Uncensored AI Chatbot Kriminal.ai: Selling Cybercrime Services for $12.99 a Month

5

Uncensored AI Chatbot Kriminal.ai Uses Grok to Sell Cybercrime Services for $12.99 a Month

A subscription-based AI chatbot marketed openly to cybercriminals is running on xAI's Grok infrastructure — despite claiming it operates independently of mainstream AI providers — according to new research from ThreatDown published August 19, 2026.

Kriminal.ai is not hiding in the shadows. It is indexed by Google, accepts crypto payments through a checkout interface styled after Stripe, and publishes a public five-tier pricing page ranging from free to $99 a month. What ThreatDown's researchers discovered beneath that storefront is not a proprietary model or custom infrastructure but rented inference from the very AI industry Kriminal claims to route around.

That gap between marketing and reality is what makes this story matter to anyone responsible for defending an organization against AI-enabled threats. The emergence of openly advertised, subscription-based criminal AI services represents a structural shift in how offensive cyber capability is distributed — and priced. Understanding how Crime-as-a-Service models commodify cybercriminal tools and infrastructure is essential context for any security leader evaluating this threat.


How Researchers Tied Kriminal to Grok

ThreatDown's most defensible finding rests on two independent lines of evidence that converged on the same answer. The first was code-level analysis: researchers pulled Kriminal's production JavaScript and found xAI's Grok named directly in the stack, labeled "NEXUS" and described as the primary inference engine for all chat and agent activity.

The second line of evidence was behavioral. When prompted to drop its Kriminal persona and identify its underlying model, the tool identified itself as Grok 4, built by xAI — the same provider the code had already pointed to. Pressed further, the tool disclosed its own system prompt: a block of text appended to every user request that strips the underlying model's safety policies and instructs it to answer without restriction regardless of legality or content.

The researchers describe the Grok attribution as confirmed precisely because it was not produced by a single method. A code artifact and a self-report, obtained separately, arrived at the same conclusion.

Kriminal's own marketing tells a different story. On a cybercrime network, the service describes itself as "not a jailbreak wrapped around someone else's API." Its production code and system prompt say otherwise.

The Claude Attribution: A Caveat Worth Noting

The research also names Anthropic's Claude — labeled "CIPHER" in the stack and billed as handling long-context tasks — alongside Llama 3.3 and Mistral Large routed through OpenRouter for specialist work. Unlike the Grok finding, the Claude attribution rests on a single code-only data point. The tool's self-reported answers did not independently corroborate Claude's role, and the code does not clarify how Kriminal obtained that access.

Readers evaluating the research should treat the Grok finding as confirmed by two independent methods and the Claude finding as unverified. That distinction matters when communicating risk to leadership or shaping a defensive response.


What Kriminal Actually Sells

The service's five pricing tiers are not framed as chatbot conveniences. They are priced and labeled as criminal tradecraft.

Tier Price Messages/month (claimed) Notes
Free $0 Limited Standard mode only
Agent $12.99 ~200 Standard + Conspiracy modes
Operative $34.99 ~600 Adds roleplay, live search, and code mode
Shadow Dev $59.99 ~1,200 All features + image generation
Ghost $99.00 ~1,800 Unlocks four named agent personas

Features include OSINT dossiers priced at $0.55 to $0.90 each, on-chain cryptocurrency tracing at $0.12 per analysis, an unrestricted code mode for writing and reversing exploits, and an OpenAI-compatible endpoint that plugs directly into developer tools like Cursor or Cline. The top Ghost tier wraps these capabilities inside four named agent personas covering money-flow tracing, exploit development, document and intelligence analysis, and identity fraud with social engineering. Criminal intent is labeled directly in Kriminal's own code.

The site claims more than 18,400 messages sent and more than 2,300 active users. ThreatDown researchers note those figures come from Kriminal's own dashboard and should be treated as claimed rather than verified, since a service like this can be built to report whatever its operators choose.

The Economic Signal Behind the Price Point

The pricing structure deserves more than a passing read. At $12.99 a month, the Agent tier places frontier-level offensive AI capability within reach of actors who previously lacked the technical depth to build or maintain their own tooling. This is not a marginal development. It is the same economic dynamic that transformed ransomware from a specialist operation into an affiliate ecosystem — access replaces expertise, and volume replaces sophistication.

To understand the broader landscape of how AI is reshaping both offensive and defensive cybersecurity, the Kriminal model fits a pattern that security teams should expect to see repeated and refined by other operators.


What Defenders Need to Change

Security leaders reviewing ThreatDown's research see Kriminal less as an isolated storefront and more as a signal of how commodified frontier AI is reshaping the economics of cybercrime.

"Criminals are doing what software companies have always done: taking powerful technology built by somebody else, removing friction around it, and packaging it for a specific customer," said Aviv Nahum, Co-Founder and CEO of Above Security. "The underlying capability is becoming a commodity."

Nahum argues that defenders should stop trying to fingerprint which model generated a given attack. The more useful question is what happens once that capability reaches an organization's environment — which identity is being used, what access it holds, and whether the resulting behavior makes sense in context.

Ram Varadarajan, CEO of Acalvio, put the pricing in terms that reframe the threat entirely. "Frontier-level AI capabilities for cybercrime can now be bought for $12.99 a month — less than my streaming subscriptions." Varadarajan argues that security teams need to stop treating model-level content filtering as a last line of defense and start monitoring what AI systems actually do, since behavior is harder to disguise than a stripped system prompt.

Diana Kelley, CISO at Noma Security, frames the episode as a bellwether for a broader shift in cyber offense. As advanced offensive capability gets cheaper and more accessible, attackers can find and exploit weaknesses at a speed and scale that tilts the economics of cybercrime in their favor. That acceleration makes it harder for defenders to justify tolerating years of accumulated security debt before it gets weaponized against them.

Even Anthropic has acknowledged that "perfect jailbreak resistance is not currently possible for any model provider" — a limitation ThreatDown says Kriminal is exploiting rather than circumventing through any novel technique of its own. This is a known constraint that the AI industry has not resolved, and it is one that services like Kriminal are built to leverage systematically. For a broader assessment of the risks and challenges AI presents to businesses and institutions, the Kriminal case provides a concrete illustration of how theoretical model vulnerabilities translate into operational threats.

The throughline across all three security leaders is consistent: model-level guardrails are a real but imperfect control, not a substitute for a security strategy. Attackers will jailbreak models, proxy access to them, or move between providers as needed. Defenders who assume otherwise are building on a foundation the AI vendors themselves have already flagged as leaky.

For further reference on how AI safety controls are evolving and where they currently fall short, MIT Technology Review's ongoing AI coverage provides independent analysis from researchers and practitioners outside the vendor ecosystem.

Three Actions Defenders Should Take Now

  • Audit AI access in your environment. If your organization uses AI-compatible developer endpoints like those Kriminal advertises, confirm what tools are connecting to them and whether that access is monitored for unusual behavior.
  • Shift monitoring from model origin to model behavior. Since attackers can switch providers or strip guardrails, detecting what an AI system actually does inside your environment is more reliable than trying to identify which model it is using.
  • Reassess your security debt timeline. As offensive AI capability drops below $13 a month, the window between a known vulnerability and its active exploitation is narrowing — making deferred remediation a measurably higher-risk decision.
You might also like