A new malicious AI platform named Xanthorox AI has emerged, positioning itself as a friendly tool for hackers.
First spotted in late Q1 2025, Xanthorox AI is being promoted in underground cybercrime forums as a modular, self-hosted solution for automated hacking operations, marking a new era in the sophistication of cyber threats.
By its independent, multi-model framework, Xanthorox AI distinguishes itself from previous malicious AI tools like WormGPT, FraudGPT, and EvilGPT.
It operates on private servers, avoiding reliance on public cloud infrastructure or APIs, significantly reducing its visibility and traceability.
The platform boasts five distinct AI models, each tailored for specific cyber operations, from code generation to data analysis, all integrated into a modular architecture that allows for future updates or replacements of functionalities.
Application Security is no longer just a defensive play, Time to Secure -> Free Webinar
Capabilities of Xanthorox AI
The toolkit includes:
- Xanthorox Coder: Automates tasks such as code creation, script development, malware generation, and vulnerability exploitation.
- Xanthorox Vision: Adds visual intelligence by analyzing uploaded images or screenshots, extracting relevant data, and interpreting visual content.
- Reasoner Advanced: Mimics human logic to generate convincing and consistent outputs, aiding in manipulation and social engineering.

Additionally, the SlashNext report states that Xanthorox AI supports voice-based interaction through real-time calls and asynchronous messaging, enabling hands-free command and control.
It can perform live internet search scraping using over 50 engines, offering up-to-date information, and operates offline, ensuring data containment and reducing the risk of third-party AI telemetry.

The emergence of Xanthorox AI represents a shift in the cyber threat landscape. It provides attackers with tools to execute complex, multilayered attacks without relying on external systems.
Its modular design and offline capabilities make it an all-in-one toolkit for cybercriminals. It can generate malware, analyze images, scrape data, and more.
Xanthorox AI’s introduction into the cybercrime arena underscores the ongoing arms race between attackers and defenders in the digital realm.
Its capabilities highlight the need for advanced AI-powered detection technologies and a proactive, collaborative approach to cybersecurity.
As AI continues to evolve, its dual role in both enhancing security measures and empowering attackers necessitates a vigilant and innovative response from the cybersecurity community.
Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try 50 Request for Free