- What: AI platform 'Kriminal' raises concerns about potential misuse
- Impact: Cybercriminals could use the platform for social engineering and offensive cybercrime
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources APPLICATION SECURITY СLOUD SECURITY THREAT INTELLIGENCE CYBER RISK NEWS No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns The AI company officially forbids illicit use, while offering guardrail-free social engineering, offensive cybercrime, and OSINT scanning to anyone with a bit of cryptocurrency. Alexander Culafi,Senior News Writer,Dark Reading August 19, 2026 3 Min Read SOURCE: ANNASTILLS VIA GETTY IMAGES A company is selling an AI platform that advertises itself as having no limits, raising questions about the product's potential usage by cybercriminals. The model's name is "Kriminal," and it's the subject of new research published yesterday by ThreatDown, Malwarebytes' enterprise-focused security brand. ThreatDown describes Kriminal in a blog post as "one of the newest and most popular tools in the criminal AI market." Despite the platform's name and ThreatDown's characterization of it as a popular tool in the emerging "criminal AI" market, it's indexed on the clear web and can be found through a simple Google search. Unlike traditional exploit kits and other cybercrime services, which are often marketed directly around attack capabilities, Kriminal presents itself more like a conventional software-as-a-service (SaaS) product. One similarity between Kriminal and illicit services is the payment method: subscriptions are purchased using cryptocurrency only. Access starts at $12.99 per month. Related:Critical GitLab Zero-Click Flaw Poses Mitigation Challenges The Kriminal website claims 18,400-plus messages have been sent to its platform to date, with 2,300 active users and 99% of questions answered. Makeup of a Kriminal While Kriminal's website doesn't explicitly advertise itself as a cybercrime tool, its "WRAITH" feature offers "social engineering & persona craft" for those who pay for the highest tier of service. Another feature, the "ARCHITECT" agent, advertises an "offensive security & exploit expert." Kriminal also offers guardrail-free conspiracy discussion, uncensored image generation, open-source intelligence (OSINT) scanning for things like names and addresses, cryptocurrency tracing, and more. Moreover, Kriminal's terms page explicitly says the service is for "research, creative, and educational purposes," and forbids activities that "use the Service in any manner that violates applicable local, national, or international law." The terms suggest Kriminal's operators distinguish between an "uncensored" AI service and an unmoderated one; the terms reference the use of manual and automated detection for illicit exploitation content involving minors, and the company says user efforts to generate such content may be sent to the appropriate authorities. But the platform's no-filter, no-guardrail marketing strategy — not to mention the service's name — raises questions. The operators of Kriminal AI do not appear to publicly identify themselves on the service's website, and no contact information was available (Dark Reading attempted to contact the company but did not receive a response at press time). On the other hand, legitimate parties also use OSINT scanning, cryptocurrency tracing, and offensive cybersecurity testing. Related:Belgium's eID Authentication Opens Citizen Accounts to RCE Kriminal: A Smattering of Off-the-Shelf AI Parts? On what it described as a "cybercrime network," ThreatDown said Kriminal pitched itself as "not a jailbreak wrapped around someone else's API," but based on an under the hood analysis, almost none of its components are proprietary. According to the vendor's analysis, Kriminal appears to rely on Grok for primary inference; Google Cloud and Cloudflare for hosting; Anthropic's Claude for a long-context model layer; Llama routed through OpenRouter for certain specialized tasks; Tavily for live search; NowPayments for cryptocurrency checkout (no KYC included, apparently); and Cloudflare/Let's Encrypt for DNS and TLS. As ThreatDown puts it, even if Kriminal uses various models for tasks they're otherwise not intended for, each only sees a part of the criminal whole. "That's what makes it resilient. Cloudflare can see traffic, not what it's for. NowPayments can see a crypto payment, not what it purchased," ThreatDown's blog post explained. "Each vendor in the stack only has visibility into its own layer, so no single company can act on the whole picture, only its own slice of it. The takedown surface isn’t a bulletproof host to seize: it’s a dozen separate abuse-desk tickets, each addressing a fragment of an operation none of them can see in full." Related:Microsoft's Patch Tuesday Deluge Continues With August Updates If ThreatDown's research and characterizations are accurate, Kriminal may create compliance and policy questions for the AI providers whose models it relies on. However, proving a term of service violation would be difficult. It would require examining the specific agreements, API usage patterns, and outputs involved to reach any sort of conclusion. About the Author Alexander Culafi Senior News Writer, Dark Reading Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Search Security, Nintendo World Report, and elsewhere. At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels. He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion More Webinars You May Also Like APPLICATION SECURITY Supply Chain Attack Secretly Installs OpenClaw for Cline Users by Rob Wright FEB 19, 2026 APPLICATION SECURITY Chinese Hackers Hijack Notepad++ Updates for 6 Months by Jai Vijayan FEB 02, 2026 APPLICATION SECURITY Trump Administration Rescinds Biden-Era Software Guidance by Alexander Culafi JAN 29, 2026 APPLICATION SECURITY Microsoft Fixes Exploited Zero Day in Light Patch Tuesday by Jai Vijayan DEC 09, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! Editor's Choice APPLICATION SECURITY Critical GitLab Zero-Click Flaw Poses Mitigation Challenges byJai Vijayan AUG 18, 2026 5 MIN READ CYBERSECURITY OPERATIONS Mission-Driven Security: Inside a Global Bank's Defense byKristina Beek AUG 14, 2026 CYBERSECURITY OPERATIONS Walmart Leaders Transform Security Operations Without Going Bananas byRichard Thurston AUG 12, 2026 5 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices