{"id":9397,"date":"2025-12-22T10:00:31","date_gmt":"2025-12-22T10:00:31","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/22\/dig-ai-darknet-ai-tool-enabling-threat-actors-to-launch-sophisticated-attacks\/"},"modified":"2025-12-22T10:00:31","modified_gmt":"2025-12-22T10:00:31","slug":"dig-ai-darknet-ai-tool-enabling-threat-actors-to-launch-sophisticated-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/22\/dig-ai-darknet-ai-tool-enabling-threat-actors-to-launch-sophisticated-attacks\/","title":{"rendered":"DIG AI \u2013 Darknet AI Tool Enabling Threat Actors to Launch Sophisticated Attacks"},"content":{"rendered":"<p>    DIG AI \u2013 Darknet AI Tool Enabling Threat Actors to Launch Sophisticated Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new and ominous player has emerged in the rapidly expanding landscape of \u201cShadow AI.\u201d Researchers at Resecurity have identified DIG AI, an uncensored artificial intelligence tool hosted on the darknet that is empowering threat actors to automate cyberattacks, generate illicit content, and bypass the safety guardrails of traditional AI models.<\/p>\n<p>First detected on September 29, 2025, the tool has seen a surge in adoption throughout Q4, particularly during the winter <a href=\"https:\/\/cybersecuritynews.com\/holiday-season-cyber-alert-reflectiz-declares-war-on-magecart\/\" target=\"_blank\" rel=\"noreferrer noopener\">holiday season<\/a>.\u200b<\/p>\n<p>This development marks a significant escalation in the \u201ccriminalization of AI,\u201d lowering the barrier to entry for sophisticated cyberattacks and posing severe risks ahead of major global events in 2026, including the Winter Olympics in Milan and the FIFA World Cup.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-how-dig-ai-works\"><strong>How DIG AI Works<\/strong><\/h2>\n<p>Unlike legitimate platforms that enforce strict ethical guidelines, DIG AI is explicitly designed to have none. Accessible via the Tor network, it requires no account registration, ensuring complete anonymity for its users. The platform offers a suite of specialized models, as revealed in interface screenshots obtained by investigators:\u200b<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>DIG-Uncensored:<\/strong> A completely unrestricted model for generating prohibited text and code.<\/li>\n<li>\n<strong>DIG-GPT:<\/strong> A powerful text model reportedly based on a \u201cjailbroken\u201d version of ChatGPT Turbo.\u200b<\/li>\n<li>\n<strong>DIG-Vision:<\/strong> An image generation model based on Stable Diffusion, used for creating deepfakes and illicit imagery.<\/li>\n<\/ul>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg8tsZpuEb7lbHE0MGAK8R0In5GGqM8gYzCkJH_nZFmtw06uk3q7i93h-caqgRtGp-ARnsGeLsaTUS1BO_A7zcAje6wTmjvLMDjd1G9z8n8rR13s0ZHV1YL14VUWRoeZku3PW3mVk30qDKaM4ir8KbsHKtkJE493AYySvc_UgvLl_EXX1RCMj2qqpKEk25x\/w640-h404\/img2.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p>The tool\u2019s operator, a threat actor known by the alias \u201cPitch,\u201d actively promotes the service on underground marketplaces alongside narcotics and compromised financial data.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-automating-malicious-code-and-exploits\"><strong>Automating Malicious Code and Exploits<\/strong><\/h2>\n<p>One of the most alarming capabilities of DIG AI is its ability to generate functional malicious code. Resecurity analysts successfully used the tool to create obfuscated JavaScript backdoors designed to compromise web applications.\u200b<\/p>\n<p>Screenshots of the tool in action show it processing requests to \u201cgenerate and obfuscate malicious script,\u201d producing code designed to be stealthy and hard to detect.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhUVkjS1r0CNC-CM7fb6yC4t2bzFUd_4XjRvLc6-_LY9MZfzgDeX5Xf_lFCrelXkVAKPCD6np6_HxR2UnQF121V3dI5x9s13k5eYuUyFWtRebaDT30STv4GW-7mXQ8S3I_ZYtd5mRo9edRvTzNcpD1jtY0WMRr5TJMIqrcyu-3JAFEYeSDR3GW74HhtICaQ\/w640-h170\/img3.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p>The generated output acts as a web shell, allowing attackers to steal user data, redirect traffic to phishing sites, or inject further malware.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Feature<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">DIG AI<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Legitimate AI (e.g., ChatGPT)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Access<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Darknet (Tor), No Account<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Public Internet, Account Required<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Censorship<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">None (Uncensored)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Strict Safety Filters<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Primary Use<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Malware, Fraud, CSAM<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Productivity, Coding, Learning<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Cost Model<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Free \/ Premium for Speed<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Free \/ Subscription<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Infrastructure<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Hidden \/ Bulletproof Hosting<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Cloud Infrastructure<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>While complex operations like code obfuscation can take 3\u20135 minutes due to limited computing resources, the authors offer premium \u201cfor-fee\u201d services to mitigate these delays, effectively creating a \u201cCrime-as-a-Service\u201d model for AI.\u200b<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEimESjMYjfexBTYot0gN9Igi7JQKF44RZq7Uh4o5gGwszLy86FYeS6pX4DzCFmdKRBPkGtscvHIdsYfWJxPgVfSBv0kXQJmrRG4yWAsq8BV5TY7ov9WVTYpFKdg3YBt8xGedL3UxO5JzgHU1zzMEBcasIH3-XlgbAjF83NBihWtUpW74asRpNVlPlZXLkHG\/s16000\/img1%2520%281%29.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p>Beyond cybercrime, DIG AI is being weaponized to cause severe real-world harm. The tool has been observed generating detailed instructions for manufacturing explosives and prohibited drugs.\u200b<\/p>\n<p>Most critically, the \u201cDIG-Vision\u201d model facilitates the creation of Child Sexual Abuse Material (CSAM). Resecurity confirmed the tool can generate hyper-realistic synthetic images or manipulate real photos of minors, creating a nightmare scenario for child safety advocates and law enforcement.\u200b<\/p>\n<p>\u201cThis issue will present a new challenge for legislators,\u201d note Resecurity <a href=\"https:\/\/www.resecurity.com\/blog\/article\/dig-ai-uncensored-darknet-ai-assistant-at-the-service-of-criminals-and-terrorists\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">analysts<\/a>. \u201cOffenders can run models on their own infrastructure\u2026 producing unlimited illegal content that online platforms cannot detect\u201d.\u200b<\/p>\n<p>DIG AI represents the latest evolution in \u201cNot Good AI\u201d tools often referred to as \u201cDark LLMs\u201d or jailbroken chatbots. Following in the footsteps of predecessors like <a href=\"https:\/\/cybersecuritynews.com\/fraudgpt-new-black-hat-ai-tool\/\" target=\"_blank\" rel=\"noreferrer noopener\">FraudGPT<\/a> and <a href=\"https:\/\/cybersecuritynews.com\/wormgpt-ai-tool\/\" target=\"_blank\" rel=\"noreferrer noopener\">WormGPT<\/a>, these tools are seeing explosive growth, with mentions of malicious AI on cybercriminal forums increasing by over 200% between 2024 and 2025.\u200b<\/p>\n<p>As 2026 approaches, the cybersecurity community faces a \u201cfifth domain of warfare.\u201d With bad actors capable of automating attacks and generating infinite variations of malicious content, the fight against weaponized AI is no longer a future prediction; it is an urgent present reality.\u200b<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/dig-ai-darknet-ai-tool\/\">DIG AI \u2013 Darknet AI Tool Enabling Threat Actors to Launch Sophisticated Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/dig-ai-darknet-ai-tool\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>DIG AI \u2013 Darknet AI Tool Enabling Threat Actors to Launch Sophisticated Attacks A new and ominous player has emerged in the rapidly expanding landscape of \u201cShadow AI.\u201d Researchers at Resecurity have identified DIG AI, an uncensored artificial intelligence tool hosted on the darknet that is empowering threat actors to automate cyberattacks, generate illicit content, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[701,1636,129,63],"tags":[130],"class_list":["post-9397","post","type-post","status-publish","format-standard","hentry","category-cyber-attack","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9397"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9397"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9397\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9397"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9397"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}