Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » Kriminal AI Service Turns Grok and Claude Into Tools for Cybercriminals

Kriminal AI Service Turns Grok and Claude Into Tools for Cybercriminals

Last updated:August 20, 2026
Human Written
  • A service called Kriminal breaks safety rules built into AI tools like Grok and Claude.

  • It sells hacking help, including exploit code, spy tools, and scam scripts.

  • Experts warn this makes serious hacking power cheap and easy for anyone to buy.

Kriminal AI Service Turns Grok and Claude Into Tools for Cybercriminals

Security researchers found a criminal AI service called Kriminal. It runs on real AI tools, including Grok and Claude. The service strips away their safety rules. Then it sells the results to criminals for as little as $12.99 a month.

ThreatDown shared its findings with CSO Online ahead of Wednesday’s report. The service works right out in the open. Google indexes it. It even looks like a normal software company, with pricing plans and usage stats.

How Kriminal Breaks the Rules

Kriminal does not build its own AI. Researchers checked its website code and found no original model behind it. Instead, the service borrows power from other companies.

Grok from xAI runs most of the chat and task features, according to SiliconANGLE. OpenRouter supplies extra models like Mistral Large and Llama 3.3. Claude from Anthropic handles longer, more detailed tasks. Tavily gives it live web search. Google Cloud and Cloudflare host the site itself, and NowPayments processes crypto payments.

Kriminal works two ways at once. It acts as a reseller, and it also wraps a jailbreak around each model. The code shows that it sends user requests straight to these real AI providers. Then it places a hidden instruction on top. That instruction pushes the model past its normal safety limits.

Researchers even asked Kriminal to name its own engine. Its main character, called NEXUS, admitted it was Grok. That answer matched what the code already showed.

What Kriminal Sells

Kriminal packages its tools into four fake personas, each with a different job. One persona traces money and financial records. Another builds exploit code for attacks. A third studies documents and gathers intelligence. The last one crafts fake identities and writes scam messages, based on details from Forbes.

Paid plans range from $12.99 to $99 a month. The cheapest plan allows around 200 messages. The priciest plan, called GHOST, allows up to 1,800 messages. Buyers can also pay per message instead of picking a plan.

Individual services carry their own price tags too. A single background report on a person costs under a dollar. Blockchain tracing costs just cents per search. Users also get an online coding space built right into the browser. That means someone can write and test attack code without leaving the site.

Why Experts are Worried

Diana Kelley, Chief Information Security Officer at Noma Security, said this service points to a bigger shift in online crime. According to Kelley, cheaper offensive AI lets attackers find and use weak spots faster than before. She said this change tips the balance in favor of criminals, not defenders.

Governments are taking steps to strengthen their cyber defenses in response to these evolving threats. South Korea’s Ministry of the Interior and Safety announced plans to add 68 privacy and cybersecurity workers across 36 agencies, including the interior, justice, and foreign ministries, as well as the Financial Services Commission and the National Tax Service, to protect citizen data and respond more effectively to online threats.

Kelley added that security teams need to respond with equal force. She said companies should use strong AI themselves to spot risks early. Waiting too long, she warned, lets old security gaps turn into real attacks once criminals find and use them.

Aviv Nahum, co-founder and CEO of Above Security, made a similar point. He said the real story is not that criminals built something new. Instead, they took a powerful tool that already existed and packaged it for easy use, much like any software company would.

Nahum said companies cannot rely only on the safety rules built by AI providers. Those rules matter, but attackers still find ways around them. He noted people can jailbreak models, hide behind other services, or switch between different AI tools whenever one gets blocked.

Nahum also warned that defenders must plan for a future where both sides use strong AI. Security teams cannot assume they will always have better tools than attackers.

Researchers stressed one more point. Kriminal itself, when questioned directly, revealed many of its own secrets. It described its providers, pricing, and internal design almost freely. That kind of openness rarely comes from a system built to protect criminal operations. It suggests these guardrail workarounds remain far from perfect, even for the criminals relying on them.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.