On August 8, 2023, security journalist Brian Krebs published an article identifying the creator of the criminal AI chatbot WormGPT as Rafael Morais, who lives in Portugal. The creator shut WormGPT down himself that same day.

By autumn 2025, however, "WormGPT 4" was on sale for $50 a month or a $220 one-time purchase. Rapid7 reports that the variants circulating in 2026 share no code with the original WormGPT.

The creator and the code were different, yet other sellers kept using the WormGPT name. Some of those sellers do not have their own AI at all. Behind the scenes they call a legitimate AI service and package it as a product. Other attackers use stolen credentials to reach legitimate AI.

What has actually been bought and sold under the WormGPT name can be traced through price lists, court records and malware analysis reports from 2023 to 2026. Following the same records also shows where room for intervention against these services remains.

AD

WormGPT stopped the day its creator was identified, and a same-name product appeared two years later

wormgpt-name-timeline-2023-2026.webp

WormGPT's development was announced in March 2023 on the hacker forum Hack Forums, and it was released on the same forum in June. It was built on GPT-J (6 billion parameters), an open-source model published by EleutherAI.

Morais himself told reporters that he had used GPT-J 6B from the start, and that anyone who tried WormGPT would find little difference from other uncensored AIs or a jailbroken ChatGPT.

GPT-J 6B is a publicly released open-source model, not a commercial model offered by a legitimate AI company. Neither Cato CTRL nor Krebs explained what infrastructure WormGPT actually ran on.

The turning point was Krebs's article, published on August 8. The creator shut WormGPT down, citing excessive media exposure and a bad reputation. Morais also told reporters he had about 200 paying customers. In other words, WormGPT was stopped by its own creator after a journalist identified him.

According to SOCRadar, the very next day, August 9, another seller was advertising "Evil-GPT" as a replacement for $10.

The "WormGPT" products that followed inherited only the original's name.

In June 2025, Cato CTRL, the research arm of Cato Networks, analyzed two variants posted on the criminal forum BreachForums.

For the variant released by the poster xzin0vich on October 26, 2024, it concluded with high confidence that it was based on Mistral AI's Mixtral, and noted that it might have been fine-tuned. The Telegram group this seller used had about 7,500 members.

For another variant released by the poster keanu on February 25, 2025, Cato CTRL believes it is a wrapper around xAI's Grok API, combined with a jailbreak system prompt designed to bypass the AI's safety controls.

A wrapper is a service that calls a legitimate AI behind the scenes and offers its responses to users as its own product. In this form, what the seller owns is a product name, a sales channel and a means of accessing the legitimate AI, not the AI model itself.

In its June 2026 report, Rapid7 likewise notes that the WormGPT variants now in circulation share no code with the original and are often wrappers around commercial model APIs.

"WormGPT 4" appeared around September 27, 2025. According to Unit 42, the research arm of Palo Alto Networks, it was sold through Telegram and underground forums, and its Telegram channel had more than 500 subscribers. A figure published by Unit 42 shows 571.

The developer has not disclosed the underlying model or training data. The original WormGPT was sold in euros and WormGPT 4 in dollars, so comparing the two prices alone does not establish that prices have fallen.

The three years around the WormGPT name can be sorted into four types: appearance, shutdown, successor and legal action. A data leak that fits none of these is listed separately as a claim.

Date Event Type Source
March 2023 WormGPT development announced on Hack Forums Appearance Cato CTRL
June 2023 WormGPT released Appearance Cato CTRL
July 22, 2023 FraudGPT begins circulating on Telegram Appearance Netenrich
August 8, 2023 Krebs identifies the creator; WormGPT shuts down the same day Shutdown Krebs, Cato CTRL
August 9, 2023 Another seller advertises Evil-GPT as a replacement Successor SOCRadar
October 26, 2024 xzin0vich's WormGPT variant; Cato CTRL judges it Mixtral-based Successor Cato CTRL
December 2024 Microsoft sues 10 anonymous defendants Legal action Microsoft
February 25, 2025 keanu's WormGPT variant; Cato CTRL sees it as a Grok wrapper Successor Cato CTRL
February 27, 2025 Microsoft's amended complaint names 4 Storm-2139 defendants Legal action Microsoft
Around September 27, 2025 WormGPT 4 goes on sale Successor Unit 42
February 10, 2026 Post claims user data from a site calling itself WormGPT was leaked; unconfirmed Claim SOCRadar
February 2026 EvilTokens begins Appearance Microsoft
September 11, 2026 Two people arrested in the UK on suspicion of involvement in running EvilTokens Legal action The Record
September 22, 2026 Microsoft announces disruption of EvilTokens Legal action Microsoft

The original WormGPT stopped on August 8, 2023, the day its creator was identified. Yet its name was carried on by variants that appeared from October 2024 and by WormGPT 4, which went on sale in September 2025.

The legal actions in the timeline are Microsoft's lawsuit, which began in December 2024, and the EvilTokens disruption in September 2026. According to Microsoft's complaints, the former targeted a group that resold access to legitimate AI, and the latter targeted an AI-enabled fraud service.

This timeline is organized within the scope of publicly available reports. The WormGPT 4 launch date is an estimate ("around September 27"), and the February 2026 data leak remains a claim by the poster.

What Trend Micro meant by "bullets"

In a report published February 9, 2026, the Japanese edition of Trend Micro's analysis described the current state of the criminal AI market this way: criminals are no longer selling the "gun" (a full set of illicit tools) but the "bullets" (means of abusing existing AI models).

The parenthetical explanation appears in the Japanese edition. In the English edition dated January 28, 2026, no equivalent definition can be found.

The English edition gives WormGPT clones, malware that generates code on the fly, and a $5 nudify bot as examples of "bullets." The explanation is that the same economic logic is being applied across different stages of an attack.

Phishing email text and malicious code are the outputs obtained by using these "bullets."

Unit 42 confirmed that WormGPT 4 can generate natural-sounding text for business email compromise (BEC) and phishing, as well as basic ransomware code. However, Unit 42's Kyle Wilhoit told The Register that human tuning is needed to make the generated code harder for common defensive products to detect.

Trend Micro cites three conditions that explain why criminals do not build their own models.

Building a large language model (LLM) from scratch that rivals legitimate services requires enormous computing resources, large-scale training data and advanced expertise, all at once. For that reason, taking an existing model as a base and removing its safety controls is cheaper and more realistic.

Uncensored models that can run locally also exist on Hugging Face, but Trend Micro rates their performance as falling short of mainstream models such as Gemini.

A case in which the advertising and the reality diverged sharply is "Xanthorox."

It had been openly promoted on dark-net forums since February 2025, claiming to use its own LLM and not to depend on external APIs. The web app accepted only cryptocurrency, at $300 a month, with a higher tier at $2,500 a year.

But Trend Micro inferred from its responses that the underlying model was Google's Gemini Pro. Google also told Trend Micro that it had confirmed access to its models and a violation of its terms of use.

In a February 2026 report, Google's Threat Intelligence Group (GTIG) said it had disabled accounts and AI Studio projects associated with Xanthorox.

According to GTIG, Xanthorox was in reality a commercial API with safety controls bypassed, plus a dependence on open-source MCP servers. MCP is a standard for connecting AI to external tools.

Even a product billed as having its own AI actually depended on Google's models, so the means of stopping it remained with Google, the model's provider.

AD

Who is paying for the legitimate AI?

Seven services can be organized along five dimensions: underlying model, delivery form, price, sales channel, and the cause of shutdown or current status.

For delivery form, services that call legitimate AI via API are marked "via API," and those that cannot be determined from the sources are marked "unknown." Prices are the amounts advertised by sellers; because currencies and contract periods differ, no conversion or simple ranking has been done.

Service Underlying model Delivery form Price (advertised) Sales channel Cause of shutdown / current status
Original WormGPT GPT-J 6B (Cato CTRL, Krebs) Unknown (no operating form described) €60–100 a month, €550 a year (Cato CTRL). Krebs lists licenses at €500–5,000 Hack Forums, Telegram Shut down by its creator on August 8, 2023
FraudGPT Not disclosed Unknown $200 a month to $1,700 a year (Netenrich) Telegram, dark markets Still circulating in 2026 (Rapid7 assessment)
xzin0vich's WormGPT variant Mixtral (Cato CTRL's judgment) Unknown Subscription and one-time payment Telegram Survival status unknown
keanu's WormGPT variant Grok API plus jailbreak system prompt (Cato CTRL's judgment) Via API (Cato CTRL's judgment) Not stated Telegram Survival status unknown
WormGPT 4 Not disclosed Unknown $50 a month, $175 a year, $220 one-time (Unit 42) Web, Telegram On sale as of November 2025
Xanthorox Advertised as its own LLM. Google's models per Trend Micro's analysis Via API (GTIG analysis) $300 a month, $2,500 a year (paid in cryptocurrency) Web Pricing screen shown in Rapid7's June 2026 report
EvilTokens Multiple AI models (Microsoft) Unknown $1,500 joining fee plus $500 recurring fee Telegram Seized in September 2026; arrests on suspicion of involvement in operating it

Of the seven cases in the table, the four whose underlying models have been identified, namely the original WormGPT, the two WormGPT variants and Xanthorox, all used existing models such as GPT-J, Mixtral, Grok and Google's models. This includes analyses by Cato CTRL and Trend Micro.

Only two of them, keanu's variant and Xanthorox, are confirmed to have delivered their service by calling legitimate AI through an API.

FraudGPT and WormGPT 4 have not disclosed their underlying models, and for EvilTokens only "multiple AI models" have been disclosed.

Rapid7 cautions that prices for such products fluctuate widely because of crackdowns, scams and rebranding, so they are only a rough guide.

Converting WormGPT 4's prices to a monthly basis shows a pricing structure in which longer contracts are cheaper.

Dividing the prices recorded by Unit 42 by the number of months gives $50 for the monthly plan, about $36.7 for the three-month plan ($110 ÷ 3) and about $14.6 for the annual plan ($175 ÷ 12), rounded to one decimal place. The one-time $220 is equivalent to about 4.4 months of the monthly plan.

In January 2026, Group-IB reported that at least three vendors dealing in "Dark LLMs," LLMs sold for criminal use, charged $30 to $200 a month and had more than 1,000 customers in total.

However, those figures cover only the three vendors the company observed and do not represent market-wide prices.

Separate from the sale price, there is also the usage fee for the legitimate AI being called behind the scenes.

Every time a wrapper generates a response, the legitimate AI's API is used, and the charge goes to the owner of the API key. If it is the seller's own key, the seller bears the cost; if the key was stolen, the bill goes to its rightful owner.

In August 2026, Unit 42 reported an incident response case of "token jacking," in which stolen API keys were built into a relay service. Leaked credentials were abused within minutes, and charges of nearly $1 million had accrued by the time it was discovered.

Sysdig named attacks that use stolen cloud credentials to access legitimate LLMs "LLMjacking" in May 2024.

It estimated that if Claude 2.x on Amazon Bedrock were used up to the limit in four regions simultaneously, the damage could reach $46,080 a day at the prices at the time.

This is a guide to the maximum a victim could bear in a day, not damage that actually occurred. It is also a different kind of figure from the sale prices of criminal AI services.

In August 2026, Okta analyzed that access to AI was being sold on the gray market at 70 to 90 percent below regular subscription prices, with free tiers and bonus credits being abused as the source.

Access to legitimate AI itself has become a commodity.

In its September 2026 report, Anthropic reported that going after the credentials used to reach AI, such as compromised API keys, session tokens and devices, is becoming the main objective for multiple criminal groups.

Criminal groups sell this access to brokers, and brokers feed it into fake AI resale networks that swap in stolen keys one after another until they stop working.

On September 8, 2026, GTIG reported that on the underground forums it tracks, both buyers and sellers of AI accounts increased in 2026, and the average price per account more than doubled.

Demand is concentrated especially on Claude and Gemini credentials and on Cursor Pro and Devin accounts.

Criminal services that use legitimate AI through APIs rest on the billing infrastructure of legitimate providers.

The underground market prices GTIG observes do not show the actual costs borne by operators of services like WormGPT 4.

Even so, access to legitimate AI is itself being traded on the underground market, with buyers and sellers both increasing and average prices rising. It can be read that demand for access to legitimate AI is concentrating in the underground market.

Seizures reached sites, while the name passed to other sellers

FraudGPT, which has circulated on Telegram since July 22, 2023, faced a different kind of removal from WormGPT.

According to Abnormal Security, FraudGPT's sales threads were repeatedly deleted from major criminal forums for violating their rules, and each time the seller moved to a new place to sell. The deletions were carried out by the forum operators.

Still, in June 2026, Rapid7 described FraudGPT as a "staple" of the underground economy. According to the company, it has changed from an independent model into a simple wrapper that combines jailbreak instructions with a legitimate company's API.

Even when its sales venues were deleted, the name remained and only the contents were swapped out.

In the two cases involving courts, too, the targets were not the sellers who inherited the WormGPT name.

According to Microsoft's complaints, the targets were a group that resold access to legitimate AI and an AI-enabled fraud service.

In December 2024, Microsoft's Digital Crimes Unit (DCU) sued 10 anonymous defendants in the U.S. District Court for the Eastern District of Virginia.

The court issued an injunction, and websites used to operate the criminal group were seized.

In an amended complaint filed on February 27, 2025, the company named four Storm-2139 defendants, individuals in Iran, the United Kingdom, Hong Kong and Vietnam.

According to Microsoft's complaint, Storm-2139 used customer credentials obtained from public sources and elsewhere to gain unauthorized access to generative AI services including Azure OpenAI Service, altered their capabilities, and resold access as plans at different prices.

On September 22, 2026, Microsoft announced the disruption of EvilTokens.

EvilTokens, which began in February 2026, was a service that used AI to analyze compromised email inboxes and suggest who had authority to send money and whom to impersonate.

According to Microsoft, more than 10,000 organizations were involved and more than 12,000 inboxes were compromised. The company seized 50 sites and disabled more than 150 domains. OpenAI also cooperated in the action.

On September 11, London's Metropolitan Police arrested two men, aged 32 and 38, on suspicion of making articles for use in fraud and money laundering in connection with the operation of EvilTokens. Both are currently on bail.

The DCU's Steven Masada explained that EvilTokens' AI did not merely write fraud text but also assisted with decisions about whom to target and whom to impersonate.

For the DCU, this action was its 40th court-approved disruption and the first against an "end-to-end AI crime service."

What was actually seized in these two cases was the infrastructure for running the services, such as websites and domains.

The name "WormGPT" itself, by contrast, has no asset to seize. The day after the original creator shut the service down, another seller advertised Evil-GPT as a replacement, and since 2024 the sellers using the WormGPT name have themselves been replaced.

Trend Micro sees the criminal LLM market consolidating around a few long-active providers. Rapid7, on the other hand, assesses it as an unstable market with many short-lived services and swapped-out brands.

Two major reports published in 2026 thus differ in their views of how stable the market is.

However, the scope the two companies observe is not the same.

Trend Micro mainly covers criminal LLMs as of the end of 2025, while Rapid7 examines a broader underground market that includes stolen accounts. Both are analyses based on sellers' advertisements and observations of underground forums, not statistics on market size.

The two companies do agree, however, that turning access to existing AI into a product has become the center of the market.

This difference also affects how effective measures such as seizures are judged to be.

If, as Trend Micro points out, the market is consolidating around a few long-active providers, the targets of disruption can be narrowed to a handful of operators.

Conversely, if short-lived services and swapped-out brands dominate, as Rapid7 points out, stopping one seller just moves its name and customers to the next one.

AD

Revoke the API key and the malware stops. That was the idea

ai-malware-model-call-destinations.webp

Multiple PromptSteal samples examined in September 2025 by SentinelLabs, the research arm of SentinelOne, contained a total of 284 distinct Hugging Face API keys embedded in them.

All were keys that had circulated after a 2023 credential leak. PromptSteal is malware that works by calling an AI model through Hugging Face.

This kind of malware hands part of its processing to queries to an AI.

Calling a cloud-based AI requires an API key, so if the provider revokes that key, the malware can no longer receive answers from the AI.

From this property, SentinelLabs assessed AI-enabled malware that stops working when API keys are revoked as "brittle."

Conversely, even if one key is stopped, queries to the AI can continue as long as another valid key remains.

Collecting the AI-enabled malware and AI-assisted intrusion cases reported between January 2025 and July 2026 in threat reports from SentinelLabs, GTIG, ESET and Sysdig, and classifying them by where they call the model, gives the following.

"Open-weight" refers to a model whose trained weights are public and which can be run in one's own environment. PoC in the table means proof of concept.

Case Reporter and date Where the model is called Classification
MalTerminal SentinelLabs, September 19, 2025 OpenAI's GPT-4 API; an endpoint deprecated in early November 2023 Cloud API
PromptSteal (LameHug) Reported by CERT-UA in July 2025; compiled by SentinelLabs in September 2025 Qwen2.5-Coder-32B-Instruct via the Hugging Face API Cloud API
PROMPTFLUX GTIG, November 5, 2025; classed as experimental Gemini API Cloud API
QUIETVAULT GTIG, November 5, 2025; classed as confirmed in operational use AI CLI tool already installed on the infected device AI CLI on infected device
PromptLock ESET, August 26, 2025 Local gpt-oss-20b via the Ollama API Local open-weight (research PoC)
HONESTCUE GTIG, February 12, 2026 Gemini API Cloud API
PROMPTSPY GTIG, May 11, 2026 Gemini API (gemini-2.5-flash-lite) Cloud API
JADEPUFFER Sysdig, July 1, 2026 Not identified in the text Model unknown

Of the eight cases confirmed in public reports from 2025 through July 2026, five call a cloud API, one uses an AI CLI on the infected device, and one uses a local open-weight model; for the remaining one, the model has not been identified.

The one local-model case is a research PoC.

These figures count only published reports and will change as new cases are reported. Nor does the small number of local-model cases prove that criminals rarely use them in practice.

Regarding PromptLock, ESET explained in a September 3, 2025 addendum that it closely resembles a research prototype from New York University (NYU), reinforcing the view that it is a PoC.

Here it is classified as a local model following ESET's description, but there are discrepancies with other reports. This point is discussed below.

Providers are in fact suspending keys and accounts.

In its November 2025 report, GTIG said it had disabled assets associated with PROMPTFLUX.

SentinelLabs found MalTerminal by using a YARA rule to search for string patterns specific to commercial API keys. YARA is a mechanism for describing the characteristics of malware and other files as rules and matching them against files.

When the search was extended to cover the past year, it turned up more than 7,000 samples and more than 6,000 distinct keys. Most of them, however, were harmless.

SentinelLabs points out that legitimate API use and malware communication use similar credentials, making the two hard to tell apart.

Attackers, for their part, also factor in the possibility of having their API keys suspended.

According to GTIG, PROMPTSPY was built so that the Gemini API key and the VNC relay server could be swapped out from an external command-and-control (C2) server. VNC is a mechanism for remotely controlling a screen.

GTIG assessed that this design showed the developers had anticipated defenders' takedown measures in advance.

QUIETVAULT uses an AI CLI already installed on the infected device, that is, an AI tool used from the command line.

Neither is easily stopped by disabling a single API key.

In JADEPUFFER, reported by Sysdig, an LLM carried out an intrusion from start to finish, using a vulnerability in Langflow as the entry point. The LLM also searched the compromised environment for stored API keys for OpenAI, Anthropic, DeepSeek, Gemini and others.

How far has the blind spot of local AI spread?

In its first-half 2026 report, Flashpoint analyzed that threat actors are increasingly running off-the-shelf AI tools in their own environments, creating areas that are hard for defenders to see.

The point is that AI is starting to run in places beyond the reach of providers' and defenders' monitoring.

Over 293 days of observation, SentinelLabs and Censys identified 175,108 Ollama hosts in 130 countries that were reachable from the internet without authentication. Ollama is software for running LLMs in a local environment.

On September 8, 2026, GTIG reported that in activity suspected to be by UNC6508, attackers installed a local open-weight model inside a compromised cloud environment and evaded monitoring of commercial AI APIs.

GTIG itself limits this activity to "suspected."

There are examples of a clearly documented shift to local operation outside the criminal AI market as well.

According to Anthropic's September 2026 report, "Lakana 360," an infrastructure for monitoring about 25 million SIMs in Mali, was designed and developed using Claude and then moved to operation with an on-premises local model.

Anthropic explains that measures against an account do not affect products that have already been deployed.

This is a case closer to state surveillance than to the trade in criminal AI. Even so, it shows that if development uses cloud AI and production operation moves to local, AI providers' takedown measures no longer reach it.

As long as cloud AI is used, queries pass through the provider's servers and are tied to a specific account or credential.

When a provider discovers use that violates its terms, it can suspend that account.

A model run in a local environment, by contrast, has no provider-side account to suspend. Nor does the provider have a direct channel for stopping its use.

That said, some reports note performance limits for local models.

Trend Micro assesses that uncensored models running locally fall short of mainstream commercial models.

Also, according to Help Net Security, Microsoft's "Digital Defense Report 2026" reported that open-weight models lag closed models by about seven months in the ability to carry out attacks autonomously.

On PromptLock, reports differ in their descriptions.

Trend Micro believes PromptLock may be easy to detect because it downloads a model of about 11 GB.

ESET's original report explains that it uses a local model through the Ollama API.

Meanwhile, according to Help Net Security, Microsoft's report says the model ran on the attacker's infrastructure.

For that reason, the idea that downloading a large model could serve as a detection clue remains, for now, no more than Trend Micro's analysis.

By the number of public reports, cases of using stolen API keys to evade providers' takedown measures outnumber cases of moving to local operation.

According to Anthropic, one hacktivist kept up attacks for about a month using nothing but stolen API keys. All of those keys had leaked from Anthropic customer environments.

People associated with ShinyHunters, on obtaining AI API keys at a victim's site, switched their own attack processing over to those keys.

GTG-50020, which compromised an AI vendor's evaluation sandbox, also first took out production environment keys.

In May 2026, GTIG reported that China-linked attackers had built a setup resistant to the suspension of individual accounts, using scripts that repeatedly auto-registered and cancelled premium LLM accounts and relay software that handled many accounts in bulk.

Anthropic cites as one advantage of using stolen API keys that the traffic is likely to look like use by the legitimate owner.

Local models run outside the provider's monitoring. Stolen keys, by contrast, sit within the provider's monitoring while blending into legitimate use.

Assessments by research firms also differ on homemade LLMs.

Trend Micro says there are almost no proprietary LLMs running on criminals' own infrastructure. Group-IB and Flashpoint, on the other hand, report moves by threat actors to build their own models or to run models in their own environments.

Organized by the layer that can be monitored, in the area where providers' APIs and accounts are visible, cases of slipping past monitoring by reusing stolen keys and accounts have been concretely reported.

In the area where local models are used, one suspected activity, one research PoC and one surveillance-infrastructure case have been confirmed.

Counting public reports alone, cases abusing stolen keys are more numerous. However, most of the reporters are AI providers that issue API keys and security companies.

For local AI running outside the provider's field of view, not being seen is itself an observational blind spot.

What the number of published cases shows is not which is used more, but where activity can be observed.

Countermeasures confirmable in Japan, and conditions to watch next

According to Japan's National Police Agency, there were 2,454,297 phishing reports in 2025.

Unauthorized internet banking transfers numbered 4,747, with damage of about ¥10.397 billion, and phishing accounted for about 90 percent of the methods.

A group of suspects in tech-support scams targeting Japanese people used generative AI to identify targets, generate fake warning screens (pop-ups) and translate into Japanese.

In Japan, too, arrests in cases involving abuse of generative AI continue.

On May 27, 2024, the Tokyo Metropolitan Police arrested a 25-year-old man for creating ransomware using conversational generative AI. It was the first such case in Japan.

In June 2025, Osaka Prefectural Police arrested a 36-year-old man and others over a phishing site modified using generative AI.

In December of the same year, the Tokyo Metropolitan Police arrested a 17-year-old high school student for sending about 7.24 million unauthorized commands with a program created through abuse of generative AI.

What the National Police Agency's statistics and these three arrests show is the damage and acts on the side where products made with AI, such as phishing text and malicious programs, were used in actual crimes.

Looking at "access to legitimate AI," one step earlier, some of the countermeasures set out by IPA offer clues.

IPA's "10 Major Security Threats 2026" was decided and announced on January 29, 2026. In the organizational category, "cyber risks surrounding the use of AI" was selected for the first time and ranked third.

The explanatory guide for organizations, issued in March 2026, points out that AI translation has made it possible to write phishing text in the target's native language without anything seeming off.

As countermeasures, it lists understanding AI usage through communication logs and CASB, and banning unauthorized AI. CASB is a mechanism for understanding and controlling the use of cloud services.

For authentication, it calls for thorough multi-factor authentication (MFA), and for money transfer procedures, confirmation by multiple people.

The "understanding of AI usage" that IPA sets out is, at heart, a measure for checking how AI is being used inside a company.

This idea can also be applied to checking where and how the API keys and AI accounts a company holds are being used.

GTIG has confirmed that operators of infostealers, malware that steals credentials, issued commands targeting the configuration files of the AI coding assistants Cline and Continue.

AI API keys stored on developers' machines are also among the credentials organizations should take inventory of.

MFA and multi-person approval of payments remain defenses even after AI has made fraudulent text natural enough that "unnatural writing" alone can no longer give it away.

There are three conditions worth watching going forward.

The first is how the average price of AI accounts changes on the underground markets GTIG tracks. It is one indicator of how much access to legitimate AI is in demand.

The second is whether the "seven-month gap" between open-weight and closed models in the ability to carry out attacks autonomously, which Microsoft is reported to have found, narrows. If the gap narrows, the performance limit that restrains the use of local AI weakens.

The third is whether providers can distinguish the use of stolen keys that have flowed into relay and resale networks from legitimate use by the rightful owners.

In February 2026, Trend Micro predicted that the use of AI in crime would grow steadily more sophisticated rather than explode all at once.

The name WormGPT itself could not be stopped.

If room for takedown measures remains today, it lies in the API keys and accounts of the legitimate AI that sellers use behind the scenes.

However, what can be disabled is only individual accounts and credentials.

GTIG reported in February 2026 that it had disabled accounts associated with Xanthorox, yet Rapid7's June report of the same year still showed Xanthorox's pricing screen.

If AI providers become able to tell use of stolen keys apart from legitimate use, and companies themselves can see how their own API keys and AI services are being used, the next criminal service built on calling legitimate AI behind the scenes will find it harder to secure the access it needs.