// 1 CRITICAL · 1 ZERO-DAY · 4 CVE · 3 EXPLOIT · 1 ADVISORY IN THE LAST 24H
Trellix researchers have uncovered LLM-powered hacking tools for sale on underground forums that dramatically lower the technical barrier for sophisticated attacks. The report details services offering step-by-step ransomware attack plans, signature-based detection bypass, and AI models advertised without ethical guardrails, signaling a shift where the line between novice actors and APT-grade tradecraft is dissolving in real time.

Trellix published a report on Wednesday, August 12, 2026, on LLM-powered hacking tools for sale on underground forums. The research documents services that provide step-by-step attack plans, antivirus bypass, and AI models lacking ethical constraints, drastically reducing the expertise required for sophisticated operations. The takeaway for defensive teams: the barrier between a novice attacker and APT-level tradecraft is dissolving in real time.

Key Takeaways
  • APEX AI, offered by "Shadowx007," generates ransomware attack plans with step-by-step commands after the user inputs a target domain.
  • Metamorphic Crypter, sold by "ImpactSolutions" on Exploit forum, is designed to bypass signature-based detection; the actor claims it is undetectable by Windows Defender and most antivirus products.
  • MessiahGPT, which appeared on BreachForums in July 2026, is advertised as an "ethically unconstrained" AI model capable of generating exploits, payloads, proof-of-concept code, and malware refactoring.
  • Proofpoint detected indirect prompt injection tools for sale at $150 per month but found no evidence of specific attacks based on these tools; the activity appears to be in an exploratory phase.

From Manual Chain to Single Prompt: How the Kill Chain Changes

Jambul Tologonov, security researcher at Trellix, drew a sharp line between the pre-AI offensive model and the emerging one. "Traditionally, hacking required a deep, manual understanding of how network defenses interact with an exploit... You had to chain vulnerabilities yourself, which required a high level of specialized human knowledge." Now the same result is achieved with a prompt.

The report documents APEX AI as an emblematic case: the user enters a target domain and receives a complete attack plan for ransomware deployment, including step-by-step commands. The source does not specify the service price or user base. It has not been independently verified that the generated plans are actually functional or that APEX AI has been used in real-world attacks.

This shift has a direct effect on the defensive threat model. Security teams have traditionally relied on indicators of technical incompetence — scripting errors, recognizable patterns, behavioral signatures — to filter noise from real attacks. When orchestration is handled by an AI agent, those indicators disappear.

The Three Tools in Trellix's Sights

The report analyzes three distinct services, each with a different positioning in the underground market.

Metamorphic Crypter, offered on Exploit forum by user "ImpactSolutions," focuses on evasion. It is designed to bypass any signature-based detection technology; the actor claims it is undetectable by Windows Defender and most other antivirus products. Trellix has not independently verified this claim. The tool represents a level of evasion commoditization that previously required reverse engineering skills and payload tweaking.

MessiahGPT, which appeared in July 2026 on English-language dark web forums, is positioned as a generative model without ethical filters. According to the advertisement reported by Trellix, it generates exploits, payloads, proof-of-concept code, and writes and refactors malware. Unlike older tools such as WormGPT or KawaiiGPT — documented by Palo Alto Networks' Unit 42 in previous research — MessiahGPT was cited in a joint presentation by Accenture and Google Cloud at Black Hat USA 2026, granting it institutional visibility though not legitimacy. The source does not clarify whether it is a proprietary model, a fine-tuned model, or a wrapper around an existing LLM.

The third thread concerns indirect prompt injection. Proofpoint detected tools for sale at $150 per month that hide malicious prompts in PDFs, emails, web pages, and calendar invites. Yaniv Miron, director of threat research at Proofpoint, explained the mechanism: "If the agent falls for the indirect prompt injection, the adversary could potentially exfiltrate information from the user, steal credentials, or deploy malware on the user's device." Proofpoint has not, however, found evidence of specific attacks based on these tools; the activity appears to be in an exploratory or testing phase.

"Someone who wouldn't know where to begin in a pen test can now get a prioritized attack plan that mirrors APT-grade tradecraft" — Jambul Tologonov, security researcher at Trellix

Detection Must Adapt to an Attacker Without Traces of Incompetence

Tologonov's assertion has an immediate technical corollary for defenders. When the attacker no longer leaves fingerprints of inexperience — malformed scripts, recognizable sequences, opsec errors — detection systems based on low-quality behavioral patterns lose efficacy. The Trellix report does not detail specific countermeasures, but the implication is clear: the center of gravity of defense must shift toward detecting anomalous agent behavior rather than human operator error.

Palo Alto Networks, cited indirectly in the report, had previously highlighted how LLMs process malicious requests even when structured to appear legitimate. This raises a design problem for systems that integrate AI agents with access to sensitive data or executive capabilities.

What to Do Now

Security teams must recalibrate three operational levers in response to this commoditization. First: retune detection systems to identify anomalous AI agent behavior — such as automatically generated command sequences or reconnaissance patterns that are too rapid — rather than human scripting errors. Second: verify whether AI agents with access to corporate data are exposed to indirect prompt injection via PDFs, emails, or calendar invites, the vectors documented by Proofpoint. Third: treat automatically generated attack plans — such as those produced by APEX AI — as plausible threat models in resilience testing, even without confirmed evidence of operational use.

The exploratory phase flagged by Proofpoint leaves an unquantifiable window of time, but the iteration speed of AI models reduces the useful horizon for these adjustments.

Frequently Asked Questions

Have these tools already been used in real-world attacks?

Proofpoint explicitly stated it found no evidence of specific attacks based on the indirect prompt injection tools. For APEX AI and Metamorphic Crypter, the Trellix report does not independently verify efficacy or operational use.

Was MessiahGPT developed by Accenture or Google?

No. Accenture and Google Cloud cited it in a presentation at Black Hat USA 2026 as an example of AI model abuse, not as developers or promoters of the tool.

How much do these services cost?

The report documents only the price of the indirect prompt injection tools: $150 per month. For APEX AI, Metamorphic Crypter, and MessiahGPT, the price is not specified.

Sources

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. cybersecuritydive.com
  2. nextbigwhat.com
  3. packetlabs.net
  4. unit42.paloaltonetworks.com
  5. channeldive.com
  6. ciodive.com