use deepfakes to bypass KYC systems, while AI-augmented malware infrastructure boosts data exfiltration efficiency. Jailbroken AI services, mainly hacked accounts, are the cheapest offerings.

Ransomware attacks have surged by 20% since 2023, targeting smaller enterprises, which now account for 80% of attacks. Speaking at Infosecurity Europe, Cynthia Kaiser of Halcyon noted that major ransomware operators like Akira mirror legitimate business models by selling services and infrastructure, albeit with exploits and stolen credentials. Sales channels include Telegram bot-driven systems, and AI tools even offer customer service.

Despite the sophistication, criminal OpSec is lacking. Rival criminals frequently steal from each other, as seen when WormGPT credentials were dumped on their originating forum. This professionalization, however, allows for scalable attacks.

Ransomware remains lucrative. Rapid7's research shows a 39% profit increase from Q1 2025 to Q1 2026, with groups like Qilin making $193 million in under a year. The ecosystem has matured into a marketplace offering services like initial access and exfiltration. AI-driven social engineering, especially for crafting phishing lures, is common.

Law enforcement is making a dent, but businesses must also bolster defenses. Halcyon suggests focusing on preventing initial access, detecting lateral movement, and disrupting data exfiltration and encryption. Tabletop exercises can build resilience, Kaiser advises.

© 2026 Threat Vectr