A Russian-speaking actor, "Trim," dismantled publicly available frontier models and integrated them with offensive security tools.
July 21, 2026
An enterprising Russian-speaking hacker spent part of the year jailbreaking publicly available, frontier large language models (LLMs) to create a for-fee offensive cybercriminal tool, researchers have found.
The cybercriminal known as "Trim" started his operation by publishing jailbreaking techniques on an underground forum in late March. He eventually turned them "into a fully productized, commercially marketed AI-powered penetration-testing platform," researchers from Cato Networks' Cato CTRL revealed in a report published today.
The operation demonstrates once again how artificial intelligence (AI) models themselves have become part of the attack surface for cybercriminals, according to the report. Moreover, other bad actors are beginning to follow this blueprint for weaponizing AI models, which increases the security risk.











