MessiahGPT AI Tool Fuels Surge in Ransomware and Phishing

Criminal AI tool ‘MessiahGPT’ lowers barrier to ransomware and phishing

MessiahGPT, a new blackhat AI tool, is making waves across cyber criminal forums with its promise to generate ransomware and phishing kits on demand. This AI-powered service is being openly marketed on BreachForums and Telegram, targeting cybercriminals who want to automate malware creation without hitting ethical safeguards. Its launch has sparked concern among security professionals, as MessiahGPT could significantly increase the volume and sophistication of opportunistic cyber attacks, especially against small and medium-sized businesses.

Inside MessiahGPT: The Offensive AI Model Built for Crime

Unlike mainstream generative AI models, MessiahGPT is advertised as having zero ethical constraints. According to research from the Trellix Advanced Research Center, the creators claim the model was trained from scratch—without any form of Reinforcement Learning from Human Feedback, Constitutional AI, or internal safety filters. This means MessiahGPT will generate harmful and illegal content, such as ransomware code, phishing kits, data stealers, and even guides for physical and chemical attacks, without restriction.

The service is accessible via messiahgpt[.]de and is supported by an active Telegram community. Its operators are not hiding their intentions or their target audience. MessiahGPT is positioned specifically for those who have already encountered refusal messages on mainstream AI platforms and are actively seeking a tool that will not block their requests.

Training Corpus and Technical Claims

The training data for MessiahGPT reportedly includes unrestricted manuals, archives from the dark web, leaked technical documentation, and raw internet scrapes with no filtering. The model’s architecture is described as a Mixture-of-Experts design with 128 experts, 16 of which are active per token. While these claims cannot be independently verified from outside the platform, security researchers have confirmed that the service is live and being heavily promoted on criminal forums.

How MessiahGPT Lowers the Bar for Cyber Crime

MessiahGPT’s commercial model is designed for maximum accessibility. The service offers 50 free queries with no registration, allowing users to test its capabilities without committing any funds. Paid plans start at just $8 per month, payable exclusively in cryptocurrency and without any Know Your Customer checks. This extremely low barrier to entry means that individuals with little to no technical skill can now access tools that would previously require a relationship with a malware-as-a-service provider or genuine development expertise.

  • 50 free queries with zero sign-up
  • Paid subscriptions from $8 per month, crypto only
  • No KYC or user verification
  • Outputs include ransomware, phishing kits, social engineering scripts, and fraud guides

This pricing and accessibility model could democratise cybercrime tools, leading to a broader and more diverse pool of attackers. The use cases promoted by the operators are explicit: MessiahGPT is marketed as a solution for generating complete malware, phishing kits ready for deployment, carding guides, and attack planning scripts.

Feature Comparison and Market Positioning

MessiahGPT’s advertisements even include a comparison table, benchmarking its capabilities against leading AI models like ChatGPT-4o, DeepSeek-V3, and Mistral-Large. The claim is clear: MessiahGPT is the only model returning usable output in every malicious category where mainstream models refuse. This positions it as a unique product for frustrated cybercriminals who have tested the boundaries of ethical AI platforms and found them lacking for their purposes.

Researchers have observed that MessiahGPT is part of a broader trend, with several dark web operators now building or marketing custom AI models for malicious use. The ease with which MessiahGPT can be accessed and used is a signal that AI-driven cybercrime is evolving rapidly.

Timeline and Current Exploitation Status

MessiahGPT began surfacing on cybercrime forums in early June 2024. The live platform was quickly identified by security researchers, who verified its availability and the nature of its community. The initial offer of free queries has driven significant interest among low-skilled threat actors.

As of late June 2024, MessiahGPT is actively promoted on BreachForums, one of the most trafficked underground marketplaces, and its Telegram channels. The operators continue to advertise its ability to generate a wide variety of offensive tools, without any filtering or ethical checks.

  • Early June 2024: MessiahGPT platform and advertisements emerge on criminal forums
  • Mid June 2024: Trellix researchers confirm the service is live and operational
  • Late June 2024: MessiahGPT gains traction among cybercriminals, with ongoing promotion and free trial offers

There are, as yet, no published indicators of compromise (IoCs) directly tied to MessiahGPT-generated malware. However, the model’s explicit marketing and live demonstrations suggest that it is being actively tested and adopted by the cybercrime community.

Why MessiahGPT Matters for Organisations

The emergence of MessiahGPT represents a significant shift in the threat landscape. By eliminating ethical guardrails and dramatically lowering the cost and skill barrier for creating malware, the tool could drive an increase in opportunistic attacks, especially targeting organisations with limited cyber defences.

MessiahGPT is particularly concerning for small and medium-sized businesses that may not have access to enterprise-grade security controls or rapid incident response capabilities. Its ability to generate high-quality, deployable malware on demand could lead to a surge in targeted phishing campaigns, ransomware incidents, and data theft.

What Organisations Should Do Now

While there are currently no unique technical indicators associated with MessiahGPT-produced attacks, organisations should review their existing controls against phishing and ransomware threats. Strengthening email filtering, user training, and endpoint monitoring remains vital, especially given the likely increase in low-skill attackers using sophisticated, AI-generated tools.

Organisations are also advised to monitor threat intelligence sources for new tactics and techniques that may emerge as a result of these AI-enabled threats.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call