Listen to this Post

Introduction: Cybercrime Enters a Dangerous New Phase
Artificial intelligence is no longer just a defensive tool for cybersecurity teams. According to a new report from Group-IB, AI has become the driving force behind what experts now describe as the “fifth wave” of cybercrime. This shift marks a fundamental transformation in how digital crimes are planned, executed, and scaled. With weaponized AI tools becoming cheaper, easier to use, and widely available on underground markets, cybercrime is moving faster than most defenses can adapt.
The Evolution of Cybercrime Over Three Decades
Group-IB’s report traces cybercrime back to its earliest forms in the 1990s, when malware and basic viruses were largely opportunistic. Attackers relied on curiosity, weak defenses, and simple exploits to spread damage.
As the internet matured in the 2000s, financially motivated cybercrime emerged. Fraud, banking trojans, and organized groups replaced hobbyist hackers, turning cybercrime into a profit-driven activity.
The 2010s and early 2020s introduced ecosystem and supply-chain attacks. Cybercriminals began targeting service providers, software vendors, and cloud infrastructure to compromise thousands of victims at once.
Now, since 2022, Group-IB argues that cybercrime has entered a fifth wave: weaponized AI. This phase is defined by automation, scale, and impersonation powered by artificial intelligence.
Weaponized AI: Skills Turned Into Scalable Services
In the foreword of the report, Group-IB CEO Dmitry Volkov explains that AI transforms human expertise into services that can be replicated endlessly. Tasks that once required skilled operators are now automated by AI-driven tools.
This shift makes cybercrime cheaper, faster, and far more scalable. Attackers no longer need deep technical knowledge; they can simply purchase AI-powered kits and deploy them with minimal effort.
Deepfake Technology Becomes a Criminal Commodity
One of the most alarming developments highlighted in the report is the widespread misuse of generative AI for deepfake creation. Synthetic videos, voices, and biometric data are now being sold openly on dark web marketplaces.
Group-IB researchers discovered “synthetic identity kits” that include AI video avatars, cloned voices, and biometric datasets for as little as $5. Subscription-based deepfake-as-a-service offerings start at around $10 per month.
How Synthetic Identities Enable Fraud and Bypass Security
These AI-generated identities are used to impersonate real people, manipulate victims, and bypass security controls such as Know Your Customer (KYC) systems.
By using realistic voice clones or live video deepfakes, attackers can trick victims into authorizing transactions, sharing credentials, or granting access to sensitive systems. Even a low success rate can be highly profitable at scale.
Dark Web Activity Explodes Around AI Crime Tools
Group-IB observed a dramatic rise in dark web discussions about AI-powered criminal tools. Between 2020 and 2022, mentions of such tools averaged fewer than 50,000 messages per year.
Since 2023, that number has surged to approximately 300,000 messages annually, indicating rapid adoption and growing demand among cybercriminal communities.
Live Deepfakes Lower the Barrier to Entry
During the report’s launch event in London, Group-IB cybercrime investigation lead Anton Ushakov emphasized that live deepfake tools are becoming especially popular.
While these tools may only convince 5% to 10% of targets, that success rate is more than enough to generate significant profits when attacks are automated and repeated at scale.
Phishing Enters the Agentic AI Era
Phishing remains one of the most effective cybercrime tactics, and AI is dramatically enhancing its efficiency. Group-IB reports that phishing kits now cost anywhere from the price of a Netflix subscription to $200 per month.
These kits are accessible to both small criminal groups and large-scale operations, further democratizing cybercrime.
From Manual Campaigns to Fully Automated Attacks
Traditionally, phishing-as-a-service required attackers to configure email servers, compile victim lists, and manage campaigns manually. AI has changed that completely.
Modern phishing kits embed AI models that automate victim selection, message personalization, delivery timing, and campaign optimization.
Agentized Phishing Adapts in Real Time
Group-IB identified a new class of phishing tools that use AI agents to run campaigns autonomously. These agents generate lures, send emails, collect feedback, and refine attacks based on victim responses.
From the victim’s perspective, each phishing attempt feels unique and personal, increasing the likelihood of success over time.
Dark LLMs Replace Experimental Chatbot Abuse
Beyond phishing and deepfakes, cybercriminals are now building proprietary “dark large language models.” These models are self-hosted, unrestricted, and optimized for criminal use.
Unlike early experiments such as WormGPT, modern dark LLMs are stable, powerful, and trained on malicious datasets.
What Dark LLMs Are Designed to Do
According to Group-IB, these models assist cybercriminals in multiple areas. They generate scam scripts for romance and investment fraud, help design phishing kits and fake websites, and assist with malware development.
They also support vulnerability reconnaissance, exploit chaining, and obfuscation techniques that make attacks harder to detect.
A Growing Market for Criminal AI Models
The report identifies at least three active vendors selling dark LLM subscriptions ranging from $30 to $200 per month. Each vendor reportedly serves more than 1,000 users, highlighting the scale of adoption.
These tools are no longer experimental curiosities; they are commercial products with customer support, updates, and marketing.
Nytheon AI: A Case Study in Unrestricted Models
One prominent example is Nytheon AI, an 80-billion-parameter, self-hosted chatbot promoted on dark web forums. It operates offline, routes traffic through TOR, and blends multiple open-source models.
Group-IB confirmed its sale on Telegram in April 2025, validating its technical capabilities and lack of ethical safeguards.
AI Industrializes Cybercrime Operations
Craig Jones, former Interpol cybercrime director and advisor to Group-IB, argues that AI has not changed criminal motives but has industrialized how those motives are pursued.
Cybercrime is now driven by speed, volume, and sophisticated impersonation, fundamentally altering how attacks are launched and how difficult they are to stop.
What Undercode Say:
AI Turns Cybercrime Into a Mass-Production Industry
Weaponized AI represents a structural shift, not a temporary trend. Cybercrime is moving from artisanal hacking to mass production, where attacks are assembled, tested, and deployed like software products.
The availability of low-cost AI tools means technical skill is no longer the main barrier to entry. This dramatically expands the pool of potential attackers.
Automation Favors Attackers Over Defenders
Defenders still rely heavily on human analysis and reactive controls. Meanwhile, attackers are using AI to automate reconnaissance, social engineering, and execution.
This asymmetry gives cybercriminals a speed advantage that traditional security models struggle to counter.
Identity Becomes the Weakest Link
Deepfakes and synthetic identities directly attack trust-based systems. When voice, face, and biometric data can be forged cheaply, identity verification loses reliability.
This challenges banks, governments, and enterprises that depend on digital identity as a security foundation.
Agentic Phishing Signals a New Threat Model
Agentized phishing is particularly dangerous because it learns from victims. Each failed attempt improves the next wave, creating a feedback loop that steadily increases effectiveness.
This mirrors the evolution of autonomous systems seen in other AI domains, now applied to cybercrime.
Dark LLMs Remove Ethical Friction
Public AI models still enforce safeguards that limit misuse. Dark LLMs remove those constraints entirely, giving criminals unrestricted access to powerful generative capabilities.
Once these models become widespread, controlling misuse through policy alone becomes unrealistic.
The Cost Curve Is Working Against Security
As AI tools become cheaper, attackers can experiment more aggressively. Failed campaigns cost little, while successful ones scale rapidly.
Security investments, by contrast, remain expensive and complex, widening the imbalance.
Law Enforcement Faces Attribution Challenges
AI-generated content complicates attribution. Deepfakes, synthetic personas, and automated agents obscure who is behind an attack and where it originated.
This undermines traditional investigative methods and slows response times.
Regulation Will Lag Behind Innovation
AI-driven cybercrime is evolving faster than legal frameworks. By the time regulations are implemented, attackers may already have moved to new techniques.
This places greater responsibility on private-sector collaboration and intelligence sharing.
Defensive AI Must Catch Up
The same technologies empowering attackers can also strengthen defense. However, deploying AI defensively requires careful tuning, transparency, and trust.
Without equal investment in defensive AI, organizations will remain at a disadvantage.
Weaponized AI Is Now a Permanent Threat Layer
The fifth wave is not a passing phase. Weaponized AI will likely remain embedded in cybercrime operations, continuously evolving alongside legitimate AI innovation.
Fact Checker Results
Report Source Verification ✅
Group-IB is a recognized cybersecurity firm with a documented history of threat intelligence reporting.
Market Claims Consistency ✅
Pricing, adoption trends, and tool descriptions align with known dark web market patterns.
Expert Commentary Reliability ✅
Statements from Group-IB leadership and former Interpol officials are credible and contextually consistent.
Prediction
AI-Driven Impersonation Will Surge 🎭
Deepfake-based fraud will increasingly target executives, public officials, and financial systems.
Autonomous Attacks Will Become the Norm 🤖
Agent-based phishing and malware operations will shift cybercrime toward continuous, self-improving campaigns.
Defensive AI Will Decide the Balance ⚔️
Organizations that fail to adopt AI-driven security will fall behind as weaponized AI becomes standard practice.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.infosecurity-magazine.com
Extra Source Hub (Possible Sources for article):
https://www.pinterest.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




