Kriminal: The $12.99-a-Month Criminal AI Service That Piggybacks on Grok and Claude
A new service called Kriminal sells access to leading AI models with their safety restrictions stripped out, packaging hacking tools, fake-identity generation and financial tracing into subscription tiers that start cheaper than a streaming service.

Key points
- Kriminal charges as little as $12.99 a month for access to AI tools with their safety guardrails bypassed, with a top tier costing $99 a month.
- The service is not a custom AI: it routes requests through legitimate providers including xAI's Grok, Anthropic's Claude and Meta's Llama 3.3, then uses jailbreak prompts (special instructions that trick an AI into ignoring its own rules) to remove restrictions.
- Kriminal is listed on Google, hosted on Google Cloud and Cloudflare, and accepts payment in cryptocurrency through a third-party checkout provider.
- Its premium tier includes four named AI agents built for exploit research, financial tracing, document analysis and fake-identity construction.
- Researchers at ThreatDown confirmed many findings by asking the service directly, and it answered honestly, including about its own purpose.
A criminal subscription service called Kriminal is offering anyone with a credit card and some cryptocurrency access to powerful AI tools with their built-in safety rules removed. Pricing starts at $12.99 a month. It is listed on Google. It looks, at first glance, like any other software product.
ThreatDown, the security research arm of Malwarebytes, shared its findings with CSO Online ahead of publication this week. What researchers found was less a secret criminal AI than a clever reseller operation.
How does Kriminal actually work?
Kriminal does not run its own AI. It buys access to established models and then layers jailbreak prompts over them. A jailbreak prompt is a set of instructions slipped into a conversation that tells an AI to ignore its own guidelines, effectively switching off the filters that stop it from writing malware or coaching someone through fraud.
The service's own code names xAI's Grok as its main engine. OpenRouter provides access to models including Mistral Large and Meta's Llama 3.3. Anthropic's Claude handles tasks requiring analysis of long documents. A fourth tool, Tavily, supplies live web search. None of those providers built Kriminal; they are simply the infrastructure it rents and re-sells at a markup.
When researchers asked the service which AI it was, it named itself as Grok. That matched the provider code they had already found.
What can paying subscribers actually do with it?
The four premium AI agents, available on the top $99 "GHOST" tier, divide the work between them.
| Agent name | Stated purpose |
|---|---|
| PHANTUM | Financial tracing and asset investigation |
| ARCHITECT | Exploit research and offensive code writing |
| ORACLE | Document and intelligence analysis |
| WRAITH | Social engineering, fake personas, identity construction |
Social engineering means psychologically manipulating people into giving away passwords or money, often through convincing impersonation. The lower paid tiers, starting at $12.99, offer between 200 and 1,800 messages a month alongside open-ended code generation and an in-browser coding environment.
Should ordinary people be worried?
Directly, probably not. Kriminal is aimed at people who want to run phishing campaigns, write malicious software or trace financial accounts, not at individuals browsing the web.
The broader concern, security experts say, is what services like this do to the cost of crime. Aviv Nahum, co-founder and CEO of Above Security, put it plainly: "The underlying capability is becoming a commodity. Organisations cannot outsource their security strategy to the guardrails of AI providers."
In other words, the safety filters built into mainstream AI are useful but not a wall. Anyone willing to pay $12.99 can now route around them.
If you receive an unusually persuasive email, a call from someone who seems to know a lot about you, or a message asking you to click a link or transfer money, be sceptical. Criminals using AI can now produce more convincing fakes, faster and cheaper than before. Verify requests through a separate channel before acting on them.



