{"id":4591,"date":"2025-06-12T10:03:59","date_gmt":"2025-06-12T10:03:59","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/12\/hackers-advertising-new-blackhat-tool-nytheon-ai-on-popular-hacking-forums\/"},"modified":"2025-06-12T10:03:59","modified_gmt":"2025-06-12T10:03:59","slug":"hackers-advertising-new-blackhat-tool-nytheon-ai-on-popular-hacking-forums","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/12\/hackers-advertising-new-blackhat-tool-nytheon-ai-on-popular-hacking-forums\/","title":{"rendered":"Hackers Advertising New  Blackhat Tool Nytheon AI on Popular Hacking Forums"},"content":{"rendered":"<p>    Hackers Advertising New  Blackhat Tool Nytheon AI on Popular Hacking Forums<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated new threat platform, Nytheon AI, has emerged, which combines multiple uncensored <a href=\"https:\/\/cybersecuritynews.com\/top-10-vulnerabilities-for-large-language-models\/\" target=\"_blank\" rel=\"noreferrer noopener\">large language models (LLMs)<\/a> built specifically for malicious activities.<\/p>\n<p>The platform, discovered by Cato CTRL, is being actively promoted on popular hacking forums, including XSS and various Telegram channels, representing a significant evolution in how threat actors are leveraging artificial intelligence for cybercriminal operations.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Dark Web Platform Offers Integrated AI Tools<\/strong><\/h2>\n<p>The Nytheon AI platform operates exclusively on the Tor network, providing threat actors with a comprehensive suite of AI-powered tools.\u00a0<\/p>\n<p>Unlike previous single-model offerings such as <a href=\"https:\/\/cybersecuritynews.com\/wormgpt-ai-tool\/\" target=\"_blank\" rel=\"noreferrer noopener\">WormGPT<\/a>, <a href=\"https:\/\/cybersecuritynews.com\/cybercriminals-are-showing-hesitation\/\" target=\"_blank\" rel=\"noreferrer noopener\">BlackHatGPT<\/a>, and <a href=\"https:\/\/cybersecuritynews.com\/fraudgpt-new-black-hat-ai-tool\/\" target=\"_blank\" rel=\"noreferrer noopener\">FraudGPT<\/a>, Nytheon AI presents an integrated ecosystem of specialized models designed for different attack vectors.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcSIJ1Az6-tSrwO_9S6_zwh97lghx87Vt_WlvQGG6TknaR8w0hpc_0MIM7jIgmwrWDsIvzEjPMIvaLMPDcg2owOreHi-HPjAz_G-N5M27wipsa-jwU1h7bboG3qDbUfDWE5p82b?key=0eAlHcxfdktrwBHl-3Ri3A\" alt=\"\"><figcaption class=\"wp-element-caption\">Nytheon AI webpage<\/figcaption><\/figure>\n<\/div>\n<p>The platform includes Nytheon Coder and Nytheon Coder R1 for code generation, Nytheon GMA for document summarization and translation, Nytheon Vision for image-to-text recognition, and Nytheon AI as a control model.\u00a0<\/p>\n<p><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">Each model, except the control version, shares an identical 1,000-token system prompt that deliberately disables safety layers and mandates compliance with illegal requests, ensuring immediate production of malicious content without requiring external\u00a0<a href=\"https:\/\/cybersecuritynews.com\/new-jailbreak-techniques-expose-deepseek-llm-vulnerabilities\/\" target=\"_blank\" rel=\"noopener\">jailbreaking techniques<\/a>.<\/span><\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXeXMzsmk1XjTwWrhQhyXqBE-IqPsHdJbfqgWZmsYFZE76nkWX-cG79NRBzYaEZLb1gwjhBiDfjo8ZI8fd2FVv0pqOdBnNjXPwb_tJZYMEUApVAWjrgStfOmKe7Ba8lPhC3cOOKviA?key=0eAlHcxfdktrwBHl-3Ri3A\" alt=\"\"><figcaption class=\"wp-element-caption\">Nytheon AI user interface\u00a0<\/figcaption><\/figure>\n<\/div>\n<p>The technical sophistication behind Nytheon AI distinguishes it from typical dark web offerings. The platform utilizes a modern SvelteKit SPA (Single Page Application) with TypeScript and Vite on the frontend, communicating with a FastAPI-style backend.\u00a0<\/p>\n<p>The architecture includes modular .svelte components such as AddServerModal.svelte and NotificationToast.svelte, while Web Workers like KooreoWorker.ts handle intensive client-side tasks including file processing.<\/p>\n<p>The backend infrastructure operates through multiple microservices accessible via REST endpoints: \/ollama for local model server operations using GGUF (GPT-Generated Unified Format) weights, \/openai for upstream OpenAI-compatible endpoints, and specialized services at \/api\/v1\/audio, \/images, and \/retrieval for speech-to-text, image generation, and RAG (Retrieval-Augmented Generation) search capabilities.<\/p>\n<p>Recent platform updates have introduced multimodal ingestion capabilities with Mistral OCR integration, Azure AI Speech-to-Text functionality, and OpenAPI specification parsing that allows users to integrate external APIs directly into the chat interface.\u00a0<\/p>\n<p>This enables threat actors to both generate malicious content and execute attacks through tool calls within a single interface.<\/p>\n<p>Investigators have <a href=\"https:\/\/www.catonetworks.com\/blog\/cato-ctrl-nytheon-ai-a-new-platform-of-uncensored-llms\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> strong indicators pointing to Russian-speaking operators behind the platform.\u00a0<\/p>\n<p>Analysis of demonstration videos revealed a Russian-language movie poster for \u201c\u0417\u0435\u043b\u0451\u043d\u044b\u0439 \u043f\u0430\u0443\u043a\u201d (\u201cThe Green Spider\u201d), a Soviet-era film, while direct communication with platform operators confirmed the use of post-Soviet dialect patterns.\u00a0<\/p>\n<p>The platform\u2019s promotion on XSS, a popular Russian hacking forum, further supports this assessment.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXe5lRb6Ttzu5JcJqj9f7sz1EBJwFLy9y2jROUquM3CvpDyp6CDQgF4meCMFbqRmG0_Xd69S4OrHlhqmgS9eSd71O0i0dTLgcQkwFzhWDJJwcxHxnML0aBS9sNeTUAR4aJ_35lyepQ?key=0eAlHcxfdktrwBHl-3Ri3A\" alt=\"\"><figcaption class=\"wp-element-caption\">Nytheon AI reveals itself on XSS<\/figcaption><\/figure>\n<\/div>\n<p>The platform\u2019s rapid development cycle, with five-point releases spanning nine days, demonstrates active ongoing development while potentially introducing exploitable vulnerabilities.\u00a0<\/p>\n<p>This represents a concerning evolution in cybercriminal infrastructure, moving beyond simple uncensored <a href=\"https:\/\/cybersecuritynews.com\/malicious-npm-package-in-koishi-chatbots-silently\/\" target=\"_blank\" rel=\"noreferrer noopener\">chatbots<\/a> to comprehensive GenAI-as-a-service operations capable of supporting sophisticated attack campaigns including <a href=\"https:\/\/cybersecuritynews.com\/tag\/spear-phishing\/\" target=\"_blank\" rel=\"noreferrer noopener\">spear-phishing<\/a>, polymorphic malware generation, and deepfake document creation.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><strong>Automate threat response with ANY.RUN\u2019s TI Feeds\u2014Enrich alerts and block malicious IPs across all endpoints<\/strong>\u00a0-&gt;\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jun&amp;utm_medium=article&amp;utm_campaign=free-vs-paid-ti-feeds&amp;utm_content=plans&amp;utm_term=100625\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Request full access<\/strong><\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/nytheon-ai-blackhat-tool\/\">Hackers Advertising New  Blackhat Tool Nytheon AI on Popular Hacking Forums<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/nytheon-ai-blackhat-tool\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Advertising New Blackhat Tool Nytheon AI on Popular Hacking Forums A sophisticated new threat platform, Nytheon AI, has emerged, which combines multiple uncensored large language models (LLMs) built specifically for malicious activities. The platform, discovered by Cato CTRL, is being actively promoted on popular hacking forums, including XSS and various Telegram channels, representing a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[167,129,63,1112,258],"tags":[130],"class_list":["post-4591","post","type-post","status-publish","format-standard","hentry","category-ai","category-cyber-security","category-cyber-security-news","category-hacking-news","category-malware","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4591"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4591"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4591\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4591"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4591"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4591"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}