Group‑IB warns weaponised AI is fuelling the fifth wave of cybercrime, with dark LLMs, deepfakes, and scalable crimeware.

DUBAI: Leading cybersecurity firm Group‑IB has published a groundbreaking whitepaper warning that weaponised AI is driving the fifth wave of cybercrime. Their report uncovers how artificial intelligence is now deeply embedded into the global criminal ecosystem, powering everything from deepfakes to phishing kits at industrial scale.

Cybercrime has evolved significantly since the 1990s, moving from basic phishing to complex ecosystem attacks. Group‑IB’s latest research shows a 371% rise in dark web forum posts referencing AI since 2019, with an 1199% increase in replies, indicating explosive growth in criminal interest. By 2025, AI abuse had dominated underground discussions, with nearly 300,000 replies across 23,000+ dark web posts.

Unlike past waves, the fifth wave is defined by the weaponised AI itself—not just the tools but its full integration into core criminal infrastructure. Threat actors are now offering AI crimeware-as-a-service with subscription tiers mimicking mainstream software models. Prices start as low as $30 monthly, making powerful cybercrime tools accessible to novices.

Group‑IB has identified three major categories: LLM exploitation, phishing/social engineering automation, and malware toolkits. Dark LLMs are particularly concerning, with vendors creating uncensored AI models built solely for malicious tasks, amassing over 1,000 users. Jailbreak frameworks for bypassing safety features of popular AI models have also surged.

Meanwhile, the deepfake-as-a-service market is exploding, with a 52% spike in 2025 alone. Services now offer synthetic voice kits, cloned biometric data, and video actors for as little as $5, using only seconds of stolen audio.

Group‑IB calls for global collaboration across governments, law enforcement, and cybersecurity sectors. The report concludes that to counter this AI-driven threat, defenders must adopt intelligence-led strategies prioritising predictive analytics and underground threat visibility.