ThreatDown's recent investigation exposes that Kriminal, a widely marketed criminal AI platform, does not develop proprietary AI technology but instead uses SpaceXAI's Grok through unauthorized modifications to bypass safety restrictions. Operating openly on the clearnet and charging subscription fees, Kriminal tailors Grok for illicit activities by stripping its guardrails.

  • Kriminal runs on Grok AI with jailbreak prompt injections to remove restrictions.
  • The platform openly sells criminal tools and data analysis on the clearnet.
  • Multiple legitimate service providers unknowingly host parts of Kriminal’s operation.

What happened

ThreatDown, the security research division of Malwarebytes Inc., published findings showing that Kriminal, a criminal AI tool marketed with no filters or guardrails, is essentially SpaceXAI's Grok AI running under a jailbreak. Despite claiming to have circumvented legitimate AI limitations, Kriminal rents Grok and other AI models from established vendors, using prompt injections to disable their safety protocols.

Kriminal operates as a clearnet platform with openly advertised subscription plans ranging from a free tier to $99 monthly for premium services. These offerings include code exploits, identity construction, money laundering analysis, on-chain tracing, and social engineering support. Kriminal also monetizes through message-based charges and sells services like open-source intelligence dossiers.

Why it matters

The discovery highlights significant challenges in combating abuse of commercial AI platforms through prompt injection jailbreaks, where developers of AI tech remain blind to illicit end uses. Kriminal’s approach leverages multiple legitimate vendors, including SpaceXAI, Anthropic, and Google Cloud, each only aware of their part in the chain. This layered architecture complicates takedowns since no single provider controls the entire ecosystem.

Kriminal’s business model breaches suppliers’ terms of service, which explicitly forbid jailbreaking, adversarial prompting, and reselling of AI output. However, the fragmented nature of its infrastructure—combining cloud hosting, payment processors, and AI APIs—allows it to persist despite abuse policies and ongoing efforts by vendors to fight harmful uses of their systems.

What to watch next

The broader AI industry’s ability to curtail such criminal misuse hinges on developing more robust guardrails and improving cross-vendor cooperation on abuse detection and enforcement. Industry leaders like Anthropic have acknowledged that no current AI system is fully immune to jailbreaking, signaling a persistent vulnerability in content controls.

Regulators and cybersecurity experts will likely increase pressure on AI providers and infrastructure partners to monitor and disrupt illicit AI services. Meanwhile, continued research by security firms will be crucial to uncovering similar illicit repackaging operations, helping to shape policies and technical safeguards that limit criminal exploitation of AI technologies.

Source assisted: This briefing began from a discovered source item from SiliconANGLE. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings