Underground LLM account sellers are cybercriminal marketplace actors who monetize unauthorized access to commercial AI and large language model services by selling or renting shared and private accounts, subscription upgrades, and stolen credentials. Their activity has centered on services such as ChatGPT, Perplexity, and Gemini, with offerings ranging from low-cost shared access to higher-priced private or longer-term access intended for sustained abuse. This activity is financially motivated and is closely tied to the broader underground ecosystem for stolen credentials and access brokerage. Operators obtain accounts through methods including purchases made with stolen payment cards and the resale of credentials and session material harvested by infostealer malware. The use of stolen session cookies enables session hijacking and can allow access without re-entering credentials, including bypass of some multifactor authentication protections tied to active sessions. The accounts sold by these actors can support a range of downstream criminal operations. Reported abuse cases include phishing content generation, malware development assistance, reconnaissance support, and potential exposure of sensitive business data when compromised accounts are tied to enterprise workflows. Shared-access offerings appear suited to disposable or short-term abuse, while private-access offerings are marketed for more persistent or operationally sensitive use. This is not a single named intrusion set or nation-state group, but rather a criminal market segment composed of multiple sellers and brokers operating in underground forums and markets. High-confidence reporting supports credential theft, session hijacking, initial access brokering, and financially motivated resale activity; direct attribution to a specific country or a stable organizational structure is not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.