Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

April 7, 2025

Xanthorox AI, a malicious, modular AI system launched on darknet forums in early 2025, poses a significant threat to safe and secure AI practices. This autonomous attack platform, designed for offensive cyber operations, runs on private infrastructure and incorporates models for code generation, phishing, malware, social engineering, and real-time voice/image input. Its deployment underscores the urgent need for responsible AI governance through projects like HISPI Project Cerebellum TAIM, which aims to map, measure, manage, and govern such incidents to prevent harm.

For those interested in shaping responsible AI policies and fostering trustworthy AI practices, JOIN US.

Matched TAIM controls

Suggested mapping from embedding similarity (not a formal assessment). Browse all TAIM controls

Alleged deployer
unknown-malicious-actors, darknet-forum-users, cyber-criminals, cyber-criminal-networks
Alleged developer
xanthorox-ai-creators, unknown-black-hat-ai-developers
Alleged harmed parties
victims-of-phishing-attacks, victims-of-malware-attacks, victims-of-automated-cybercrime, general-public, enterprise-it-systems, critical-infrastructure-systems

Source

Data from the AI Incident Database (AIID). Cite this incident: https://incidentdatabase.ai/cite/1015

Data source

Incident data is from the AI Incident Database (AIID).

When citing the database as a whole, please use:

McGregor, S. (2021) Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. In Proceedings of the Thirty-Third Annual Conference on Innovative Applications of Artificial Intelligence (IAAI-21). Virtual Conference.

Pre-print on arXiv · Database snapshots & citation guide

We use weekly snapshots of the AIID for stable reference. For the official suggested citation of a specific incident, use the “Cite this incident” link on each incident page.