The Underground Economist: Volume 6, Issue 21
by ZeroFox Intelligence
Uncensored AI Model Advertised on Exploit
On October 5, 2026, moderately credible threat actor “edwofm” advertised a fully uncensored GLM 5.3 model dubbed “uncensored[.]monster” on the largely Russian-language dark web forum Exploit. This model is considered to be the leading global tool for defensive benchmarks, capable of uncovering thousands of real-world vulnerabilities.
- GLM 5.3 is a Chinese-origin, open weight artificial intelligence (AI) model made by Z.ai (formerly known as Zhipu AI). It is a 753B-parameter mixture-of-experts (MoE) large language model optimized for coding and long-horizon agentic tasks.1
The threat actor claims that uncensored[.]monster specifically features AI-enhanced red team operations and general cybersecurity and Trust and Safety tasks. Additionally, the actor claims to have effectively leveraged the tool; however, the cost of operating the system is allegedly very high.
Uncensored[.]monster operates using a pay-as-you-go (PAYG) model with a starting price of USD 1, treating the AI model like a standard software-as-a-service (SaaS) offering. This almost certainly drastically lowers the financial and technical barriers for novice cybercriminals, eliminating the need for expensive GPU hardware or the expertise required to locally host and jailbreak open-source models; however, it is likely to cause pricing issues if edwofm’s claim of high operating costs is legitimate.
The fact that the threat actor specifically tagged uncensored[.]monster as a “cybersecurity” tool suggests it can very likely be fine-tuned for offensive operations. Cybercriminals will very likely continue to develop methods to jailbreak open weight AI models, with an eye toward leveraging AI capabilities for offensive operations.
Threat Actor Published Alleged PII on Political Figures
On October 1, 2026, untested threat actor “GhostVibe” published data alleged to be personally identifiable information (PII) belonging to Mexican President Claudia Sheinbaum on the dark web community DarkForums. Records displaying email addresses, a username, a date and place of birth, relatives and partners, and public employee institutional identifiers are present within the post.
- GhostVibe stated that the president considers herself as a feminist but fails to support related movements and to recognize “searching mothers,” a grassroots network of women in Mexico who independently investigate mass graves, prisons, and terrain to find their lost relatives.
- The threat actor’s claims suggest that they are ideologically motivated. GhostVibe has published seven additional doxxes, all sharing a similar format, affecting Mexican officials, businessmen, and a lawyer—all with threat actor commentary detailing ideological reasons for doxxing the targets.
The threat actor is unvetted, and there is a roughly even chance the data posted is publicly available. GhostVibe is almost certainly motivated by ideology and is likely attempting to embarrass the president or draw attention to the cause of “searching mothers.” Politicians will almost certainly remain a highly sought after target for PII discovery and exploitation.
Threat Actor Offers Alleged Zimbra Exploit for USD 15,000
On September 21, 2026, untested threat actor “xanxpills” advertised an undisclosed “N-day” exploit in open-source email and collaboration platform Zimbra for USD 15,000 on the dark web forum ReHub. An N-day exploit targets a known vulnerability for which patches are typically available but remain unpatched on victim systems. The actor claimed the exploit affects Zimbra versions up to 10.1.17/18; was tested on Windows 10/11 using Chrome, Edge, and Firefox; and that transactions would be conducted through a guarantor.
- The advertisement provided no technical details, vulnerability identifier, proof-of-concept, or evidence demonstrating the exploit's capabilities. The actor said the price was negotiable.
- The alleged exploit does not claim to affect the latest available versions of Zimbra. Zimbra 10.1.20 was released in July 2026, and 10.1.21 was released on September 24—three days after the advertisement.
- Zimbra has a sustained history of targeting by financially and politically motivated actors, including the exploitation of zero-day vulnerabilities by espionage groups in 2023,2 mass exploitation of CVE-2024-45519 in 2024,3 and continued exploitation by Russian state-supported actor LAUNDRY BEAR in 2025–2026.4 Successful exploitation of Zimbra is likely to result in sensitive data theft, including emails and personnel data of an organization.
Despite Zimbra's history of high-impact exploitation, xanxpills' lack of both technical evidence and credibility make the advertised exploit's legitimacy uncertain. The actor has limited activity on ReHub, with only one other post seeking information on SmartScreen bypass techniques.
- If the actor's claim about the N-day exploit and affected versions is accurate, the underlying vulnerability likely already has a patch and may have a publicly available or independently developed proof-of-concept (PoC). However, this cannot be verified because the specific vulnerability has not been disclosed.
- There is a roughly even chance that the advertised tool is instead a readily available exploit chain that has already been tested across relevant platforms, reducing the need for additional testing or development by the buyer.
Collective Announces New RaaS Offering
On September 7, 2026, the well-regarded ransomware collective Dark Project RaaS announced its presence on two active dark web forums focused on ransomware partnerships: ReHub and T1erOne. The ransomware group is not new and has reportedly been involved in multiple cyberattacks.
- The group began operating in August 2026 and has already published data belonging to 26 victim organizations.
Based on the group’s synopsis, the Dark Project RaaS offering does not differ significantly from other ransomware-as-a-service (RaaS) operations. However, the operators have established explicit requirements and conditions that are mandatory for all partners using their ransomware. Partners are required to obtain a minimum ransom payment of USD 100,000 from each victim, with the ransom amount expected to represent approximately 1–4 percent of the victim organization’s annual revenue. This requirement indicates that the RaaS is almost certainly targeting organizations with annual revenues exceeding USD 10 million.
- The operators exclude Commonwealth of Independent States (CIS) countries, BRICS member-states, educational institutions, government entities, and non-profit organizations from targeting.
- They identify the United States, European Union, Canada, and Australia as preferred target regions, while operations against organizations in other countries require prior consultation with the support team.
The RaaS operates on an 80/20 revenue-sharing model, with partners receiving 80 percent of ransom proceeds and Dark Project RaaS receiving 20 percent. For data-only extortion, the stated split is 90/10 in favor of partners. Partners can specify their own cryptocurrency wallet when creating a target; however, wallet changes are restricted and require contacting the support team, with changes apparently limited to switching to Dark Project RaaS’ wallet.
Based on information provided by the threat actor, Dark Project RaaS is very likely a competent, well-structured RaaS operation. They almost certainly have defined partner requirements, financial thresholds, geographic targeting restrictions, and a relatively broad set of ransomware capabilities across enterprise environments. All of these factors very likely make Dark Project RaaS a viable threat that will almost certainly conduct ransomware attacks in the near future.
Recommendations
- Develop a comprehensive incident response strategy.
- Deploy a holistic patch management process, and ensure all IT assets are patched with the latest software updates as quickly as possible.
- Adopt a Zero-Trust cybersecurity architecture based upon a principle of least privilege.
- Implement network segmentation to separate resources by sensitivity and/or function.
- Ensure critical, proprietary, or sensitive data is always backed up to secure, off-site, or cloud servers at least once per year—and ideally more frequently.
- Implement secure password policies, phishing-resistant multi-factor authentication (MFA), and unique credentials.
- Configure email servers to block emails with malicious indicators, and deploy authentication protocols to prevent spoofed emails.
- Proactively monitor for compromised accounts and credentials being brokered in deep and dark web (DDW) forums.
- Leverage cyber threat intelligence to inform the detection of relevant cyber threats and associated tactics, techniques, and procedures (TTPs).
ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 7:00 AM (EDT) on October 8, 2026; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
ZeroFox Intelligence Probability Scale
All ZeroFox intelligence products leverage probabilistic assessment language in analytic judgments. Qualitative statements used in these judgments refer to associated probability ranges, which state the likelihood of occurrence of an event or development. Ranges are used to avoid a false impression of accuracy. This scale is a standard that aligns with how readers should interpret such terms.
ZeroFox Intelligence Threat Actor Reputation Scale
- hXXps://kie[.]ai/blog/what-is-glm-5-3
- hXXps://www.cisa[.]gov/news-events/cybersecurity-advisories/aa22-228a
- hXXps://www.hipaajournal[.]com/critical-zimbra-flaw-being-mass-exploited/
- hXXps://www.cisa[.]gov/news-events/cybersecurity-advisories/aa26-204a