INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Ransomware Attacks Target Japanese Companies with AI-Powered Malware

| 2026-10-01 12:56 CRITICAL HIGH AI-ENABLED ATTACK RANSOMWARE & EXTORTION MALWARE & BOTNETS
Executive Summary
AI-generated
Ransomware incidents have been on the rise globally, with Japan experiencing a 4.7% increase in ransomware attacks during the first half of 2026 compared to the same period last year. The Gentlemen was identified as the most active ransomware group in this time frame, potentially involving Russian-speaking individuals. A total of 90 organizations were affected by these attacks, with Taiwan recording the highest number of incidents followed by the United States and Philippines. Meanwhile, a prominent accounting firm, Krycler, Ervin, Taubman & Kaminsky, has been targeted by ransomware operators, resulting in an 88gb data breach. This incident highlights the growing threat of cyber attacks on businesses worldwide.
Technical Mitigations AI-generated
• Implementing robust backups and disaster recovery plans to minimize data loss in the event of a ransomware attack. • Utilizing endpoint security solutions, such as antivirus software and intrusion detection systems, to detect and prevent ransomware infections on individual devices. • Conducting regular network segmentation and isolation techniques to limit the spread of ransomware within an organization's network.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
QilinQilin CVE-2025-24799CVE-2025-24799 CVE-2020-1472CVE-2020-1472 CVE-2025-2479CVE-2025-2479
Target & Sectors
TW JP RU
manufacturingmanufacturing financefinance transportationtransportation legallegal retailretail healthhealth
Incident Timeline
‎January to 87
The number of victims targeted by Akira increased sharply from 48 in January to 87 in February.
‎around July 2025
The Gentlemen ransomware group has been active since around July 2025, targeting victims including Krycler, Ervin, Taubman & Kaminsky.
tactic Ransomware
‎2025/09/17
Ransomware incidents in Japan increased by approximately 4.7% compared to the same period last year, with a total of around 86 reported incidents from January to July this year.
tactic Ransomware
target_region Japan
general_metric 4.7 %
general_metric 86 incidents
malware Qilin
organisation SafePay
‎January to July 2026
Threat actors used ransomware to target Japanese companies, resulting in the publication of a new victim.
tactic Ransomware
target_region Japan
general_metric 1 companies
‎January – July 2026
Threat actors used The Gentlemen leak site to publish a new victim listing for Krycler, Ervin, Taubman & Kaminsky between January and July 2026.
‎2026/10/01
The threat actor Qilin leveraged AI to improve the efficiency of its operations, using a tool that periodically sent ping requests to a specified IP address and logged whether the host was reachable.
organisation SSN
infrastructure Windows
organisation /mnt/Backup
organisation VHDX
victims 90 organizations
organisation NightSpire
organisation LockBit 5.0
organisation AiLock
organisation LLM
organisation Ervin, Taubman & Kaminsky
organisation Krycler
data_breach 88 gb
organisation GPO
organisation Active Directory Group Policy
organisation Windows/Active Directory
organisation NetExec
organisation Proofs
organisation RustHound
organisation BloodHound
organisation SQL
organisation Responder
organisation NTLM
organisation AnyDesk
organisation Rclone
organisation RDP
organisation CVE-2025-24799
organisation PoC
organisation SAM
organisation Chisel
organisation Nmap
organisation SMB
organisation Active Directory
organisation cPanel/WHM
organisation SSH
organisation HTTP/S
organisation DNS/DoH
organisation IP
organisation the .bash_history File
organisation MFA
organisation EDR
organisation SNORT®
data_breach 100 number
data_breach 16 files
‎the first half of 2026
The Gentlemen ransomware group was the most frequently observed in Japan during the first half of 2026, resulting in 14 incidents.
organisation Ransomware
target_region Japan
general_metric 14 incidents
Tactical Metrics
Metrics
data_breach
88
Gb
Metrics
victims
90
Organizations
Metrics
infrastructure
‎Windows
Affected Product
Metrics
data_breach
100
Number
Metrics
data_breach
16
Files