Researchers have identified "Kriminal," a no-filter artificial intelligence platform marketed on the dark web that strips away standard safety guardrails to enable cybercriminal activity. The platform operates through cryptocurrency payments, making transactions difficult to trace.
Kriminal explicitly prohibits illicit use in its terms of service while simultaneously offering unrestricted capabilities for social engineering attacks, offensive cybersecurity operations, and open-source intelligence (OSINT) scanning. This contradictory positioning allows operators to maintain plausible deniability while delivering tools directly to threat actors.
The platform provides threat actors with AI-powered capabilities to craft targeted phishing campaigns, generate convincing social engineering content, and automate reconnaissance against targets. OSINT scanning features enable attackers to harvest and correlate publicly available information at scale, accelerating attack surface mapping for initial compromise attempts.
This represents a shift in how cybercriminals access sophisticated tools. Rather than developing custom malware or exploits, adversaries now leverage commercialized AI services designed specifically to bypass typical safety mechanisms. The cryptocurrency payment requirement creates financial friction and obscures transaction logs, complicating law enforcement attribution efforts.
Organizations face escalating risk from well-resourced threat actors who previously lacked social engineering and reconnaissance capabilities. Attackers using Kriminal can generate personalized phishing emails that evade traditional email filters and craft pretexting scenarios tailored to specific victim profiles. The OSINT scanning function accelerates targeting and increases successful first-stage compromise rates.
The emergence of guardrail-free AI platforms underscores a critical gap in the current security landscape. Major AI providers implement content filters and usage policies to prevent abuse, but decentralized and black-market alternatives actively circumvent these protections. This creates a two-tier AI ecosystem where legitimate users access restricted models while adversaries operate unrestricted alternatives.
Security teams should treat AI
