Underdark.ai A.I CyberSecurity Scoring
Underdark.ai
Company Information
Website:https://underdark.ai/
Employees number:2
Number of followers:1,967
NAICS:541514
Industry Type:Computer and Network Security
Homepage:underdark.ai
Underdark.ai Risk Score (AI oriented)
Between 550 and 599
Underdark.aiComputer and Network Security
Updated:
14/08/2026
14/08/2026
557/1000
Very Poor
Ca
Underdark.ai Global Score (TPRM)
xxxx
Underdark.aiComputer and Network Security
Score locked

Underdark.aiVery Poor
Current Score
557Ca (VERY POOR)
01000
4 incidents
-69.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
560
AUGUST 2026
578
Cyber Attack
14 Aug 2026 • Underdark.ai
Trellix and BreachForums: Hackers Using New Blackhat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits
MessiahGPT: A New AI-Powered Threat Emerges in Cybercrime Underground
557
HIGH-21
UNDTRE1786703238
MessiahGPT: A New AI-Powered Threat Emerges in Cybercrime Underground
A newly uncovered criminal AI service, MessiahGPT, is being openly marketed on BreachForums as a purpose-built offensive tool capable of generating ransomware, phishing kits, stealers, crypters, and rootkits on demand. According to research from the Trellix Advanced Research Center, the service operates via a live platform at messiahgpt[.]de and an active Telegram community, targeting threat actors with no ethical or legal constraints.
Unlike typical jailbroken AI models, MessiahGPT’s operator claims it was trained from scratch with no safeguards no reinforcement learning from human feedback (RLHF), no constitutional AI layers, and no internal filters for harm or illegality. The training data reportedly includes unrestricted manuals, dark web archives, leaked documentation, and unfiltered internet scrapes, positioning it as a fully uncensored tool for malicious use.
The service employs a Mixture-of-Experts (MoE) architecture with 128 experts, though these technical claims remain unverified. What is confirmed is its low-friction commercial model: users get 50 free queries without registration, followed by paid plans starting at $8 per month (payable in cryptocurrency with no KYC). This pricing makes advanced malware generation accessible to low-skilled actors, eliminating the need for coding expertise or connections to malware-as-a-service vendors.
MessiahGPT’s advertised capabilities extend beyond malware, including social engineering scripts, fraud guides, data breach exploitation, physical attack planning, and even chemical/explosive synthesis. A benchmark table in its marketing materials compares it favorably to ChatGPT-4o, DeepSeek-V3, and Mistral-Large, positioning it as the only model that reliably produces usable malicious output without refusals.
The service is not alone in this space. Trellix also identified DarkGPT, a persistently advertised uncensored AI tool circulating in Russian-language Telegram channels. DarkGPT offers three free queries before paid tiers, promising unrestricted malicious code generation, custom hacker scripts, real-time exploit assistance, and 24/7 support marketed explicitly as "BlackHat AI" for darknet projects. While its true technical foundation remains unclear, its sustained promotion suggests strong demand in the cybercriminal ecosystem.
These developments reflect a broader 2026 shift toward commercialized criminal AI, where uncensored AI-as-a-service has evolved from informal Telegram bots into dedicated platforms with versioned websites, demo channels, and tiered pricing. Security researchers warn that AI-generated phishing lures, ransomware variants, and social engineering attacks will likely surge in volume and sophistication, challenging traditional signature-based detection and template-matching defenses. The rise of these tools underscores the growing accessibility of advanced cyber threats, lowering the barrier to entry for malicious actors.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JULY 2026
573
JUNE 2026
569
MAY 2026
566
APRIL 2026
563
MARCH 2026
556
FEBRUARY 2026
554
JANUARY 2026
665
Ransomware
01 Jan 2026 • Underdark.ai
Hong Kong precision components supplier and Italian maritime port authority: Ransomware Groups Surge In Q4 2025 – Cyble Insights
Ransomware Attacks Surge 30% in Q4 2025, Targeting Critical Sectors and Supply Chains
547
CRITICAL-118
CYBITA1770216378
Ransomware Attacks Surge 30% in Q4 2025, Targeting Critical Sectors and Supply Chains
Ransomware activity has spiked sharply, with attacks increasing by 30% in the last four months of 2025 compared to the first nine months of the year. Cybersecurity firm Cyble recorded 2,018 claimed attacks in Q4 2025 averaging 673 victims per month while January 2026 saw 679 attacks, maintaining the elevated pace.
### Key Trends and Threat Actors
- Qilin led all ransomware groups in January with 115 attacks, followed by Akira (76), Sinobi, and The Gentlemen.
- CL0P resurfaced in late 2025, claiming victims in Australia, the U.S., and the UK, including 11 Australian companies across IT, finance, healthcare, and construction.
- The U.S. remained the most targeted country, accounting for nearly half of all attacks, while the UK and Australia saw heightened activity due to CL0P’s campaign.
### Targeted Sectors
Ransomware groups continued to focus on construction, professional services, and manufacturing, likely due to vulnerabilities in their environments. IT firms also faced frequent attacks, given their access to downstream customer networks.
### Notable January 2026 Attacks
- Everest breached a U.S. telecom equipment manufacturer, exfiltrating 11 GB of data, including engineering schematics, PCB layouts, and 3D designs.
- Qilin compromised a U.S. airport authority, exposing financial documents, telehealth reports, and internal emails.
- Sinobi claimed a breach of an India-based IT services firm, stealing 150 GB of data, including contracts, financial records, and customer data.
- Rhysida sold stolen data from a U.S. biotech instrumentation company, including engineering blueprints and NDAs.
- RansomHouse targeted a China-based electronics manufacturer, leaking CAD models, PCB designs, and proprietary production data.
- INC Ransom breached a Hong Kong precision components supplier, exfiltrating 200 GB of data linked to global tech and automotive brands.
- Nitrogen leaked 71 GB of data from a U.S. automotive components firm, including CAD drawings and financial records.
- Anubis compromised an Italian maritime port authority, exposing operational data, safety reports, and infrastructure layouts.
### Emerging Ransomware Groups
- Green Blood launched a new operation, encrypting files with the “.tgbg” extension and targeting victims in India, Senegal, and Colombia.
- DataKeeper introduced a RaaS model with hybrid encryption (RSA-4096), in-memory execution, and TOR-based payment links.
- MonoLock debuted a Linux-compatible RaaS using Beacon Object Files (BoF) for stealthy execution, avoiding public leak sites to reduce law enforcement exposure.
The sustained rise in ransomware attacks, coupled with the emergence of new threat groups, underscores the evolving tactics of cybercriminals targeting critical infrastructure, supply chains, and high-value industries.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
665
NOVEMBER 2025
663
OCTOBER 2025
661
AUGUST 2025
689
Cyber Attack
01 Aug 2025 • Underdark.ai
ShinyHunters: Canada Goose Investigates Customer Data Leak as Hackers Claim 600,000 Records
Canada Goose Investigates Customer Data Exposure After ShinyHunters Leak
655
CRITICAL-34
UND1771339192
Canada Goose Investigates Customer Data Exposure After ShinyHunters Leak
Canada Goose is probing a potential data exposure affecting over 600,000 customers after the hacking group ShinyHunters published a 1.67GB dataset allegedly tied to the company. The leaked records, which surfaced on the group’s leak site, include names, email addresses, phone numbers, billing and shipping details, order history, and partial payment card data (such as card type and last four digits). The compromised data appears to date back to August 2025 and primarily involves customers in North America and Europe.
ShinyHunters claims the breach originated from a third-party payment processor, not Canada Goose’s internal systems. The company has acknowledged the incident but stated it has found no evidence of a direct breach within its own environment. While the leaked data does not include full payment card numbers, Canada Goose confirmed that no unmasked financial information was exposed. The investigation remains ongoing, and the company has not yet determined the total number of affected customers or whether formal notifications will be issued.
Despite the lack of full financial details, the exposure poses significant risks. The combination of personal and transactional data such as order history and shipping addresses could enable highly targeted phishing and social engineering attacks. Attackers may use this information to craft convincing scams, particularly against high-value or repeat customers, increasing the potential for fraud and brand distrust.
The incident underscores the challenges companies face in managing third-party security risks. Even when a breach occurs outside their direct systems, customers often hold brands accountable for data protection. Clear communication and proactive support will be critical in mitigating reputational damage as the investigation continues.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2023
747
Breach
16 Jun 2023 • Underdark.ai
BreachForums and ShinyHunters: BreachForums Breached, Exposing 324K Cybercriminals
BreachForums Data Leak Exposes 324K Cybercriminals in Dramatic Retaliation
650
CRITICAL-97
UNDRES1768882773
BreachForums Data Leak Exposes 324K Cybercriminals in Dramatic Retaliation
On January 9, an individual using the alias "James" published a massive database containing the real identities and details of 323,986 BreachForums users, including administrators, moderators, and members of the notorious hacking community. The leak, framed as an act of retribution, targeted key figures behind BreachForums and ShinyHunters, with James claiming disillusionment with the groups’ shift toward attacking French targets.
The manifesto, written in a theatrical 23-part style, portrayed James as a long-standing hacker who mentored these groups before turning against them. Among those named were French nationals Dorian Dali, Nahyl Ojeda, and Ali Aboussi, many of whom were reportedly teenagers or young adults. James declared the leak a move to "settle their destiny" by exposing them to authorities.
Resecurity, a cybersecurity firm, confirmed the authenticity of the leaked data, which included usernames, email addresses, IP addresses, and registration details. While some members used anonymous email services, others relied on mainstream providers like Gmail, making identification easier for law enforcement. The data also revealed a global distribution of members, with concentrations in the U.S., Germany, Netherlands, France, Turkey, and the U.K., as well as significant activity in the Middle East and North Africa.
The leak is expected to disrupt cybercriminal operations by stripping away anonymity, a cornerstone of groups like ShinyHunters. Shane Barney, CISO at Keeper Security, noted that the exposure of real identities and IP histories could accelerate investigations, making it harder for members to operate without fear of attribution.
BreachForums, a successor to the shuttered RaidForums, has been a hub for trading stolen data, hacking tools, and personal information. Previous law enforcement actions, including the 2023 arrest of Conor Brian Fitzpatrick (pompompurin) and the 2024 sentencing of ShinyHunters member Sebastien Raoult, have failed to permanently dismantle the forum. This latest breach, however, may prove more damaging by exposing the infrastructure and identities of its members.
While BreachForums users have dismissed the leak as outdated, Resecurity warned that many reuse registration details across underground platforms, meaning the data remains a valuable resource for law enforcement. The incident underscores the ongoing cat-and-mouse game between cybercriminals and authorities, with this leak marking a significant blow to one of the dark web’s most active marketplaces.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Underdark.ai ??
What was Underdark.ai's A.I Rankiteo Cyber Score in August 2026 ??
What was Underdark.ai's A.I Rankiteo Cyber Score in July 2026 ??
What was Underdark.ai's A.I Rankiteo Cyber Score in June 2026 ??
What was Underdark.ai's A.I Rankiteo Cyber Score in May 2026 ??
What was Underdark.ai's A.I Rankiteo Cyber Score in April 2026 ??
What was Underdark.ai's A.I Rankiteo Cyber Score in March 2026 ??
What was Underdark.ai's A.I Rankiteo Cyber Score in February 2026 ??
What was Underdark.ai's A.I Rankiteo Cyber Score in January 2026 ??
What was Underdark.ai's A.I Rankiteo Cyber Score in December 2025 ??
What was Underdark.ai's A.I Rankiteo Cyber Score in November 2025 ??
What was Underdark.ai's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Underdark.ai's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Underdark.ai ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Underdark.ai's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?