top of page

Underground Hacker Tutorials Are Becoming an Early Warning System for Defenders as AI Fuels a New Wave of Cybercrime

  • Jul 13
  • 3 min read

Threat intelligence teams have long monitored ransomware groups, malware marketplaces, and dark web chatter for signs of emerging cyber threats. A new report from Radware suggests security teams may be overlooking another valuable source of intelligence: the underground tutorials where cybercriminals teach one another how to attack organizations.


After analyzing nearly 9,000 tutorial posts published across 24 deep and dark web forums over more than three years, Radware researchers found that hacker education is expanding again after a slowdown, with the focus shifting sharply toward financial fraud, account takeover, and identity theft. The findings suggest these communities are no longer simply recycling aging techniques. They are increasingly producing fresh instructional content that reflects where cybercrime is headed next.


According to the research, original hacking tutorials fell to their lowest point during 2024 before rebounding significantly in late 2025. By 2026, new tutorial production had roughly doubled, signaling renewed investment in creating original underground content rather than simply reposting older material.


Financial Fraud Has Replaced Growth Hacking


One of the report's clearest trends is a dramatic change in what cybercriminals are teaching.

Instead of emphasizing black hat SEO, affiliate manipulation, or other gray area monetization schemes, today's tutorials increasingly focus on carding, identity theft, cash-out operations, and account takeover techniques.


Researchers found that tutorials covering carding and identity theft grew from roughly one fifth of all instructional content in 2024 to nearly two fifths in 2026, making financial fraud by far the dominant topic across underground forums. Offensive security and phishing tutorials also increased, suggesting threat actors are documenting both the initial compromise and the monetization stages of attacks instead of treating them as separate disciplines.


The industries receiving the most attention reinforce that conclusion.


Telecommunications providers and social media platforms accounted for nearly two thirds of all tutorials that identified a specific target sector. Researchers say those services represent critical infrastructure for fraud operations because they enable SIM swapping, one-time password interception, verified account farming, and identity abuse needed to monetize stolen credentials.


AI Is Making Underground Content Easier to Produce


The report also highlights how generative AI is changing cybercriminal education.

Rather than replacing experienced operators, AI appears to be lowering the barrier for producing convincing looking hacking guides. Researchers documented multiple examples where threat actors appeared to use AI to generate broad technical overviews, rewrite legitimate security research into malicious tutorials, or create large catalogs of attack techniques designed primarily to attract attention and build credibility.


One case examined an apparent AI-generated tutorial listing 100 techniques for attacking PHP applications. While comprehensive on the surface, researchers found numerous technical inaccuracies, outdated exploitation methods, and language patterns consistent with automated content generation followed by word substitution designed to evade AI safety filters. The guide appeared intended more as a reputation-building tool than a practical operational manual.


Another example involved a threat actor reposting publicly available research about using Claude Code to deobfuscate JavaScript, presenting it as original experimentation after paraphrasing the content with AI. Researchers concluded the forum post closely mirrored an earlier public blog while manufacturing the appearance of hands-on expertise.


Popularity Doesn't Mean Influence


The study also challenges a common assumption about underground forums.

Many tutorials that appear highly popular are not spreading organically. Instead, researchers found that a relatively small group of accounts is responsible for much of the activity.


The most active one percent of forum users generated more than one quarter of all posting activity, while the top ten percent produced well over half. Among tutorials reposted at least ten times, nearly four out of five were driven by coordinated promotion campaigns rather than independent sharing by community members. Some of these campaigns likely function as marketing efforts or lead generation for paid cybercrime services instead of genuine educational resources.


A New Intelligence Source for Security Teams


While the report examines how cybercriminals share knowledge, Radware argues the bigger opportunity lies with defenders.


Rather than viewing underground tutorials solely as criminal content, organizations can treat them as an intelligence feed that reveals emerging attack trends before they become widespread campaigns.


Monitoring which techniques are being taught, which industries are receiving attention, and how quickly new fraud methods appear could help security teams identify evolving business logic attacks and account takeover techniques earlier in the attack lifecycle.


As AI continues lowering the cost of producing both offensive research and convincing technical documentation, underground forums may become an increasingly valuable indicator of where financially motivated cybercrime is heading next.

bottom of page