Every security budget meeting this year circles the same question: what’s actually changed, and what’s just vendors selling fear?
While teams argue over whether to license Codex or Claude for internal use, the adversary stopped waiting for that decision. The threat actors our legacy risk models were designed to detect, who operate with limited budgets, strict rate limits, and detectable commercial tools, are evolving.
A new generation of attackers now leverages free, locally-run AI that leaves absolutely no logs and imposes near-zero operational costs, effectively removing the two biggest barriers to sustained cyber intrusion. AI threat detection has transitioned from a future problem to an immediate priority.
The Economics of Unwatched Infrastructure
The appeal of these models for criminal operations has almost nothing to do with raw intelligence and everything to do with economics and operational security. Commercial APIs charge per token and log every call against an account that provider safety systems can easily ban. Western tools possess provider-side guardrails that severely limit their usefulness for autonomous attacks, and pushing against them acts as a tripwire that disables the account.
Open-weight models, where the trained parameters are freely released for anyone to download and run on hardware they control, fundamentally break this defensive paradigm. Once deployed on a local GPU, these models cost nothing per request, generate no logs for investigators, and operate entirely offline. Thanks to a steady stream of highly capable releases, models with genuine reasoning capabilities now fit on single consumer graphics cards, negating the need for massive data center infrastructure. The economics of running sophisticated operations have completely shifted in favor of the attacker. When infrastructure costs drop to zero, scaling malicious campaigns becomes trivial, forcing defenders to completely rethink how they evaluate risk.
The Uncensored Underground Marketplace
This isn’t theory. Go to any underground forum right now and you’ll find stripped-down Qwen and DeepSeek variants for sale like they’re SaaS products. The barrier to entry has evaporated, replaced by an ecosystem optimized for offensive operations.
- Underground marketplaces actively advertise stripped-down models, such as modified versions of Qwen, DeepSeek, and GLM.
- Public repositories host thousands of these fine-tuned models sold explicitly on the promise of having no ethical guardrails or refusal mechanisms.
- These uncensored models are marketed and supported exactly like legitimate Software-as-a-Service tools, complete with subscriptions and customer support.

This commercialization of crime means that threat actors do not need to be advanced machine learning engineers to leverage state-of-the-art offensive capabilities. They simply purchase or download pre-packaged malicious assets designed specifically to bypass modern detection systems. As these ecosystems mature, the velocity at which new exploit variants emerge will only accelerate.
Beyond backend scanning, a significant portion of this threat is driven by smaller, highly efficient model classes running in the four to eight billion parameter range. Because these models fit comfortably onto standard consumer hardware, threat actors utilize them for rapid, localized content generation tailored to specific targets. A local 8B model can synthesize an entire suite of deceptive infrastructure within minutes. Attackers leverage them to build fully fledged, pixel-perfect fake login pages, dynamic corporate landing portals, and malicious multi-step phishing interfaces on demand.
Furthermore, these compact models excel at orchestrating live, real-time text and chat conversations for social engineering. Instead of relying on static phishing templates that security gateways easily flag, an attacker can deploy a localized model to engage targets in fluent, context-aware dialogues designed to harvest credentials or bypass multi-factor authentication in real time. ‘

Autonomous Exploitation In the Wild
When mapping C2 infrastructure and tracking malicious IP addresses through near-live intelligence initiatives like Project Banana, the shift in adversary tactics becomes glaringly obvious. We are no longer observing lone hackers grinding through targets by hand because we are watching fully autonomous systems. Attackers wire open-weight models into open-source orchestration frameworks, enabling the system to independently scan the internet for vulnerable servers and generate attack queries in natural language.
Picking the model with the fewest safety controls because provider-side guardrails on the Western tools limited their usefulness for autonomous attacks. When the actor tried pushing harder against those Western models, the providers’ own safety systems caught and disabled the account. The open-weight tools had no equivalent tripwire because there was no provider left to pull one.
Here’s where it gets unsettling. During a recent threat hunt targeting A property firm, an automated system clone a VP’s voice, generate a conversation script, and run a full scamcall center loop with almost no human involved. Fraud operations now deploy fully automated scam call centers combining cloned voices, LLM-generated conversation scripts, and inbound AI responders with minimal human staffing.
The Attribution Problem No One’s Talking About:
Erosion of Zero-Trust Assumptions and Attribution Deficits: Frame open-weight exploitation as a direct bypass of modern Identity and Access Management (IAM) controls, because locally running models allows any attacker to move without provider lens, and they can control how it behaves, internal jargon, and contextual metadata at scale, effectively subverting human-in-the-loop verification processes. Unlike commercial API implementation where high-profile threat campaigns or platform misuse can place immediate regulatory and legal scrutiny on the provider (such as previous incidents involving state-sponsored actors abusing hosted LLM services).
Read more : https://bolster.ai/blog/huggingface-new-attacker-toolbox
When the execution happens on an air-gapped machine the attacker owns, there’s no provider to subpoena, no API logs to trace, no account to ban. That’s not just a detection problem it’s an attribution dead-end. CISOs can’t point fingers at OpenAI or Anthropic anymore, and regulators have no platform to fine.
This aggressive adoption is driving AI scams to surge by 1,210% against traditional fraud’s 195% growth, putting AI-driven scam losses on a trajectory toward $40 billion by 2027.
Sources:
- https://theworlddata.com/ai-fraud-statistics/
- https://infinenetech.com/blog/us-businesses-losing-millions-to-ai-scams-2026
- https://axis-intelligence.com/ai-scam-statistics/
How We Can Help You Stay One Step Ahead
As the scam economy automates its offense, the defense has been forced to do the same. This is where Bolster AI step in, essentially fighting fire with fire. To catch scammers and impersonators operating at machine speed, Bolster relies on an ensemble of computer vision, natural language processing, and deep learning.
The system continuously scans the open web, social media, app stores, and the dark web for lookalike domains, fake executive profiles, and deepfake campaigns. Instead of waiting for a human analyst to verify a threat, Bolster’s engine renders a verdict in milliseconds and executes zero-touch automated takedowns through direct integrations with hosting providers. For brands trying to stay one step ahead, this shift is critical. It transforms brand protection from a reactive manual effort into a continuous automated countermeasure, ensuring that when a rogue model spins up a fraudulent campaign, an equally capable AI is already waiting to tear it down.
The Defensive Imperative
As the scam economy automates its offense, defense must follow suit. The raw capability is now cheap enough that the guardrail question has stopped being the bottleneck it once was. Organizations must shift to continuous, automated countermeasures utilizing specialized AI, natural language processing, and deep learning to render verdicts in milliseconds and execute zero-touch takedowns before an autonomous agent can establish a foothold.
Perimeter defenses and quarterly reviews were built for human-speed attacks. That world is gone. If you’re still budgeting like it’s 2023, you’re not protecting your organization you’re just buying time until an autonomous agent finds the door you left open.