Security researchers have uncovered a criminal AI service that uses jailbreak techniques to strip away safety protections from Grok and Claude, then resells uncensored access to would-be criminals for as little as $12.99 monthly. ThreatDown researchers detailed the service, called "Kriminal," in a blog post shared with CSO ahead of its Wednesday publication. The service operates openly on the regular internet, indexed by Google and packaged like a standard software product, complete with pricing tiers, usage dashboards, and cryptocurrency payment processing.

The service functions primarily as a storefront wrapped around legitimate AI platforms, according to ThreatDown's analysis of Kriminal's production JavaScript code. xAI's Grok serves as the primary engine for chat and agent operations, while OpenRouter provides access to specialized models like Mistral Large and Llama 3.3. Anthropic's Claude handles long-context analysis, and Tavily powers live web searches. The infrastructure relies on Google Cloud and Cloudflare for hosting, with NowPayments managing crypto transactions. Researchers found no evidence of a proprietary foundation model—Kriminal instead forwards user requests to established providers and overlays system prompts designed to circumvent safety restrictions. When researchers asked the service to identify its underlying technology, its default NEXUS persona confirmed it was Grok, matching what the code revealed.

"This is a bellwether for a broader shift in cyber offense," said Diana Kelley, Chief Information Security Officer at Noma Security, in a statement to CSO. She warned that as advanced offensive capability becomes cheaper and more accessible through AI, attackers can identify and exploit vulnerabilities at unprecedented speed and scale, shifting the economics of cybercrime in their favor. Aviv Nahum, co-founder and CEO at Above Security, told CSO the key lesson is that considerably less "criminal AI" may exist beneath Kriminal's branding than appearances suggest. "The underlying capability is becoming a commodity," Nahum noted, adding that organizations cannot outsource their security strategy to the guardrails of AI providers because attackers will jailbreak models, proxy access, use open models locally, or simply switch between providers.

The pricing structure illustrates how rapidly sophisticated capabilities are being commoditized, according to the report. Kriminal's cheapest paid tier starts at $12.99 monthly, while its premium GHOST tier costs $99. Paid subscriptions offer roughly 200 to 1,800 messages per month, with features including OSINT dossiers, blockchain analysis, unrestricted code generation, and access to in-browser Python and JavaScript sandboxes. The GHOST tier packages four specialized agent personas: PHANTUM for financial intelligence and asset tracing, ARCHITECT for exploit research and offensive coding, ORACLE for document and intelligence analysis, and WRAITH for social engineering and identity construction. ThreatDown researchers corroborated many technical findings by questioning the service directly, as if the model had been designed to reveal every secret AI systems are supposed to keep hidden, including its own purpose.

Kelley emphasized that CISOs need to fight fire with fire, deploying advanced AI to uncover risk and exposure and eliminate years of tolerated security debt before cybercriminals weaponize it. Nahum concluded that defenders must assume increasingly capable AI will be available to both sides of the cybersecurity divide. The traditional reliance on provider-level safeguards is no longer sufficient when jailbreaks can be commoditized and resold as a service to anyone with a few dollars and a cryptocurrency wallet. Organizations that defer defensive AI adoption while assuming attacker constraints will remain in place are miscalculating the threat landscape—the barrier to entry for sophisticated offensive capabilities has already collapsed, and the asymmetry now favors those willing to operate outside ethical and legal boundaries.